For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…
US travel firm $4.5M ransom negotiation open chat
41–50 of 480 posts
Re: US travel firm $4.5M ransom negotiation open chat
#42Earlier quoted context omitted.
Maybe require cyber insurance instead, pricing premiums based on audits performed by infosec practitioners. Similar to auto insurance, and what happens when you’re a high risk driver; you still have insurance, but you’re paying out the nose for it. Our current legal framework doesn’t support such a draconian suggestion as presented imho. You want poor security practices to be painful, not fatal, to the corporate enti…
Our legal framework already contains many prohibitions on financial transactions with criminals and terrorists. It wouldn't be difficult to add one more.
Banning ransomware payments just makes it more difficult; someone will still find a way to save their business by paying. You want to resolve the root issue: a business not taking security seriously.
Re: US travel firm $4.5M ransom negotiation open chat
#43Earlier quoted context omitted.
But now you have $4 million in a bitcoin address linked to criminal activity. Then what? How much do you lose along the way to having laundered cash in hand?
Aren’t there mixer services for that or just convert to monero? This is off an exchange so lots of shenanigans to make things less traceable. I am guessing these people know what they are doing.
I hope.
Re: US travel firm $4.5M ransom negotiation open chat
#44For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…
I don't know about that. For one, travel margins are not exactly the same as SaaS margins. Secondly, there's the global pandemic and all, kinda hurts the free cash of most travel companies. I wouldn't be surprised if they genuinely would have trouble coughing up 10 million two days after the attack hit.
Re: US travel firm $4.5M ransom negotiation open chat
#45It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?
Re: US travel firm $4.5M ransom negotiation open chat
#46It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?
Re: US travel firm $4.5M ransom negotiation open chat
#47So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.
Continuous append-only backups, where one can't rewrite them without physical access to the system, would - most likely - help with a data loss, malicious or accidental.
Re: US travel firm $4.5M ransom negotiation open chat
#48It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
Re: US travel firm $4.5M ransom negotiation open chat
#49It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
Criminalizing ransoms will result in victims doing it in secret, not in the elimination of ransoms. People won't be able to share information, and the financial incentive will continue to exist.
Re: US travel firm $4.5M ransom negotiation open chat
#50Earlier quoted context omitted.
I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?
In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.