Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

41–50 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#42
post #16

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

I'm sorry but I have to ask: why assume the attacker is female?

"Mallory" is commonly understood to be a woman's name. Come to think of it, so is "Trudy".

It's interesting to see the various reactions to a perfectly innocent idiom.

https://en.wikipedia.org/wiki/Alice_and_Bob#Cast_of_characte...

Re: 80% of orgs that paid the ransom were hit again

#43

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

Never negotiate with terrorists is only a thing because it puts you in a stronger negotiation position.

Re: 80% of orgs that paid the ransom were hit again

#45
post #16

Earlier quoted context omitted.

I'm sorry but I have to ask: why assume the attacker is female?

Probably trying to diversify pronoun usage. Would we be pointing this out if they said 'he'?

No, because for better or worse “he” is the default for a plurality or unknown gender in most (all?) romance languages, including English. Times and sensitivities change but “she” still connotes more knowledge than “he” so it’s bound to cause some confusion.

Re: 80% of orgs that paid the ransom were hit again

#46
post #8

Looks like ransomware criminals are going for the subscription model.

To unsubscribe you have to talk to a sales representative and send in a fax.

Just click that innocent looking unsubscribe link at the bottom of the email. Case solved!

Re: 80% of orgs that paid the ransom were hit again

#48
post #11

I believe that's a big part of why governments don't negotiate with terrorists and police just stall for time in real world ransom cases.

"We don't negotiate with terrorists" is more of a slogan than a real policy[1]. [1] https://www.foreignaffairs.com/articles/2007-01-01/negotiati...

The difference is that even if you don't negotiate with terrorists, they can still terrorize you. It's impossible to successfully ransom someone without their cooperation.

Re: 80% of orgs that paid the ransom were hit again

#49
post #12

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Everyone knows that once you find a loose slots machine, you keeping playing it.

Re: 80% of orgs that paid the ransom were hit again

#50

Looks like ransomware criminals are going for the subscription model.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

https://en.wikipedia.org/wiki/History_of_firefighting#Rome

Fire fighting in Rome had a similar premise.

Post reply on HN