Ransomware payments surged 500% due to legacy MFA failures

The 500% Increase in Ransomware Attacks and the Legacy MFA Problem

The cybersecurity landscape has recently seen a staggering surge in ransomware payments, with a more than 500% increase. Sophos' "State of Ransomware 2024" report indicates that the average ransom payment has skyrocketed from $400,000 in 2023 to $2 million in the past year. RISK & INSURANCE also reported a dramatic rise, with the median ransom demand jumping from $1.4 million in 2022 to $20 million in 2023, and actual payments soaring from $335,000 to $6.5 million. This significant rise in ransom payments reflects the growing sophistication of cyberattacks and the vulnerabilities of outdated security measures. A major factor behind this trend is the continued use of legacy Multifactor Authentication (MFA) systems, which are increasingly ineffective against modern cyber threats. Additionally, the use of Generative AI by cybercriminals to create highly convincing phishing attacks has made detection by even the most vigilant users more difficult. Let's examine the reasons behind the increase in ransomware payments, the limitations of traditional MFA, and the importance of adopting next-generation MFA solutions.

John Gunn, CEO, Token
2 minute read
Deepfakes vs Interactive Deepfakes

How AI Deepfakes Bypass MFA and What Stops Them

With the rise of AI-generated deepfakes, which are becoming more convincing and widespread in video conferencing, companies are finding it increasingly difficult to ensure they know who they’re actually talking to during online meetings. We’re seeing the damage cybercriminals can cause when they steal credentials using social engineering, only to then bypass outdated MFA systems to access critical data or deploy ransomware. These older MFA systems just aren’t cutting it anymore, leaving companies vulnerable in ways that are making the news almost daily.

Kevin Surace
4 minute read

Enhancing Security with Seamless Integration: The Power of Duo & Token

In the ever-evolving landscape of cybersecurity, the partnership between Duo and Token marks a significant advancement, combining Duo's identity access management with Token's identity assurance. This collaboration is not just about adding layers of security; it's about redefining the user experience and streamlining the deployment of security measures across organizations.

John Gunn, CEO, Token
2 minute read
Biometric Authentication Methods

Why Biometric Authentication on Your Users' BYOD Devices Is Not Enough

From the perspective of someone responsible for securing an enterprise organization, the inclusion of biometric recognition capabilities in PCs and phones has been a positive development. The draw of using biometrics for recognition is that most are suitably unique and entropic, such that the biometric will more secure than a short passcode or easily-remembered password. Furthermore, biometric verification systems are viewed by most as being intuitive and convenient to use. In this way, biometric verification as the way users authenticate themselves to their devices has reduced a large attack surface for organizations whose employees work remotely or in hybrid environments. At first glance, one biometric authenticator may seem as secure as another. Users might feel secure using the fingerprint scanner on their Windows laptop, and the experience may be similar across different devices. However, the security and effectiveness of biometric systems vary significantly. This blog will explore the differences between fingerprint authentication built into popular PCs and next-generation biometric multifactor authenticators, highlighting vulnerabilities and how advanced solutions, such as these, provide the expected security and convenience.

Evan Krueger, VP Product
4 minute read
Ransomware Protection with MFA

Ransomware Protection Services: The Role of Biometric Identity Assurance

We were recently honored to be invited for an interview by Chuck Harold from SecurityGuyTV. During this discussion, our CEO, John Gunn, shared insights about protecting against ransomware with Token’s innovative biometric identity assurance smart ring, TokenCore™ Wearable. With ransomware attacks continuing to dominate the cybersecurity landscape, Token’s approach offers a promising solution that could revolutionize how we protect ourselves from these threats.

John Gunn, CEO, Token
2 minute read
MFA Solutions and Trends

Multi-Factor Authentication Solutions: What Top CISOs Say

Discover how top security leaders are integrating advanced IAM and MFA strategies to protect against emerging threats and ensure every user's credentials are protected against breaches.

John Gunn, CEO, Token
2 minute read
Fast Company - World Changing Ideas - Protection against Ransomware

Token Wins Fast Company’s World Changing Ideas 2024 Award. It Stops Ransomware

In an era where cyber threats are becoming increasingly sophisticated, Token’s biometric identity assurance stands out as a beacon of innovation. Recently, this groundbreaking device earned a prestigious spot in the Science and Technology category of Fast Company's 2024 World Changing Ideas Awards. With over 1,300 global entries vying for recognition, Token's achievement is a testament to its transformative impact on cybersecurity.

John Gunn, CEO, Token
2 minute read

Modern Identity Security in the Age of Gen AI and Mega-Breaches

Watch Webinar In today's rapidly evolving cyber landscape, identity security is more critical than ever. As organizations face growing threats like data breaches and ransomware attacks, the role of identity and access management (IAM) has never been more vital. In a recent webinar, "The Increasing Importance of Identity Security in the Era of the Mega Breach," John Gunn, CEO of Token, and Jon Lehtinen, Senior Director of Security at Okta, shared their insights on the current state of identity security, key trends driving these threats, and practical steps for organizations to enhance their defenses.

John Gunn, CEO, Token
2 minute read
cyber incidents and ramsomware

Crucial Cybersecurity Insights from Harvard Business Review

In a landscape where cybersecurity threats are ever-present, informed awareness is key. To support this need for ongoing education, we're making available a notable article from the Harvard Business Review, "The Devastating Business Impacts of a Cyber Breach," as a complimentary resource.

John Gunn, CEO, Token
1 minute read
2024 Cybersecurity To-Do List

Cybersecurity Strategy and Insights for the Year Ahead

Webcast Recording As we step into 2026, the cybersecurity landscape presents new challenges and evolving threats. In a recent webcast with Wolfgang Goerlich, Advisory CISO at Cisco, we delved into the crucial task of prioritizing cybersecurity initiatives for the year. This conversation highlighted the need for strategic planning in AI integration, combating phishing, navigating regulatory changes, and securing adequate budgets.

John Gunn, CEO, Token
1 minute read
new SEC cybersecurity rules

Navigating the New SEC Cybersecurity Rules

Cyber incidents and losses escalate every year and the impact on every organization can range from significant to crippling. With the average cost from a data breach in the U.S. now approaching $10 million and losses in market value for victim companies sometimes exceeding $100 million, it was time for the U.S. Securities and Exchange Commission (SEC) to introduce robust cybersecurity rules for public companies. This was an obvious necessity to protect investors and the integrity of U.S. securities markets. As a C-level executive or person with responsibility for cybersecurity, understanding these rules is crucial for remining in compliance with the new regulations, maintaining a strong security posture, and the financial health of your organization.

John Gunn, CEO, Token
2 minute read

SSO Meets Identity Assurance: Announcing the miniOrange TokenCore™ Partnership

2023 marks a pivotal time in cybersecurity. The back and forth escalation between cybercriminals and security professionals has surpassed legacy MFA strategies, and each year the need for stronger authentication solutions becomes more clear. Losses to data breaches and ransomware attacks are at an all-time high, doubling the last two years in a row. The average loss reached $9.44 million per incident, and an increasing number of organizations do not survive a ransomware attack.

John Gunn, CEO, Token
2 minute read

Stay Identity Assured

Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.