Frequently Asked Questions

FIN12 Ransomware Threat Actor & Targeting Trends

What is FIN12 and why is it significant in the context of ransomware attacks?

FIN12 is a ransomware threat actor known for aggressively targeting high-value sectors, especially healthcare organizations. Unlike some groups that claimed to avoid hospitals during the COVID-19 pandemic, FIN12 has shown no such restraint, making it a significant risk to critical care providers and other large enterprises. (Source: Original Webpage)

Which sectors does FIN12 most frequently target?

FIN12 most frequently targets the healthcare sector, with nearly 20% of observed victims operating medical facilities. Other targeted sectors include business services, education, finance, government, manufacturing, retail, and technology. (Source: Original Webpage)

How does FIN12 select its victims?

FIN12 prioritizes victims based on annual revenue, typically targeting organizations with more than 0 million USD in revenue. This focus on high-revenue companies aligns with trends in underground forums and enables larger ransom demands. (Source: Original Webpage)

What regions are most affected by FIN12 ransomware attacks?

Nearly 85% of FIN12's known victims are based in North America. However, the group's reach is expanding, with recent victims in Australia, Colombia, France, Indonesia, Ireland, the Philippines, South Korea, Spain, the United Arab Emirates, and the United Kingdom. (Source: Original Webpage)

How has FIN12's targeting changed over time?

FIN12's regional targeting is expanding. In the first half of 2021, the number of victim organizations outside North America doubled compared to 2019 and 2020 combined, indicating a growing global reach. (Source: Original Webpage)

Why does FIN12 focus on high-revenue organizations?

FIN12 targets high-revenue organizations because larger companies are perceived as more likely to pay substantial ransom demands. This approach is consistent with broader ransomware trends and is often discussed in underground forums. (Source: Original Webpage)

How does FIN12's targeting compare to other ransomware groups?

Unlike some ransomware groups that claimed to avoid hospitals during the COVID-19 pandemic, FIN12 has consistently targeted healthcare organizations. FIN12 also tends to target larger companies compared to the average ransomware affiliate. (Source: Original Webpage)

What role do underground forums play in FIN12's victim selection?

Underground forums influence FIN12's victim selection by setting revenue thresholds for potential targets. Some threat actors, including those using RYUK, specify minimum annual revenue requirements for victims, which aligns with FIN12's focus on high-value organizations. (Source: Original Webpage)

How does FIN12's selection of victims impact ransom demands?

By targeting high-value organizations, FIN12 can justify and demand larger ransom payments. Comments in malware administration panels used by FIN12's initial access providers often reference revenue information to prioritize targets. (Source: Original Webpage)

What evidence is there of FIN12's activity in the healthcare sector?

Mandiant observed FIN12 activity at healthcare organizations both before and after the October 2020 joint alert by U.S. government entities warning of increased ransomware threats to hospitals and medical facilities. (Source: Original Webpage)

How does FIN12's approach differ from ransomware groups that avoid hospitals?

While some ransomware groups stated intentions to avoid hospitals, especially during the COVID-19 pandemic, FIN12 has shown no such restraint and continues to target healthcare organizations aggressively. (Source: Original Webpage)

What is the significance of the October 2020 joint alert regarding ransomware threats?

The October 2020 joint alert by multiple U.S. government entities highlighted an "increased and imminent" ransomware threat to hospitals and medical facilities, which was corroborated by observed FIN12 activity in the sector. (Source: Original Webpage)

How does FIN12's targeting pattern reflect broader ransomware trends?

FIN12's focus on high-revenue and critical sectors mirrors a broader trend among ransomware groups to pursue larger targets for higher ransom payouts. (Source: Original Webpage)

What is the impact of FIN12's attacks on healthcare organizations?

FIN12's attacks on healthcare organizations can disrupt critical care functions, putting patient safety and business operations at risk. (Source: Original Webpage)

What factors may be driving FIN12's expanding global reach?

FIN12's expanding global reach may be due to working with more diverse partners for initial access and increased attention from U.S. government agencies, prompting the group to target organizations outside North America. (Source: Original Webpage)

How does Cymulate help organizations defend against ransomware threats like FIN12?

Cymulate enables organizations to simulate real-world ransomware threats, including those from groups like FIN12, to test and validate their defenses. The platform provides continuous threat validation, exposure management, and actionable insights to improve resilience against ransomware attacks. (Source: Knowledge Base)

What types of ransomware threats can Cymulate validate?

Cymulate validates threats across the full kill chain, including ransomware, phishing, malware, lateral movement, data exfiltration, and zero-day exploits, using daily updated threat templates and AI-generated attack plans. (Source: Knowledge Base)

How does Cymulate's immediate threats module help with emerging ransomware attacks?

Cymulate's immediate threats module is rapidly updated to reflect new attacks, allowing organizations to quickly assess their IT estate for exposure to new ransomware threats and implement remedial actions promptly. (Source: Knowledge Base)

Healthcare & High-Value Sector Cybersecurity Risks

Why is the healthcare sector a prime target for ransomware groups like FIN12?

The healthcare sector is targeted due to the high value of patient data and the critical nature of healthcare operations. Ransomware attacks can disrupt essential services, making healthcare organizations more likely to pay ransoms to restore operations quickly. (Source: Knowledge Base)

What are the primary cybersecurity risks faced by the healthcare sector?

The healthcare sector faces risks such as ransomware attacks, data breaches, and operational disruptions. The sensitivity of patient data and the need for continuous operations make healthcare organizations especially vulnerable to cyberattacks. (Source: Knowledge Base)

What types of cyber threats does the financial services sector face?

The financial services sector is targeted by sophisticated threats, including ransomware, phishing, and advanced persistent threats (APTs), requiring robust security controls to protect both internal systems and customer-facing applications. (Source: Knowledge Base)

What are the evolving tactics used by cyber threat actors to cause data breaches?

Cyber threat actors use tactics such as phishing (including spear-phishing and whaling), malware (ransomware and viruses), and social engineering to cause data breaches. These methods are constantly evolving to bypass security controls. (Source: Knowledge Base)

What types of threats and techniques does Cymulate simulate for endpoint security validation?

Cymulate simulates threats such as known malicious file samples, malicious behaviors, ransomware, worms, trojans, rootkits, DLL side-loading, and code injection to validate endpoint security controls. (Source: Knowledge Base)

How does Cymulate address immediate and emerging threats?

Cymulate's immediate threats module is updated rapidly to assess new attacks, enabling organizations to quickly evaluate their risk exposure and implement remedial actions. This ensures simulation of the latest threats, including ransomware and other current attack vectors. (Source: Knowledge Base)

What feedback have customers given about Cymulate's immediate threats module?

Customers praise Cymulate's immediate threats module for its rapid updates and ability to quickly assess risk from new attacks. One Lead Cyber Defense Engineer stated: "I am particularly enamored with the immediate threats module and how quickly this gets updated. In short if an attack is new, you can quickly assess your IT estate for how much of a risk is posed to you and implement remedial action quickly." (Source: Knowledge Base)

How does Cymulate help organizations prioritize threat exposures?

Cymulate uses automated threat validation and exposure scoring to help organizations identify and rank vulnerabilities based on actual exploitability and impact on business-critical assets, enabling focused remediation efforts. (Source: Knowledge Base)

What problems does Cymulate's Threat Validation solution solve for security teams?

Cymulate's Threat Validation solution addresses the lack of confidence in security controls and security configuration drift, ensuring defenses can prevent and detect the latest attacks and reducing gaps caused by evolving configurations. (Source: Knowledge Base)

What are insider attacks and how can the risks be mitigated?

Insider attacks originate from internal actors, either malicious or accidental. Risks can be mitigated by enforcing least privilege access, monitoring user behavior with UEBA, and regularly testing segmentation and access controls. (Source: Knowledge Base)

Cymulate Platform Features & Use Cases

What is Cymulate and what does it do?

Cymulate is a leader in exposure management and security validation, providing a platform to assess, simulate, and improve organizational security posture. It enables continuous threat validation, vulnerability prioritization, security control optimization, and compliance support. (Source: Knowledge Base)

Who can benefit from using Cymulate?

Cymulate is designed for CISOs, Red Teams, SecOps, vulnerability management teams, and detection engineers in organizations of all sizes, especially those in high-value sectors like healthcare and finance. (Source: Knowledge Base)

How easy is it to implement Cymulate?

Cymulate is designed for rapid, agentless deployment with no need for additional hardware or complex configurations. Customers can start running simulations almost immediately after deployment. (Source: Knowledge Base)

What feedback have customers given about Cymulate's ease of use?

Customers consistently praise Cymulate for its intuitive design and ease of use. Testimonials highlight simple implementation, a user-friendly dashboard, and actionable insights accessible even for teams with limited resources. (Source: Knowledge Base)

What are the key capabilities of Cymulate's platform?

Cymulate offers continuous threat validation, exposure awareness, defensive posture optimization, attack path discovery, automated mitigation, integration with security tools, and dedicated cloud validation features. (Source: Knowledge Base)

What business impact can customers expect from using Cymulate?

Customers can expect a 30% improvement in threat prevention, a 52% reduction in critical exposures, a 60% increase in operational efficiency, 40X faster threat validation, and an 81% reduction in cyber risk within four months. (Source: Knowledge Base)

What is Cymulate's pricing model?

Cymulate operates on a subscription-based pricing model, customized based on the chosen package, number of assets, and scenarios. For a tailored quote, organizations can schedule a demo with the Cymulate team. (Source: Knowledge Base)

How does Cymulate compare to other exposure management and security validation platforms?

Cymulate stands out with its unified platform, continuous threat validation, AI-powered optimization, complete kill chain coverage, ease of use, and the industry's largest attack simulation library. It is recognized as a leader by Gartner and G2. (Source: Knowledge Base)

What security and compliance certifications does Cymulate hold?

Cymulate holds SOC2 Type II, ISO 27001:2013, ISO 27701, ISO 27017, and CSA STAR Level 1 certifications, demonstrating adherence to industry-leading security and privacy standards. (Source: Knowledge Base)

What technical documentation is available for Cymulate?

Cymulate provides technical documentation including data sheets on custom attack simulations, technology integrations, and a whitepaper on its exposure management platform. These resources are available on the Cymulate website. (Source: Knowledge Base)

New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More
New Case Study: How a Financial Authority Validates Cyber Resilience
Learn More

FIN12 Ransomware Threat Actor Aggressively Pursued Healthcare Targets

October 13, 2021

FIN12's operations provide illustration that no target is off limits when it comes to ransomware attacks, including those that provide critical care functions.
Almost 20 percent of directly observed FIN12 victims were in the healthcare industry and many of these organizations operate medical facilities.
Mandiant observed FIN12 activity at healthcare organizations both before and after the joint alert by multiple U.S. government entities in October 2020 that warned of an "increased and imminent" threat to hospitals and medical facilities.
This targeting pattern deviates from some other ransomware threat actors who had at least stated an intention to show restraint in targeting hospitals, especially throughout the COVID-19 pandemic.
FIN12's remaining victims have operated in a broad range of sectors, including but not limited to business services, education, finance, government, manufacturing, retail, and technology.

North America as a Key Target

While these victim organizations have been overwhelmingly located in North America, there is some evidence that FIN12's regional targeting is expanding.
Nearly 85 percent of the group's known victims have been based in North America,

Growing Global Reach

Mandiant observed twice as many victim organizations based outside of North America in the first half of 2021 than they observed in 2019 and 2020 combined.
Collectively, these organizations have been based in Australia, Colombia, France, Indonesia, Ireland, the Philippines, South Korea, Spain, the United Arab Emirates, and the United Kingdom.
This shift could be due to various factors such as FIN12 working with more diverse partners to obtain initial access and increasingly elevated and unwanted attention from the U.S. government.

Revenue-Driven Targeting

Preference for High-Revenue Victims

Mandiant believe that the most significant factor in FIN12's targeting calculus has been a victim's annual revenue.
The vast majority of known FIN12 victims have more than $300 million USD in revenue, based on corporate financial data compiled from ZoomInfo.

Alignment with Underground Forum Activity

While this data is skewed to our direct visibility, FIN12 does appear to consistently target larger companies in comparison to the average ransomware affiliate.
Targeting victims that meet a certain revenue threshold also aligns with underground forum activity; some threat actors, including those using RYUK, have specified different ranges of minimum requirements for potential victims' annual revenue.

High-Value Targets for High Ransom Demands

Further, comments detailing revenue information in malware administration panels operated by FIN12's initial access providers illustrate that this is a relevant factor for victim selection or at minimum for prioritization of available targets.
FIN12's selection of high-value targets is consistent with the broader trend of threat actors pursuing larger targets in recent years, almost certainly because of the perception that it justifies proportionally large ransom demands..