Connect with us

E-Business

Ransomware Attack: Only 26 Percent of Retail Organizations Were Able to Halt Cybercriminals from Encrypting Their Data- Sophos

Published

on

Kindly share this post

Sophos, a global leader in innovating and delivering cybersecurity as a service, on Thursday shared findings from its sector survey report, “The State of Ransomware in Retail 2023,” which found that only 26% of retail organizations this past year were able to disrupt a ransomware attack before their data was encrypted.

This is a three-year low for the sector—a decline from 34% in 2021 and 28% in 2022—suggesting the sector is increasingly unable to halt ransomware attacks already in progress.

“Retailers are losing ground in the battle against ransomware. Ransomware criminals have been encrypting increasingly greater percentages of their retail victims in the last three years, as evidenced by the steadily declining rate of retailers stopping cybercriminal attacks in progress. Retailers must up their defensive game by setting up security that detects and responds to intrusions earlier in the attack chain,” said Chester Wisniewski, director, global field CTO, Sophos.

In addition, the report found that, for those retail organizations that paid the ransom, their median recovery costs (not including the ransom payment) were four times the recovery costs of those that used backups to recover their data ($3,000,000 versus $750,000).

“Forty-three percent of retail victims paid the ransom according to our survey respondents, yet the median recovery cost to victims who paid the ransom was four times the cost to those who used backups and other recovery methods. There are no shortcuts in these situations and rebuilding systems is almost always required. It’s better to deprive the criminals of their spoils and build back better,” said Wisniewski.

Advertisement

Additional key findings from the report include:

·       In line with a broader, cross-sector trend, the retail sector experienced its highest rate of encryption over the past three years, with 71% of those organizations targeted by ransomware stating that attackers successfully encrypted their data

·       The percentage of retail organizations attacked by ransomware declined from 77% last year to 69% this year

·       The percentage of retail organizations that recovered in less than a day decreased from 15% to 9% this year, while the percentage of retail organizations that took more than a month to recover increased from 17% to 21%

Sophos recommends the following best practices to help defend against ransomware and other cyberattacks:

Advertisement

·       Strengthen defensive shields with:

o   Security tools that defend against the most common attack vectors, including including endpoint protection with strong anti-ransomware and anti-exploit capabilities

o   Zero Trust Network Access (ZTNA) to thwart the abuse of compromised credentials.

o   Adaptive technologies that respond automatically to attacks, disrupting adversaries and buying defenders time to respond.

o   24/7 threat detection, investigation and response, whether deliveredin-house or by a specialized Managed Detection and Response (MDR) provider

Advertisement

·       Optimize attack preparation, including regularly backing up, practicing recovering data from backups and maintaining an up-to-date incident response plan

·       Maintain security hygiene, including timely patching and regularly reviewing security tool configurations

To learn more about the State of Ransomware in Retail 2023, download the full report from Sophos.com.

The State of Ransomware 2023 survey polled 3,000 IT/cybersecurity leaders in organizations with between 100 and 5,000 employees, including 355 from the retail sector, across 14 countries in the Americas, EMEA and Asia Pacific.

Advertisement

Kindly share this post

Ugo Onwuaso is an ICT enthusiast. He believes technology should be used for general good. He holds a Master of Public Administration (MPA) degree from the Lagos state University. Dear Reader, Your support matters. But we believe that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. That is why, we have devoted our energy to independent reportage of technology and finance and how they affect lives. Our incisive and analytical view of how technology news affects the daily life help individuals and organizations make up their minds. Quality journalism costs money. Today, we're asking that you support us to do more. Kindly support our effort to deliver technology and finance journalism to everyone in the world. Donate as little as N1,000. Bank transfers can be made to: UBA Plc 1017156876 Communication Week Media Ltd

E-Business

HURIWA, CLO Protests Bill Asking Social Media Firms’ to Open Shops Nigeria

Published

on

Kindly share this post

Human Rights Writers Association of Nigeria (HURIWA) has opposed a bill seeking to compel major global social media companies to establish physical offices in Nigeria.

HURIWA, CLO Protests Bill Asking Social Media Firms’ to Open Shops Nigeria

The rights advocacy group urged the National Assembly to discard the proposed legislation, warning that it could become a tool for censorship and undermine citizens’ constitutional right to freedom of expression, despite being presented as a measure to strengthen Nigeria’s digital economy and improve corporate accountability.

The position was contained in a presentation submitted yesterday by Emmanuel Onwubiko, national coordinator, HURIWA, to the chairman of the Senate Committee on ICT and Cyber Security.

The bill, sponsored by Senator Ned Munir Nwoko, has already passed second reading in the Senate and is before the committee for further legislative consideration.

HURIWA said it carefully reviewed the proposed legislation and concluded that compelling global technology companies to establish offices in Nigeria was unnecessary and potentially counterproductive.

Advertisement

The organisation argued that while the firms generate substantial revenue from Nigeria’s vast digital market, they already engage Nigerians through existing structures, including paying eligible content creators, working with local technology professionals and participating in legal proceedings whenever required.

According to the group, appointing local representatives where necessary would adequately address concerns about engagement with regulators and users without forcing the companies to maintain physical offices.

It also dismissed claims that mandatory country offices would significantly improve consumer complaint resolution, technology transfer or employment generation.

HURIWA maintained that the platforms already have effective feedback mechanisms for resolving users’ complaints and routinely appear before Nigerian courts through their representatives whenever litigation arises.

The group, however, said its greatest concern was the potential for the proposed law to be used as an instrument for restricting freedom of expression.

Advertisement

It argued that establishing local offices could expose global social media companies to pressure from government authorities to remove online content considered critical of those in power.

According to the rights group, the presence of social media companies in Nigeria could become an avenue for authorities to pressure them into abandoning internationally recognised digital rights standards in favour of politically motivated content moderation.

It recalled previous attempts to regulate social media in Nigeria that generated widespread concerns over possible restrictions on free speech, stressing that any legislation affecting the digital space must contain clear safeguards against abuse.

The organisation warned that the proposed law should never become “a backdoor mechanism for government surveillance, arbitrary content removal or political censorship.

 

Advertisement

Kindly share this post
Continue Reading

E-Business

Nigeria Leads Africa in Online Gambling Regulation – GCI

Published

on

Kindly share this post

Nigeria has emerged as one of Africa’s most regulated online gambling markets, even as illegal operators continue to dominate the continent, according to a new report by Gaming Compliance International (GCI).

Nigeria Leads Africa in Online Gambling Regulation - GCI

The report, the first comprehensive assessment of online gambling across all 54 African countries, showed that Africa’s online gambling Gross Gaming Revenue (GGR) reached $23 billion in 2025.

However, only $5.2 billion (23 per cent) was generated by licensed operators, while $17.8 billion (77 per cent) remained in the unregulated market.

In West Africa, total online gambling revenue rose to $4.8 billion in 2025 from $4.3 billion in 2024. Of the 2025 figure, regulated operators accounted for $1.5 billion (31 per cent), while $3.3 billion (69 per cent) flowed to unlicensed platforms, highlighting the region’s persistent enforcement challenges.

Nigeria stood out as the region’s strongest performer, recording the lowest unregulated market share at 56 per cent, compared with the West African average of 69 per cent and the African average of 77 per cent.

Advertisement

The study also found that online gambling participation across Africa increased from 198 million people (13 per cent of the population) in 2024 to 215 million (14 per cent) in 2025.

Despite this growth, GCI estimated that illegal operators deprived African governments of about $3.55 billion in tax revenue in 2025. The number of unlicensed gambling platforms targeting African consumers also rose to 4,129, up from 3,644 in 2024.

Commenting on the findings, Matt Holt, chief executive officer, GCI, said the report provides regulators with the first continent-wide benchmark for strengthening oversight and consumer protection.

Ismail Vali, president, GCI, urged governments to develop competitive and well-regulated markets that encourage consumers to patronise licensed operators, boost public revenue and attract greater investment.

Online gambling in Nigeria is regulated by the Nation Lottery Regulatory Commission.

Advertisement

Kindly share this post
Continue Reading

E-Business

Kaspersky Warns Mobile‑data Buyers about Scammers Posing as Telecoms Operators

Published

on

Kindly share this post

At the height of the Northern Hemisphere tourist season, demand for communications and mobile Internet services rises sharply. Kaspersky’s security experts have uncovered scams that target anyone purchasing mobile connections or SIM cards worldwide.

Fraudsters create counterfeit websites that look like the portals of major regional and international telecom providers to trick users into revealing their phone numbers, personal details or banking information.

Kaspersky is sharing several examples of these fake login pages that mimic legitimate telecom operator sites and giving recommendations on how not to be deceived.

In the first case, scammers exploit the brand name of an international telecommunications company operating services in Asia, Africa and Europe. Fake authentication pages encourage users to put in their phone number and credentials.

While the first example shows the different design, the second scam site closely mimics the original log in page, making it hard for users to tell the difference and spot a fake. Entering authentication or payment data on fraudulent web sites may result in money or data loss and become a reason for more frequent spam and fraudulent calls.

Advertisement

Another example is a scam page which poses as another international communications company, working in North Africa, the Middle East and Southeast Asia. In this scheme scammers encourage users to top up their mobile data/Internet plans by entering their personal information and bank cards details.

Kaspersky experts have also identified a scam when cyber criminals suggest users enter their personal data to check and pay a bill inquiry. Such scam schemes are usually aimed at gaining victims’ personal data for further fraud or account hacking and stealing money.

“Because of the active use of AI, scammers can now create fake pages with ever increasing accuracy and speed, targeting the most popular user interest areas. We constantly see scams revolving around sports events, music concerts, seasonal sales and holidays. Unfortunately, the telecoms industry is no exception.

To keep your data and money safe, be vigilant when purchasing mobile or Internet plans online. Using an eSIM – purchased through an official app – is one way to avoid fake telecom sites, as it eliminates the need to enter personal details on questionable web pages.

If you’re unsure about a site’s legitimacy, search for the brand name directly in a search engine and enable a security solution that blocks phishing links for you,” comments Tatyana Kulikova, cybersecurity expert at Kaspersky.

Advertisement

 

Kindly share this post
Continue Reading

Trending