Ransomware operators jack up their ransom demands by a factor of 2.8x if they detect a victim has cyber-insurance, a study highlighted by the Netherlands government has confirmed. For his PhD thesis [PDF], defended in January, Dutch cop Tom Meurs looked at 453 ransomware attacks between 2019 and 2021. He found one of the first actions intruders take is to search for documents with the keywords “insurance” and “policy.” If the crooks find evidence that the target has a relevant policy, the ransom more than doubles on average. … Meurs said, of the intrusions he looked into, those with insurance paid the criminals 44 percent of the time, compared to 24 percent of the uninsured. In addition, insured victims paid a lot more – an average of €708,105 ($800,000, £600,000), compared to €133,016 ($150,000, £110,000) for their uninsured brethren. Phishing emails with links were the most common point of infection, accounting for a third of successful attacks, with spam accounting for eight percent. Malicious mobile apps are also an important vector, accounting for 13 percent of successful infections, and one in ten attacks was down to poorly patched applications or operating systems. By far, the retail and wholesale trades were most likely to get hit, accounting for nearly 33 percent of reported infections in the data set, with an average payout of €112,793 ($130,000, £100,000). The IT sector is less popular but much more profitable, accounting for 14.7 percent of attacks but with the highest average payout of the top ten trades covered at €268,039 ($300,000, £230,000) – which makes them a very attractive target for criminals. …