Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

41–50 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#41
post #19

For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…

Does that revenue include pass-through?

Re: US travel firm $4.5M ransom negotiation open chat

#42
post #39

Earlier quoted context omitted.

Maybe require cyber insurance instead, pricing premiums based on audits performed by infosec practitioners. Similar to auto insurance, and what happens when you’re a high risk driver; you still have insurance, but you’re paying out the nose for it. Our current legal framework doesn’t support such a draconian suggestion as presented imho. You want poor security practices to be painful, not fatal, to the corporate enti…

Our legal framework already contains many prohibitions on financial transactions with criminals and terrorists. It wouldn't be difficult to add one more.

My point is there are better, more reasonable ways to arrive at the same end goal: effective infosec practices that prevent ransomware attacks (among other threat actors).

Banning ransomware payments just makes it more difficult; someone will still find a way to save their business by paying. You want to resolve the root issue: a business not taking security seriously.

Re: US travel firm $4.5M ransom negotiation open chat

#43
post #23
post #16

Earlier quoted context omitted.

But now you have $4 million in a bitcoin address linked to criminal activity. Then what? How much do you lose along the way to having laundered cash in hand?

Aren’t there mixer services for that or just convert to monero? This is off an exchange so lots of shenanigans to make things less traceable. I am guessing these people know what they are doing.

I’d imagine the feds are involved at this point. They paid to get their data, but the feds have to be tracking the addresses from this juncture and examining the breach.

I hope.

Re: US travel firm $4.5M ransom negotiation open chat

#44
post #32
post #19

For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…

I don't know about that. For one, travel margins are not exactly the same as SaaS margins. Secondly, there's the global pandemic and all, kinda hurts the free cash of most travel companies. I wouldn't be surprised if they genuinely would have trouble coughing up 10 million two days after the attack hit.

CWT is used by corporate travel systems. I'd expect their margins to be similar to enterprise software vendors, rather than other travel agencies.

Re: US travel firm $4.5M ransom negotiation open chat

#45
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?

In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.

Re: US travel firm $4.5M ransom negotiation open chat

#46
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?

Not the OP but I think it is clearly different, as kidnappers are putting someone's life in danger.

Re: US travel firm $4.5M ransom negotiation open chat

#47

So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.

Continuous append-only backups, where one can't rewrite them without physical access to the system, would - most likely - help with a data loss, malicious or accidental.

Maybe a dumb question but -- I'm not a sysadmin, why isn't this the case already? At least for a company doing $1.5 billion in revenue.

Re: US travel firm $4.5M ransom negotiation open chat

#48
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.

Re: US travel firm $4.5M ransom negotiation open chat

#49
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

Isn't this likely short sighted in the same way that people talk about draconic enforcement of immigration laws?

Criminalizing ransoms will result in victims doing it in secret, not in the elimination of ransoms. People won't be able to share information, and the financial incentive will continue to exist.

Re: US travel firm $4.5M ransom negotiation open chat

#50
post #45

Earlier quoted context omitted.

I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?

In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.

Reading "Never Split The Difference" - sounds like the police will work with families pay off kidnappers is some countries, but get it down from millions to a token amount. I think he aims for zero though most of the time.
Post reply on HN