https://www.reuters.com/article/us-cyber-cwt-ransom/payment-...
US travel firm $4.5M ransom negotiation open chat
31–40 of 480 posts
Re: US travel firm $4.5M ransom negotiation open chat
#32For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…
I wouldn't be surprised if they genuinely would have trouble coughing up 10 million two days after the attack hit.
Re: US travel firm $4.5M ransom negotiation open chat
#33So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.
Take backups, practice restoring them, invest in a security program.
You really need comprehensive, air-gapped backups that date to years back.
Re: US travel firm $4.5M ransom negotiation open chat
#34It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
Our current legal framework doesn’t support such a draconian suggestion as presented imho.
You want poor security practices to be painful, not fatal, to the corporate entity.
Re: US travel firm $4.5M ransom negotiation open chat
#35Re: US travel firm $4.5M ransom negotiation open chat
#36They're not out of the woods yet. Whats the bet they get crypto locked again next week?
Re: US travel firm $4.5M ransom negotiation open chat
#37It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
Re: US travel firm $4.5M ransom negotiation open chat
#38Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…
To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claimi…
The kidnapping analogy makes for a better understanding of why paying ransoms is bad for everybody else. If kidnappers know, or really just think, that they’ll get paid, they’re more likely to kidnap and hold hostages.
It’s not that companies are not solely responsible for their own lax security policies. It’s that incentivizing the exploiting of them is bad for society.
Re: US travel firm $4.5M ransom negotiation open chat
#39It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
Maybe require cyber insurance instead, pricing premiums based on audits performed by infosec practitioners. Similar to auto insurance, and what happens when you’re a high risk driver; you still have insurance, but you’re paying out the nose for it. Our current legal framework doesn’t support such a draconian suggestion as presented imho. You want poor security practices to be painful, not fatal, to the corporate enti…
Re: US travel firm $4.5M ransom negotiation open chat
#40While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly.
I don’t support these attacks and some of the targets in particular are insidious, like hospitals where an attack could lead to an actual death toll, but it might actually be the kick in the ass many organizations need to actually care.
It’s sad that it’s come to this point but the end result may be better for everyone.