Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

21–30 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#22
post #11

I believe that's a big part of why governments don't negotiate with terrorists and police just stall for time in real world ransom cases.

"We don't negotiate with terrorists" is more of a slogan than a real policy[1].

[1] https://www.foreignaffairs.com/articles/2007-01-01/negotiati...

Re: 80% of orgs that paid the ransom were hit again

#24
post #5

Shouldn't they improve their security?

About half did. From the article...

> After an organization experienced a ransomware attack, the top 5 solutions implemented included security awareness training (48%), security operations (SOC) (48%), endpoint protection (44%), data backup and recovery (43%), and email scanning (41%). The least deployed solutions post-attack included web scanning (40%), endpoint detection and response (EDR) and extended detection and response (XDR) technologies (38%), antivirus software (38%), mobile and SMS security solutions (36%), and managed security services provider (MSSP) or managed detection and response (MDR) provider (34%). Only 3% of respondents said they did not make any new security investments after a ransomware attack.

Re: 80% of orgs that paid the ransom were hit again

#25
post #16

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

I'm sorry but I have to ask: why assume the attacker is female?

Probably trying to diversify pronoun usage. Would we be pointing this out if they said 'he'?

Re: 80% of orgs that paid the ransom were hit again

#26
post #12

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Makes more sense if the group offered a subscription model for decrypting files encrypted by that group. Then you wouldn't have to keep paying the big lump sum.

Re: 80% of orgs that paid the ransom were hit again

#27
post #16

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

I'm sorry but I have to ask: why assume the attacker is female?

English up until recently used male pronouns by default for everything but we have learned recently, thanks to our heroic Gender Studiers, that this actually perpetuates systemic sexist patriarchy. So the solution is to randomly use male or female pronouns, making language unclear and confusing--which helps fight the patriarchy.

Re: 80% of orgs that paid the ransom were hit again

#28
post #21
post #2

Once you pay 'em the Danegeld You'll never be rid of the Dane

I don't see why you have to pick on the Danes :) But the similarities are there, although the person's behind the ransomware attacks are probably not vikings.

https://www.poetryloverspage.com/poets/kipling/dane_geld.htm...

https://en.wikipedia.org/wiki/Danegeld

Re: 80% of orgs that paid the ransom were hit again

#29
post #23

Anyone else think we should make it illegal to pay ransom? These people are just financing the next generation of cyber criminals. Once people stop paying, people will stop attacking.

I think we should actually legalize ransomware. By that I mean create a government-ran national bug bounty program. All companies of a certain size are automatically included in it. Bounties are awarded based off severity, and bounties are paid for by fines to the companies hit.

Re: 80% of orgs that paid the ransom were hit again

#30
post #13

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

Because second attacker might not be briefed by the first one.

If they actually have proper backups to avoid paying the first one, my guess is they are much more likely to also have the skills to prevent a second breach.
Post reply on HN