Cybersecurity Alert: Key Insights from Ontinue’s 2H 2024 Threat Intelligence Report
As Ransomware Tactics Shift, Your Security Strategy Must Too – The Economics of Cybercrime
Ransomware attacks jumped 132% while payments fell 35%, and vishing spiked 1,633%. For a Houston business, the report is a then-vs-now map of where the risk moved in the second half of 2024.
The Ontinue 2H 2024 Threat Intelligence Report is a second-half-2024 snapshot from Ontinue's Advanced Threat Operations team that documents how attackers shifted from forcing their way into networks to logging in with stolen credentials, with ransomware volume up 132% and voice-phishing detections up 1,633%.
Reports like this one matter to a Houston business owner for one reason: they tell you where the risk moved, not just that risk exists. Ontinue released the report in March 2025, covering the second half of 2024 and early Q1 2025. The headline is a reversal of assumptions. Fewer victims paid ransoms, yet more got hit. Email filters caught more phishing, so attackers picked up the phone. This piece lines up the 2H-2024 findings by category so you can see the then-versus-now picture and decide what your own defenses need to catch.
What Changed Between the Old Threat Model and the Ontinue 2H 2024 Findings?
Same categories, moved goalposts. The report reads best as a side-by-side of what the threat used to look like and what it looks like now.
The Ontinue 2H 2024 Threat Intelligence Report describes a set of category shifts: ransomware traded payout size for attack volume, phishing traded the inbox for the phone, and malware delivery traded email attachments for browser extensions and paid ads.
| Threat category | The old pattern (then) | Ontinue 2H 2024 (now) |
|---|---|---|
| Ransomware | Fewer, larger attacks aimed at big payouts; total payments climbing. | Attack volume up 132% while payments fell 35%, from $1.25B (2023) to $813.5M (2024). More attacks, smaller takes. |
| Initial access | Exploit a vulnerability to break into the network. | Steal the login. Adversary-in-the-middle phishing became the dominant way to grab session tokens and skip MFA. |
| Phishing channel | Malicious email links and attachments. | Voice phishing surged 1,633%, using AI voice cloning to bypass email filters entirely. |
| Malware delivery | Attachments and macro-laden documents. | Information-stealing browser extensions and malvertising that survive a system reimage. |
| Tooling | Custom malware that antivirus can flag. | Built-in Microsoft tools like Quick Assist and Windows Hello abused to blend in with normal activity. |
None of these categories are new. What the report shows is the direction each one moved in the second half of 2024, and every arrow points the same way: toward blending in. A stolen session token, a cloned voice, a trusted admin tool. Each one looks legitimate to a defense built to spot the obviously malicious. That is the practical warning for a Katy or Houston business running yesterday's checklist.
Would a Stolen Login Get Caught on Your Network?
Most Houston SMBs still defend the front door and miss the valid credential walking through it. A CinchOps review shows where you sit against the 2H-2024 threat model.
Get a Security ReviewWhy Did the Report Call Identity the New Front Line?
The single biggest theme in 2H 2024 was token theft: attackers grabbing a valid session instead of cracking a password.
Adversary-in-the-middle phishing, or AiTM, is an attack where a malicious proxy sits between the user and a real login page, captures the session token after the user completes MFA, and replays that token to log in as the user without ever needing the password again.
The report names AiTM as the dominant threat of the second half of 2024, and the reason is that it defeats the control most businesses lean on. Multi-factor authentication stops a stolen password. It does not stop a stolen session. Once an attacker holds a valid token, the login looks exactly like the real employee. Ontinue's team saw this paired with several supporting tactics:
- Legitimate services as bait. Attackers staged initial landing pages on trusted platforms, then redirected victims to the credential-harvesting proxy so the first click looked safe.
- Voice phishing at scale. Vishing detections rose 1,633% quarter over quarter, using AI-cloned voices to impersonate executives and IT staff and bypass email security completely.
- Living off Microsoft's own tools. Quick Assist (remote help) and Windows Hello (authentication) were abused to gain access and operate quietly, because a built-in tool rarely trips an alarm.
- Password spray on Entra ID. Ontinue's top detections included password-spray attacks against Microsoft Entra ID, the identity service most Houston SMBs now run on.
Put together, these findings say the perimeter moved. It is no longer the firewall at the edge of your office; it is the identity of every person who can log in. That is a different thing to defend, and most small businesses have not caught up to it.
Identity Is a Service You Can Actually Staff Out
CinchOps builds phishing-resistant MFA, conditional-access rules, and identity monitoring into managed security for Houston-area SMBs, so a stolen token or a Quick Assist abuse gets flagged instead of blending in. It is part of our cybersecurity and managed IT services.
Explore CinchOps cybersecurity →If Ransom Payments Dropped, Why Did Attacks Go Up?
The economics inverted. Fewer victims paid, so groups ran more operations to make up the difference.
The Ontinue 2H 2024 report found ransomware attacks rose 132% while total ransom payments fell 35%, from $1.25 billion in 2023 to about $813.5 million in 2024, which means each attack earned less on average and groups compensated by attacking far more often.
More defenders refused to pay, better backups meant fewer businesses had to, and law enforcement disrupted several major groups. So the per-attack payout shrank. The response was volume. That changes the math for a smaller business in a way worth stating plainly: a lower average payout does not make you safer if the number of attacks more than doubled. The report's firmographic and sector findings sharpen the point:
- Smaller organizations reported more incidents than large enterprises. Firms under 50 employees logged more ransomware incidents than companies with 1,000-plus staff, because they are easier to reach and less likely to be defended.
- Manufacturing, services, and healthcare stayed the top targets. Sectors with low downtime tolerance and older systems keep drawing the most attention, which maps directly onto Houston's industrial and energy base.
- Critical infrastructure moved up the list. Attackers leaned toward targets where the stakes, and the pressure to pay, run higher, including operational technology and edge devices.
For a Houston SMB, the takeaway is that "we are too small to be a target" was already wrong, and the 2H-2024 numbers make it wronger. The volume shift means the small manufacturer in Cypress is now squarely inside the pool, not adjacent to it.
How CinchOps Helps Houston Businesses Act on the 2H 2024 Findings
CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, with the security stack and local support to turn a threat report's findings into working defenses.
CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. A report tells you where the threat moved; keeping pace with it is the part most SMBs cannot staff alone:
- Phishing-resistant identity. We deploy MFA that resists token theft, conditional access, and monitoring on Microsoft Entra ID, directly answering the AiTM and password-spray findings.
- Ransomware resilience. Tested backups, endpoint detection and response, and segmentation so a breach does not become a shutdown, built for the higher attack volume the report documents.
- Tool-abuse detection. We watch for misuse of Quick Assist, Windows Hello, and PowerShell, the exact living-off-the-land tactics Ontinue flagged.
- Staff training against vishing. We teach your team to verify a voice request out of band, the human control that beats an AI-cloned call.
The businesses that stay ahead treat a threat report as a to-do list, not a headline. If you run a company in Houston or Katy and your defense is still built around the perimeter instead of the login, talk to CinchOps and we will close the gap the 2H-2024 report just mapped for you.
Every threat report I have read in 35 years eventually says the same thing a year early, and this one nailed it: the attacker is not kicking your door in anymore, they are walking through it with a key they stole. If your whole security plan still guards the door and ignores the key, you are defending last year's attack.
Frequently Asked Questions
What is the Ontinue 2H 2024 Threat Intelligence Report?
It is a second-half-2024 threat analysis from Ontinue's Advanced Threat Operations team, released in March 2025. It documents how attackers shifted from breaking into networks to logging in with stolen credentials, and reports ransomware attacks up 132%, payments down 35%, and vishing detections up 1,633%.
Why did ransomware attacks rise while payments fell?
The report found attacks rose 132% while total payments dropped 35%, from $1.25 billion in 2023 to about $813.5 million in 2024. Fewer victims paid, thanks to better backups and law enforcement, so groups ran far more attacks to make up the lost revenue per victim.
What is adversary-in-the-middle phishing?
AiTM phishing places a malicious proxy between a user and a real login page. It captures the session token after the user completes MFA, then replays that token to log in as the user. The Ontinue 2H 2024 report named it the dominant token-theft method of the period.
Why did the report highlight voice phishing?
Vishing detections rose 1,633% quarter over quarter because attackers used AI voice cloning to impersonate executives and IT staff. A phone call bypasses email security filters entirely, so it reaches employees that a blocked malicious email never would, making verification training essential.
What does the report mean for a Houston small business?
Smaller firms reported more ransomware incidents than large enterprises, and manufacturing and healthcare stayed top targets, sectors common across Houston. The practical response is phishing-resistant MFA, tested backups, and staff trained to verify voice requests, delivered through managed security that keeps pace with attackers.
Discover More
Sources
- Ontinue, "Research Reveals Ransomware Attacks Surged 132% Despite 35% Drop in Payments" (2H 2024 Threat Intelligence Report), March 2025
- Ontinue, 2H 2024 Threat Intelligence Report - findings and full report
- Security Magazine, "Ransomware incidents increase by 132%, vishing by 1,633%," 2025
- BleepingComputer, "Ransomware payments fell by 35% in 2024, totalling $813,550,000" (Chainalysis data), 2025