Ransomware cases made up 70% of Sophos incident response cases for small businesses in 2024.
Data-focused threats to small businesses increased in 2024, including compromised network edge devices, abuse of software-as-a-service platforms, compromised business emails, and fraudulent apps with malware.
Major cybercrime trends in 2024 included the growth of remote ransomware attacks, social engineering attacks via Teams Vishing, MFA phishing, adversarial AI in phishing emails, quishing attacks, malvertising and SEO poisoning, and the use of EDR killers.
Sophos observed a browser hijacking campaign linked to Google search malvertising in the second half of 2024, using malicious web advertisements to distribute malware.