Live data from Hacker News

UCSF admits it paid NetWalker more than $1M ransom

databreaches.net

1–10 of 68 posts

Re: UCSF admits it paid NetWalker more than $1M ransom

#6

The poor IT guys there probably asked for a couple thousand for backups instead and were previously denied. Ransomeware first rose to prominence three years ago. Yet seemingly little has been learned?

Large compromises of sensitive data also have to consider the release of sensitive info, not just recovery. So even with backups there's an incentive to pay.

Re: UCSF admits it paid NetWalker more than $1M ransom

#8
post #5

Always been curious about the tax accounting for ransoms. Does anyone know how it is reported usually? Going public must make it harder I guess? How do you explain a bitcoin purchase from a business account without an invoice to the taxman otherwise?

It's a business expense like most others. In this case, it's considered theft, but you still can deduct it: https://www.forbes.com/sites/robertwood/2017/05/16/if-you-pa...

Re: UCSF admits it paid NetWalker more than $1M ransom

#9
Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

Re: UCSF admits it paid NetWalker more than $1M ransom

#10
post #6

The poor IT guys there probably asked for a couple thousand for backups instead and were previously denied. Ransomeware first rose to prominence three years ago. Yet seemingly little has been learned?

Large compromises of sensitive data also have to consider the release of sensitive info, not just recovery. So even with backups there's an incentive to pay.

Ah yes. NetWalker seems like a particularly bad variant as it does at least claim to steal the data.
Post reply on HN