
Since 2020 BlackFog has measured publicly disclosed attacks globally. The 2022 ransomware attack report reflects on the key findings from 2022. We have also published a blog discussing the key lessons learned from ransomware in 2022 which expands on the general trends we see going forward.
In 2022 we recorded a total of 376 attacks, a 29% increase over 2021 and 34% increase from 2020. Key take aways from these overall numbers is that 89% of all attacks now involve data exfiltration, 9% more than in 2021. From a tactical point of view we also saw an increase in the use of PowerShell, now at 87% of all attacks, a 7% increase from 2021. While the Dark Web was used in 23% of all attacks, a dramatic increase from 5% in 2021.

Geography
From a geographic perspective, the United States dominated as in previous years, representing 46% of all attacks with an overall increase of 18% over 2021. This was followed by the UK and Canada at 7% and 6% respectively. As in 2021, 2 out of every 3 attacks were perpetrated on the top 3 countries.
In terms of data exfiltration we saw significant growth in attacks from China and Russia, representing 27% and 17% respectively. This is an 11% increase in China and 5% in Russia, these 2 countries now represent 44% of all exfiltration globally. A very sobering number indeed.

Organizational
When we look at the organizational distribution in 2022 we saw some interesting trends. For the first time we saw education as the top attack target with 17% of all attacks followed closely by government and healthcare at 16% and 15% respectively. We saw the average size of organizations vary throughout the year and average 19,740 employees, on par with 2021.
A clear standout in 2022 was the significant increase in attacks on both the education and healthcare sectors, both increasing by 49% over 2021. This reflects the overall focus on sectors with the lowest investment in infrastructure and skills generally, as we have previously reported. This was following closely by government and technology with increases of 17% and 14% respectively from 2021.

Variants
The landscape on ransomware variants changed significantly during 2022 with LockBit clearly dominating successful attacks, with 16% of all attacks, followed by BlackCat at 13%, Hive at 12.1% and Conti 9.0%. Most notable is the sheer increase in attacks over 2021. LockBit was hardly even mentioned in 2021 yet saw a 600% increase in 2022. Similarly, BlackCat and Hive were virtually unheard of but they rounded out 2022 as the second and third most successful variants.
As mentioned earlier, BlackFog has also summarized the key lessons learned from 2022 and the general macro trends we are seeing that are influencing the broader market.

Related Posts
BlackFog report reveals 63% increase in Q2 ransomware attacks YoY
BlackFog report reveals 63% YoY surge in ransomware attacks in Q2 2025, with healthcare and retail sectors among the hardest hit.
Fog Ransomware Surges in 2025 Hitting Schools and Banks Alike
Fog ransomware has surged in 2025, targeting the educational and financial sector. Learn about its technical tactics, double extortion methods, and defense strategies.
Data Risk Assessment: The First Step Toward Smarter Data Protection
Understanding how to conduct a data risk assessment is a key step in protecting systems and networks from both internal and external threats.
Data Risk Management: A Smarter, Deeper Approach
Make sure your data risk management strategy goes beyond the basics to ensure critical information is safe from hackers, accidental breaches and other threats.
GDPR Audit: A Practical Guide to Staying Compliant
What should firms be thinking about when conducting a GDPR audit and why must this be a key part of a data risk management strategy?
5 Emerging Data Security Threats You May Not Have Considered
Keep an eye on these five rapidly-evolving data security threats to ensure sensitive information is fully protected from exposure.