Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

11–20 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#12

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Re: 80% of orgs that paid the ransom were hit again

#13
post #3

Meaningless stat without a baseline to compare against. How many who didn't pay were hit again?

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

Because second attacker might not be briefed by the first one.

Re: 80% of orgs that paid the ransom were hit again

#14
post #3

Meaningless stat without a baseline to compare against. How many who didn't pay were hit again?

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

If the victim doesn't pay the first time, they suffer consequences and next time might decide to pay instead.

Re: 80% of orgs that paid the ransom were hit again

#15
post #11

I believe that's a big part of why governments don't negotiate with terrorists and police just stall for time in real world ransom cases.

Except that is a terrible analogy and has everything to do with a poor security culture on the firm's part because IT is treated as a liability rather than an asset.

Re: 80% of orgs that paid the ransom were hit again

#16
post #3

Meaningless stat without a baseline to compare against. How many who didn't pay were hit again?

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

I'm sorry but I have to ask: why assume the attacker is female?

Re: 80% of orgs that paid the ransom were hit again

#19
post #16

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

I'm sorry but I have to ask: why assume the attacker is female?

It seems like "they're" would've been a better choice there, as there are a plurality of attackers in the world.

Re: 80% of orgs that paid the ransom were hit again

#20
post #16

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

I'm sorry but I have to ask: why assume the attacker is female?

Why not? Why assume that they are male?
Post reply on HN