80% of orgs that paid the ransom were hit again
41–50 of 386 posts
Re: 80% of orgs that paid the ransom were hit again
#42Earlier quoted context omitted.
If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.
I'm sorry but I have to ask: why assume the attacker is female?
It's interesting to see the various reactions to a perfectly innocent idiom.
https://en.wikipedia.org/wiki/Alice_and_Bob#Cast_of_characte...
Re: 80% of orgs that paid the ransom were hit again
#43“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…
Re: 80% of orgs that paid the ransom were hit again
#44Re: 80% of orgs that paid the ransom were hit again
#45Earlier quoted context omitted.
I'm sorry but I have to ask: why assume the attacker is female?
Probably trying to diversify pronoun usage. Would we be pointing this out if they said 'he'?
Re: 80% of orgs that paid the ransom were hit again
#46Re: 80% of orgs that paid the ransom were hit again
#47Looks like ransomware criminals are going for the subscription model.
Re: 80% of orgs that paid the ransom were hit again
#48I believe that's a big part of why governments don't negotiate with terrorists and police just stall for time in real world ransom cases.
"We don't negotiate with terrorists" is more of a slogan than a real policy[1]. [1] https://www.foreignaffairs.com/articles/2007-01-01/negotiati...
Re: 80% of orgs that paid the ransom were hit again
#49The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!
Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.
Re: 80% of orgs that paid the ransom were hit again
#50Looks like ransomware criminals are going for the subscription model.
Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.
Fire fighting in Rome had a similar premise.