Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

31–40 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#31
post #23

Anyone else think we should make it illegal to pay ransom? These people are just financing the next generation of cyber criminals. Once people stop paying, people will stop attacking.

It is already illegal in the US as of late 2020. But we know nothing really happens when corporations break the law.

https://cisomag.eccouncil.org/paying-ransom-is-now-illegal-u...

Re: 80% of orgs that paid the ransom were hit again

#32
“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions.

One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway.

That’s a hard one to swallow, hard enough that govs also sometimes can’t follow the mantra and just pay the ransom.

It’s crazy hard to get people to sacrifice themselves for the better good, it’s yet a bigger ask for corporations who already screw the public day in day out.

Re: 80% of orgs that paid the ransom were hit again

#33
post #12

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Although I think false advertising would be the least of their worries if they decided to do it.

Re: 80% of orgs that paid the ransom were hit again

#34

Looks like ransomware criminals are going for the subscription model.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob.

Somehow, that's a quite believable scenario.

Re: 80% of orgs that paid the ransom were hit again

#35
post #14

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

If the victim doesn't pay the first time, they suffer consequences and next time might decide to pay instead.

ISTM we only hear about the tiny minority of "victims" who do "suffer consequences". Most organizations who get ransomed just shut off a bunch of unnecessary stuff, re-provision the necessary stuff with passwords turned off, restore from backup, and hire some security consultants.

Re: 80% of orgs that paid the ransom were hit again

#36
post #13

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

Because second attacker might not be briefed by the first one.

And also due to the attacks being cheap to run

Re: 80% of orgs that paid the ransom were hit again

#37
post #15
post #11

I believe that's a big part of why governments don't negotiate with terrorists and police just stall for time in real world ransom cases.

Except that is a terrible analogy and has everything to do with a poor security culture on the firm's part because IT is treated as a liability rather than an asset.

I think the analogy is apt since both paying terrorists and ransomers is counterproductive.

If you pay the terrorists they just do it again. If you pay the ransomers they just do it again. And the payment increases their capabilities.

I think, except for rare conditions where a temporary need exists, it’s a net negative to pay.

But I think the security flaws that allow random ware typically are a sign of institutional incompetence so it makes sense they would also be incompetent to pay, and pay again, and pay again. Rather than to prevent the attack or to correct the flaw that allowed the attack.

Re: 80% of orgs that paid the ransom were hit again

#38
post #23

Anyone else think we should make it illegal to pay ransom? These people are just financing the next generation of cyber criminals. Once people stop paying, people will stop attacking.

I think we should actually legalize ransomware. By that I mean create a government-ran national bug bounty program. All companies of a certain size are automatically included in it. Bounties are awarded based off severity, and bounties are paid for by fines to the companies hit.

Interesting idea. But what you're describing is absolutely not "ransomware."

Re: 80% of orgs that paid the ransom were hit again

#40
Does it really surprise anyone that criminals would (re)target a place that paid out quickly and made their "jobs" easier? The aim is to get paid as quickly as possible with the least complexity and move on to the next target, is it not? If you're a freelancer and you have 10 clients and 8 always pay within 14 days of invoice and the other 2 let it drag on 90+ days and having to send out "reminder" letters, who do you favor doing business with?
Post reply on HN