Once you pay 'em the Danegeld You'll never be rid of the Dane
But the similarities are there, although the person's behind the ransomware attacks are probably not vikings.
21–30 of 386 posts
Once you pay 'em the Danegeld You'll never be rid of the Dane
But the similarities are there, although the person's behind the ransomware attacks are probably not vikings.
I believe that's a big part of why governments don't negotiate with terrorists and police just stall for time in real world ransom cases.
[1] https://www.foreignaffairs.com/articles/2007-01-01/negotiati...
These people are just financing the next generation of cyber criminals.
Once people stop paying, people will stop attacking.
Shouldn't they improve their security?
> After an organization experienced a ransomware attack, the top 5 solutions implemented included security awareness training (48%), security operations (SOC) (48%), endpoint protection (44%), data backup and recovery (43%), and email scanning (41%). The least deployed solutions post-attack included web scanning (40%), endpoint detection and response (EDR) and extended detection and response (XDR) technologies (38%), antivirus software (38%), mobile and SMS security solutions (36%), and managed security services provider (MSSP) or managed detection and response (MDR) provider (34%). Only 3% of respondents said they did not make any new security investments after a ransomware attack.
Earlier quoted context omitted.
If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.
I'm sorry but I have to ask: why assume the attacker is female?
The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!
Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.
Earlier quoted context omitted.
If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.
I'm sorry but I have to ask: why assume the attacker is female?
Once you pay 'em the Danegeld You'll never be rid of the Dane
I don't see why you have to pick on the Danes :) But the similarities are there, although the person's behind the ransomware attacks are probably not vikings.
Anyone else think we should make it illegal to pay ransom? These people are just financing the next generation of cyber criminals. Once people stop paying, people will stop attacking.
Earlier quoted context omitted.
If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.
Because second attacker might not be briefed by the first one.