CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise IT Services & Support in Houston, TX
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Managed IT Houston Cybersecurity
Shane
Shane March 27th, 2025

Cybersecurity Alert: Key Insights from Ontinue’s 2H 2024 Threat Intelligence Report

As Ransomware Tactics Shift, Your Security Strategy Must Too – The Economics of Cybercrime

Cybersecurity Alert
What Did the Ontinue 2H 2024 Threat Intelligence Report Actually Change? Attackers Stopped Breaking In and Started Logging In.

Ransomware attacks jumped 132% while payments fell 35%, and vishing spiked 1,633%. For a Houston business, the report is a then-vs-now map of where the risk moved in the second half of 2024.

TL;DR
The Ontinue 2H 2024 Threat Intelligence Report found ransomware attacks rose 132% even as total ransom payments dropped 35%, from $1.25 billion in 2023 to about $813.5 million in 2024. Attackers pivoted from smash-and-grab to stealing logins: adversary-in-the-middle phishing became the dominant token-theft method, vishing detections spiked 1,633%, and criminals abused built-in Microsoft tools like Quick Assist and Windows Hello. For Houston SMBs the shift is simple to read. The old threat was a locked door being forced. The new threat is a valid credential walking straight through it.
📊 Then vs Now 🔑 The Login Shift 💰 Ransomware Economics 🚀 How CinchOps Helps

The Ontinue 2H 2024 Threat Intelligence Report is a second-half-2024 snapshot from Ontinue's Advanced Threat Operations team that documents how attackers shifted from forcing their way into networks to logging in with stolen credentials, with ransomware volume up 132% and voice-phishing detections up 1,633%.

Reports like this one matter to a Houston business owner for one reason: they tell you where the risk moved, not just that risk exists. Ontinue released the report in March 2025, covering the second half of 2024 and early Q1 2025. The headline is a reversal of assumptions. Fewer victims paid ransoms, yet more got hit. Email filters caught more phishing, so attackers picked up the phone. This piece lines up the 2H-2024 findings by category so you can see the then-versus-now picture and decide what your own defenses need to catch.

The core shift: the report's throughline is that a valid login has become more valuable to an attacker than an exploit. When the credential is the key, your firewall is no longer the front door.

What Changed Between the Old Threat Model and the Ontinue 2H 2024 Findings?

Same categories, moved goalposts. The report reads best as a side-by-side of what the threat used to look like and what it looks like now.

The Ontinue 2H 2024 Threat Intelligence Report describes a set of category shifts: ransomware traded payout size for attack volume, phishing traded the inbox for the phone, and malware delivery traded email attachments for browser extensions and paid ads.

Threat categoryThe old pattern (then)Ontinue 2H 2024 (now)
RansomwareFewer, larger attacks aimed at big payouts; total payments climbing.Attack volume up 132% while payments fell 35%, from $1.25B (2023) to $813.5M (2024). More attacks, smaller takes.
Initial accessExploit a vulnerability to break into the network.Steal the login. Adversary-in-the-middle phishing became the dominant way to grab session tokens and skip MFA.
Phishing channelMalicious email links and attachments.Voice phishing surged 1,633%, using AI voice cloning to bypass email filters entirely.
Malware deliveryAttachments and macro-laden documents.Information-stealing browser extensions and malvertising that survive a system reimage.
ToolingCustom malware that antivirus can flag.Built-in Microsoft tools like Quick Assist and Windows Hello abused to blend in with normal activity.

None of these categories are new. What the report shows is the direction each one moved in the second half of 2024, and every arrow points the same way: toward blending in. A stolen session token, a cloned voice, a trusted admin tool. Each one looks legitimate to a defense built to spot the obviously malicious. That is the practical warning for a Katy or Houston business running yesterday's checklist.

ONTINUE 2H 2024: HOW THE THREAT MOVED +132% Ransomware attacks more attacks, not bigger ones -35% Ransom payments $1.25B down to $813.5M +1,633% Vishing detections AI voice cloning, no email needed The pivot in one line Attackers moved from breaking in (exploit a flaw) to logging in (steal the credential). Adversary-in-the-middle phishing became the dominant token-theft method in 2H 2024. CinchOps · cinchops.com · Source: Ontinue 2H 2024 Threat Intelligence Report; payment figures via Chainalysis
The Ontinue 2H 2024 findings as a then-vs-now shift. Sources: Ontinue Advanced Threat Operations; ransom-payment totals from Chainalysis.

Would a Stolen Login Get Caught on Your Network?

Most Houston SMBs still defend the front door and miss the valid credential walking through it. A CinchOps review shows where you sit against the 2H-2024 threat model.

Get a Security Review

Why Did the Report Call Identity the New Front Line?

The single biggest theme in 2H 2024 was token theft: attackers grabbing a valid session instead of cracking a password.

Adversary-in-the-middle phishing, or AiTM, is an attack where a malicious proxy sits between the user and a real login page, captures the session token after the user completes MFA, and replays that token to log in as the user without ever needing the password again.

The report names AiTM as the dominant threat of the second half of 2024, and the reason is that it defeats the control most businesses lean on. Multi-factor authentication stops a stolen password. It does not stop a stolen session. Once an attacker holds a valid token, the login looks exactly like the real employee. Ontinue's team saw this paired with several supporting tactics:

  • Legitimate services as bait. Attackers staged initial landing pages on trusted platforms, then redirected victims to the credential-harvesting proxy so the first click looked safe.
  • Voice phishing at scale. Vishing detections rose 1,633% quarter over quarter, using AI-cloned voices to impersonate executives and IT staff and bypass email security completely.
  • Living off Microsoft's own tools. Quick Assist (remote help) and Windows Hello (authentication) were abused to gain access and operate quietly, because a built-in tool rarely trips an alarm.
  • Password spray on Entra ID. Ontinue's top detections included password-spray attacks against Microsoft Entra ID, the identity service most Houston SMBs now run on.

Put together, these findings say the perimeter moved. It is no longer the firewall at the edge of your office; it is the identity of every person who can log in. That is a different thing to defend, and most small businesses have not caught up to it.

Identity Is a Service You Can Actually Staff Out

CinchOps builds phishing-resistant MFA, conditional-access rules, and identity monitoring into managed security for Houston-area SMBs, so a stolen token or a Quick Assist abuse gets flagged instead of blending in. It is part of our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

If Ransom Payments Dropped, Why Did Attacks Go Up?

The economics inverted. Fewer victims paid, so groups ran more operations to make up the difference.

The Ontinue 2H 2024 report found ransomware attacks rose 132% while total ransom payments fell 35%, from $1.25 billion in 2023 to about $813.5 million in 2024, which means each attack earned less on average and groups compensated by attacking far more often.

More defenders refused to pay, better backups meant fewer businesses had to, and law enforcement disrupted several major groups. So the per-attack payout shrank. The response was volume. That changes the math for a smaller business in a way worth stating plainly: a lower average payout does not make you safer if the number of attacks more than doubled. The report's firmographic and sector findings sharpen the point:

  • Smaller organizations reported more incidents than large enterprises. Firms under 50 employees logged more ransomware incidents than companies with 1,000-plus staff, because they are easier to reach and less likely to be defended.
  • Manufacturing, services, and healthcare stayed the top targets. Sectors with low downtime tolerance and older systems keep drawing the most attention, which maps directly onto Houston's industrial and energy base.
  • Critical infrastructure moved up the list. Attackers leaned toward targets where the stakes, and the pressure to pay, run higher, including operational technology and edge devices.

For a Houston SMB, the takeaway is that "we are too small to be a target" was already wrong, and the 2H-2024 numbers make it wronger. The volume shift means the small manufacturer in Cypress is now squarely inside the pool, not adjacent to it.

RANSOMWARE: FEWER PAYERS, MORE ATTACKS Total ransom paid 2023 $1.25 billion 2024 $813.5 million (-35%) +132% attack volume, same period Under-50-employee firms reported more incidents than 1,000+ enterprises CinchOps · cinchops.com · Source: Ontinue 2H 2024 report; payment totals via Chainalysis
Lower payouts, higher volume: the ransomware economics the 2H-2024 report describes. Sources: Ontinue; Chainalysis payment data.

How CinchOps Helps Houston Businesses Act on the 2H 2024 Findings

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, with the security stack and local support to turn a threat report's findings into working defenses.

CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. A report tells you where the threat moved; keeping pace with it is the part most SMBs cannot staff alone:

  • Phishing-resistant identity. We deploy MFA that resists token theft, conditional access, and monitoring on Microsoft Entra ID, directly answering the AiTM and password-spray findings.
  • Ransomware resilience. Tested backups, endpoint detection and response, and segmentation so a breach does not become a shutdown, built for the higher attack volume the report documents.
  • Tool-abuse detection. We watch for misuse of Quick Assist, Windows Hello, and PowerShell, the exact living-off-the-land tactics Ontinue flagged.
  • Staff training against vishing. We teach your team to verify a voice request out of band, the human control that beats an AI-cloned call.

The businesses that stay ahead treat a threat report as a to-do list, not a headline. If you run a company in Houston or Katy and your defense is still built around the perimeter instead of the login, talk to CinchOps and we will close the gap the 2H-2024 report just mapped for you.

Every threat report I have read in 35 years eventually says the same thing a year early, and this one nailed it: the attacker is not kicking your door in anymore, they are walking through it with a key they stole. If your whole security plan still guards the door and ignores the key, you are defending last year's attack.
Shane Stevens, CEO, CinchOps - LinkedIn
100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

What is the Ontinue 2H 2024 Threat Intelligence Report?

It is a second-half-2024 threat analysis from Ontinue's Advanced Threat Operations team, released in March 2025. It documents how attackers shifted from breaking into networks to logging in with stolen credentials, and reports ransomware attacks up 132%, payments down 35%, and vishing detections up 1,633%.

Why did ransomware attacks rise while payments fell?

The report found attacks rose 132% while total payments dropped 35%, from $1.25 billion in 2023 to about $813.5 million in 2024. Fewer victims paid, thanks to better backups and law enforcement, so groups ran far more attacks to make up the lost revenue per victim.

What is adversary-in-the-middle phishing?

AiTM phishing places a malicious proxy between a user and a real login page. It captures the session token after the user completes MFA, then replays that token to log in as the user. The Ontinue 2H 2024 report named it the dominant token-theft method of the period.

Why did the report highlight voice phishing?

Vishing detections rose 1,633% quarter over quarter because attackers used AI voice cloning to impersonate executives and IT staff. A phone call bypasses email security filters entirely, so it reaches employees that a blocked malicious email never would, making verification training essential.

What does the report mean for a Houston small business?

Smaller firms reported more ransomware incidents than large enterprises, and manufacturing and healthcare stayed top targets, sectors common across Houston. The practical response is phishing-resistant MFA, tested backups, and staff trained to verify voice requests, delivered through managed security that keeps pace with attackers.

Discover More

CinchOps Cybersecurity Services
What Is MDR (Managed Detection and Response)?
Forescout 2025 H1 Threat Review
Sophos State of Ransomware 2025
2025 Cybersecurity Threats Demand Immediate Action
How to Prevent Phishing Attacks for Texas SMBs

Sources

  • Ontinue, "Research Reveals Ransomware Attacks Surged 132% Despite 35% Drop in Payments" (2H 2024 Threat Intelligence Report), March 2025
  • Ontinue, 2H 2024 Threat Intelligence Report - findings and full report
  • Security Magazine, "Ransomware incidents increase by 132%, vishing by 1,633%," 2025
  • BleepingComputer, "Ransomware payments fell by 35% in 2024, totalling $813,550,000" (Chainalysis data), 2025
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

October 10th, 2025
Managed Service Provider Houston Cybersecurity
How Machine Learning Detects Online Fraud: The LOKI System Innovation

Understanding Query Toxicity: A New Metric For Measuring Search Result Safety – How LOKI AI System Discovered 52,493 Hidden Scam Websites By Analyzing Search Queries

June 1st, 2026
Managed IT Houston
Claude for Small Business: AI Houston Owners Can Actually Run

A Practical Look At AI For Houston Companies – Setting Up Claude For Small Business The Right Way

February 19th, 2026
Construction IT
Managed IT Services for Houston Construction Companies

When Your Job Site Goes Dark, So Does Your Bottom Line – Managed IT Built Around How Construction Companies Actually Work

February 23rd, 2026
SMB Desk
Small Business IT Support Near Me in Sugar Land TX

Sugar Land’s Small Business IT Partner – Local IT Support That Actually Shows Up

May 16th, 2025
Managed IT Houston - Cybersecurity
BitLocker Encryption Bypassed in Minutes: The Bitpixie Attack

BitLocker Vulnerability Exposes Critical Flaw in Default Encryption Settings – 5 Minutes to Decrypt

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery for Houston Businesses
  • Cloud Services
  • Business Process Automation for Houston Businesses
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy