Live data from Hacker News

Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

cyberscoop.com

1–10 of 105 posts

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#3
>A spokesperson for AXA XL [...] said the announcement doesn’t apply [...] to ransomware-related incident cleanup costs.

So rather than paying the ransom, they'll hire a "ransomware cleanup" consultancy which cleans up the ransomware by paying the ransom (under the table and with plausible deniability, of course).

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#4
post #3

>A spokesperson for AXA XL [...] said the announcement doesn’t apply [...] to ransomware-related incident cleanup costs. So rather than paying the ransom, they'll hire a "ransomware cleanup" consultancy which cleans up the ransomware by paying the ransom (under the table and with plausible deniability, of course).

Not necessarily. A ransomware attack is just a subclass of your generic security breach, so the usual response & remediation activities apply. I would actually think covertly paying ransom costs being a highly unlikely activity.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#5
This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks.

This will not solve the problem of ransomware alone, but is a step in the right direction.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#6
post #3

>A spokesperson for AXA XL [...] said the announcement doesn’t apply [...] to ransomware-related incident cleanup costs. So rather than paying the ransom, they'll hire a "ransomware cleanup" consultancy which cleans up the ransomware by paying the ransom (under the table and with plausible deniability, of course).

Do you have any proof of that (or even cases where that has happened before), or are you just making it up?

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#7
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

Put yourself in the shoes of business. Well, like the oil company now in USA.

Lets say you haven't learn the lesson of backup importance.

Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work.

Now, what do you do?

The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of the side that is held as hostage.

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#8
post #6
post #3

>A spokesperson for AXA XL [...] said the announcement doesn’t apply [...] to ransomware-related incident cleanup costs. So rather than paying the ransom, they'll hire a "ransomware cleanup" consultancy which cleans up the ransomware by paying the ransom (under the table and with plausible deniability, of course).

Do you have any proof of that (or even cases where that has happened before), or are you just making it up?

Proven Data and Monstercloud in the US were found to have been doing that.

https://features.propublica.org/ransomware/ransomware-attack...

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#9
post #7
post #5

This is the right course of action. Always think about how your actions incentivize future behaviour. The only right course of action is to halt the flow of revenue to the attackers in order to disincentivize future attacks. This will not solve the problem of ransomware alone, but is a step in the right direction.

Put yourself in the shoes of business. Well, like the oil company now in USA. Lets say you haven't learn the lesson of backup importance. Your business has stopped. Your ONLY way to recover and restore revenue stream is to get the data. You are aware that paying ransom may or may NOT work. Now, what do you do? The suggestions (cut the attackers revenue stream) may sound very right, correct and whatnot. But think of t…

Did the business follow best security practices? Did it do its due diligence to harden against attacks?

Why should insurers pay, when businesses have no incentive to do this?

Re: Experts suggest AXA’s plan to shun ransomware payouts will set a precedent

#10
> A representative of the REvil ransomware gang said in a March interview that the group specifically targets victims known to have cyber-insurance, because they’re “one of the tastiest morsels” who can more easily afford to pay.

Wow.

Post reply on HN