Threat Brief – Unit 31 | Ransomware Intelligence Report
Ransomware: A Business Crisis, Not Just a Cyber Risk
Ransomware attacks continue to escalate in frequency and impact, targeting businesses of all sizes across Greece and beyond. In 2024 alone, Greek organisations in shipping, retail, education, and media suffered breaches involving both operational shutdown and sensitive data leaks.
This edition of the Threat Brief, prepared by Unit 31, distils intelligence on three leading ransomware groups: LockBit, Akira, and Play. These actors are responsible for a significant share of global attacks and are actively targeting Greek companies today.
What makes these threats especially dangerous is the combination of data theft with system encryption, known as double extortion. Even organisations with strong backups are now facing public data leaks and reputational fallout.
This report outlines:
- How each ransomware group operates
- What to expect during an incident
- Business-level consequences of a successful breach
- Executive mitigation actions
Ransomware is no longer a distant risk. It is a present operational threat. Preparedness is no longer optional.
The Current Landscape
Ransomware continues to dominate the threat landscape in 2025. While the underlying extortion model remains familiar, the scale, stealth, and speed of recent operations have shifted significantly.
- Attackers now operate with professional infrastructure and dedicated affiliate networks.
- Double extortion has become the norm: encryption is only part of the damage.
- Data exfiltration, publication threats, and even direct contact with executives are now standard tactics.
In Greece, ransomware activity has sharply increased. Attacks have impacted universities, retail groups, shipping firms, and more. Victims have faced:
- Prolonged downtime
- Public exposure of stolen data
- High-stakes ransom negotiations
- Operational disruption during peak business cycles
The techniques may differ across threat actors, but the playbook is increasingly precise.
This edition of the Threat Brief breaks down the strategies and operations of three of the most active ransomware groups right now: LockBit, Akira, and Play.
Threat Actor Profile: LockBit
Overview
LockBit remains the most prolific ransomware group in the global threat landscape. Operating under a Ransomware-as-a-Service (RaaS) model, the group supplies malware and infrastructure to affiliates in exchange for a percentage of the ransom.
Since 2019, LockBit has evolved through multiple iterations (LockBit 2.0, 3.0, Green) and has been responsible for thousands of attacks worldwide.
Key Characteristics
- RaaS infrastructure: Enables wide distribution through affiliates.
- Double extortion: Combines data encryption with exfiltration.
- StealBit tool: Used for rapid automated data theft.
- Target range: Public sector, healthcare, critical infrastructure, education, and finance.
Activity Snapshot
- Linked to over 1,700 confirmed incidents globally (2020–2023).
- Estimated to have extorted over 90 million USD from US organisations alone.
- Identified in multiple high-impact attacks in Greece, including a media company and a national IT services provider.
Tactics
- Exploits known vulnerabilities and misconfigured systems.
- Frequently uses purchased credentials from Initial Access Brokers.
- Often deploys malware quickly after exfiltration, aiming for maximum business disruption.
Resilience
Despite law enforcement takedowns of infrastructure in early 2024, LockBit re-emerged within weeks. Its decentralised affiliate model makes it difficult to fully dismantle.
Why It Matters
LockBit’s scale, adaptability, and commercial structure make it one of the most dangerous threats to Greek and international organisations. Even mid-sized enterprises are viable targets.

Threat Actor Profile: Akira
Overview
Akira is a rapidly growing ransomware group that has gained traction since its emergence in early 2023. Despite its relatively recent arrival, the group has demonstrated advanced tactics and a high level of operational maturity.
Akira is believed to run a hybrid model, offering a RaaS platform while also executing attacks directly.
Key Characteristics
- Double extortion: Encrypts systems and threatens to leak public data.
- Branding: Operates a stylised leak site with cyberpunk visuals.
- Cross-platform: Initially targeted Windows, but expanded to Linux/VMware.
- Sophistication: Believed to use retooled methods from earlier campaigns.
Activity Snapshot
- Credited with over 250 attacks globally in its first year.
- Generated an estimated 42 million USD in ransom payments.
- Targeted a growing number of Greek firms, including maritime and manufacturing companies.
Tactics
- Uses phishing and compromised credentials for initial access.
- Maintains stealth during intrusion using admin tools and scripts.
- Prioritises rapid data theft followed by widespread encryption.
Regional Focus
Akira expanded into the Greek threat landscape during late 2024. At least two local organisations were publicly listed on its leak site. The group’s aggressive tactics and increasing visibility signal an expanding footprint across Europe.
Why It Matters
Akira exemplifies how new actors can scale quickly using proven playbooks. For executive leaders, it reinforces the need to monitor not just known groups but also fast-emerging threats capable of significant disruption.

Threat Actor Profile: Play
Overview
Play, also known as PlayCrypt, is a ransomware group that has operated under the radar yet caused widespread damage since mid-2022. Unlike larger affiliate-driven operations like LockBit, Play is believed to be a more closed and tightly coordinated group.
Its campaigns are marked by precision, stealth, and technical depth.
Key Characteristics
- Intermittent encryption: Encrypts only parts of files to evade detection.
- Minimalist ransom notes: Provide no payment amount; victims must initiate contact.
- Aggressive extortion: Known to call victims directly to escalate pressure.
Activity Snapshot
- Linked to over 900 ransomware incidents globally by mid-2025.
- Victims span North and South America, Europe, and critical infrastructure sectors.
- In Greece, Play was responsible for a 2024 ransomware attack against Eurobulk Ltd., highlighting its maritime focus.
Tactics
- Leverages known software vulnerabilities, especially in VPNs and remote access tools.
- Uses intermittent encryption to accelerate impact and avoid triggering alarms.
- Steals data before encryption and publishes it via a Tor-based leak site.
Regional Focus
Play has been active in targeting European organisations across manufacturing, shipping, and services. Its presence in the Greek threat landscape, particularly within maritime, signals a sustained interest in vulnerable logistics infrastructure.
Why It Matters
Play’s tactics combine stealth with pressure. The group’s ability to remain active across multiple industries while avoiding immediate detection highlights the need for improved early warning systems and layered defences.

How a Ransomware Attack Unfolds
From entry to extortion: understanding the attacker’s playbook
Ransomware groups follow a structured, repeatable process to maximise impact and pressure. Each stage is designed to delay detection, cripple operations, and corner leadership into paying. The lifecycle below outlines how most attacks evolve.
1. Initial Intrusion
Attackers need a foothold. This first step is about quietly breaching the perimeter. They exploit common weaknesses such as:
- Unpatched internet-facing services (e.g., VPNs, RDP)
- Phishing emails with malicious attachments or links
- Unpatched internet-facing services (e.g., VPNs, RDP)
- Leaked credentials bought from initial access brokers
Access is often sold, not stolen. Many attackers skip the intrusion phase entirely by purchasing pre-compromised access from third-party criminals.
2. Establishing a Foothold
Once inside, attackers move carefully. They aim to stay undetected for as long as possible. They often:
- Deploy legitimate administrative tools to blend in
- Install remote access trojans or backdoors
- Escalate privileges and move laterally across systems
- Conduct reconnaissance to locate high-value assets
This phase can last from days to weeks. The goal is to prepare the environment for mass disruption.
3. Data Exfiltration
Before encryption begins, data is silently stolen.
Why? It creates leverage. If the ransom is not paid, the stolen data can be exposed or sold. This double-extortion method has become standard. Key targets include:
- Financial records
- Customer and employee data
- Strategic documents and intellectual property
- Legal or regulatory files
According to multiple industry sources, over 90% of ransomware attacks now involve data exfiltration before encryption is triggered.
4. Encryption and Outage
Now the visible damage begins. Files and systems are locked, and business operations grind to a halt. This step typically involves:
- Encryption of endpoints, servers, and databases
- Disabling of security tools or backups
- Halting of operations such as email, ERP, CRM, or cloud storage
Even unaffected systems are often taken offline as a precaution. The attackers want to create urgency, confusion, and business paralysis.
5. Ransom Demand
With systems locked and data stolen, the extortion begins. Victims are usually greeted with a ransom note that includes:
- A link to initiate contact (typically via Tor)
- Payment instructions in cryptocurrency
- A warning: failure to pay will result in public data leaks
Some attackers go further. They call executives, email customers, or leak sample data to increase pressure.
6. Extortion and Negotiation
Once contact is made, negotiations begin. This is a business transaction for the criminals. Common tactics include:
- Setting high initial prices, then “offering discounts”
- Providing a test decryption file as proof
- Offering deletion of stolen data as part of the deal
There is no honour among thieves. Law enforcement investigations into groups like LockBit have shown that attackers often keep stolen data, even after victims pay.
Some groups re-exploit the same victim months later using the same stolen files.
7. Recovery or Remediation
Whether the ransom is paid or not, the road to recovery is long. Key challenges include:
- Full infrastructure from trusted backups
- Digital forensics to determine what was accessed or stolen
- Legal and regulatory reporting
- Communication with clients, partners, and staff
Paying the ransom does not guarantee quick recovery. Decryption tools are often flawed or incomplete. Many organisations still face days or weeks of downtime.
- Critical disruption: Booking systems, vessel tracking, port logistics, ERP platforms, and finance tools become inaccessible.
- Real-world cases: A Greek hospital reverted to handwritten procedures following an attack. A major logistics company lost days of revenue after a ransomware incident froze customs processing.
- Crisis escalation: Even networks untouched by the malware are often taken offline proactively, intensifying disruption.
Downtime is not just an IT issue. It affects revenue, customers, and supply chains. Most firms are unprepared for a prolonged shutdown. And every hour of inaction compounds the impact.

Why Ransomware Is a Boardroom Issue
Ransomware is no longer a technical nuisance. It is a strategic threat with the power to disrupt operations, expose sensitive data, trigger regulatory scrutiny, and erode brand trust. For maritime executives, it directly threatens continuity, compliance, and commercial resilience.
1. Operational Paralysis
The most immediate impact is downtime. When core systems are encrypted, business stops.
- Critical disruption: Booking systems, vessel tracking, port logistics, ERP platforms, and finance tools become inaccessible.
- Real-world cases: A Greek hospital reverted to handwritten procedures following an attack. A major logistics company lost days of revenue after a ransomware incident froze customs processing.
- Crisis escalation: Even networks untouched by the malware are often taken offline proactively, intensifying disruption.
Downtime is not just an IT issue. It affects revenue, customers, and supply chains. Most firms are unprepared for a prolonged shutdown. And every hour of inaction compounds the impact.
2. Data Breach Exposure
Nearly all modern ransomware attacks involve data exfiltration before encryption. This makes every incident a potential breach.
- Leaked data: Client records, contracts, financials, maritime logs, procurement files, even personal IDs.
- Double extortion: Threat actors demand payment to avoid public leaks, with data often dumped on dark web forums if ignored.
- Reputational impact: Customers, investors, and strategic partners lose trust when sensitive information is exposed.
In one university attack in Greece, hundreds of gigabytes of research, financial, and student data were leaked. That breach had long-lasting effects on institutional credibility.
3. Legal, Regulatory & Compliance Risks
For organisations subject to GDPR, NIS2, IMO 2021, and other frameworks, ransomware triggers mandatory response actions.
- Mandatory breach reporting under GDPR and national cyber legislation.
- Risk of regulatory audits, especially if outdated systems or poor controls contributed to the breach.
- Legal exposure: Affected clients or employees may seek legal remedies if personal data is leaked.
Failing to respond swiftly and transparently can increase penalties. Legal teams must often coordinate with IT and communications in high-pressure environments. For the board, this is a governance challenge.
4. Financial Impact
The financial fallout from ransomware extends far beyond ransom payments.
- Recovery costs: Incident response teams, forensic analysts, legal counsel, PR firms, and security consultants.
- Loss of revenue: Business interruption during downtime, especially if operations are customer-facing.
- Insurance gaps: Some cyber insurance providers have begun limiting ransomware coverage or increasing premiums after incidents.
- Market confidence: Listed companies often see a share price impact. M&A deals may be delayed or reconsidered post-breach.
According to the IBM Cost of a Data Breach Report 2024, the average breach in transportation now costs USD 4.45 million.
5. Reputational Harm
Cyberattacks are high-visibility events. Even when handled quietly, they often become public.
- Brand perception declines: Customers lose trust, stakeholders ask hard questions.
- Media scrutiny increases: Leaked data, failed backups, or ransom payments draw attention.
- Leadership accountability: Boards demand answers. In some cases, C-level executives step down post-incident.
In the maritime sector, where operational trust is paramount, a cyber incident can damage commercial relationships and competitive positioning for years.
Final Word: From Reaction to Readiness
Ransomware is not slowing down. It is evolving, professionalising, and targeting sectors like maritime with growing precision.
The organisations that weather these attacks best are those that prepare in advance. Not with generic policies, but with realistic drills, tested backups, strong access controls, and board-level ownership of cyber risk.
The difference between a disruption and a disaster often comes down to one factor: how well-prepared you were before the breach.
If your organisation has not yet mapped its ransomware exposure or tested how it would respond, now is the time to act.
Next Step: Simulate Before It’s Real
ThreatScene’s cyber resilience team runs real-world simulations for maritime operators, logistics firms, and critical infrastructure providers across Europe. These are not generic tabletop exercises: they are mapped to your operational environment and risk profile.
Book a consultation with our team to evaluate your ransomware readiness and pressure-test your defences.
Stay ready. Stay resilient. Stay operational.
Curated with purpose, delivered with precision — UNIT 31 | ThreatScene.

Sources:
https://www.cisecurity.org/insights/blog/ransomware-the-data-exfiltration-and-double-extortion-trends
https://medium.com/@s.lontzetidis/greeces-2024-cyber-threat-landscape-trends-and-predictions-4015a1f0fbbc
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a#:~:text=continues%20to%20be%20prolific%20in,This
https://securitydelta.nl/news/overview/law-enforcement-disrupt-lockbit-world-s-biggest-ransomware-operation#:~:text=LockBit%20is%20widely%20recognised%20as,level%20by%20Europol%20and%20Eurojust
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a#:~:text=In%202022%2C%20LockBit%20was%20the,the%20operation%2C%20LockBit%20ransomware%20attacks
https://therecord.media/akira-ransomware-group-publishes-unprecedented-leak-data
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a#:~:text=April%202023%2C%20following%20an%20initial,USD%29%20in%20ransomware%20proceeds
https://www.checkpoint.com/cyber-hub/threat-prevention/ransomware/play-ransomware-group-detection-and-protection/#:~:text=Play%20ransomware%2C%20also%20known%20as,company%20data%20and%20threaten%20businesses


