Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

51–60 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#52

Looks like ransomware criminals are going for the subscription model.

I wonder if this hurts their reputation.

If they earn a reputation of coming back for seconds...

Two things:

People fix things faster to prevent double dipping.

People opt to not pay the initial ransom if they’re going to be taken hostage again.

It’s a kind of tragedy of the commons where the commons are the potential victims.

Re: 80% of orgs that paid the ransom were hit again

#53

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

From the perspective of the individual, there is no greater good than defending one’s self.

Re: 80% of orgs that paid the ransom were hit again

#54

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

From another comment, it looks that mantra will become law in the US

https://cisomag.eccouncil.org/paying-ransom-is-now-illegal-u...

Re: 80% of orgs that paid the ransom were hit again

#55

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

It makes you think about how many of those are inside jobs and/or compromised employees. In the case of colonial, it would seem highly likely given it was a credential compromise, but then again secure passwords are a known weakness

Re: 80% of orgs that paid the ransom were hit again

#56

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

I mean couldn't government pay the ransom and then go great lengths to track the suspects and send special forces after them? Surely US govt. has the ability to track almost anyone.

Having US govt. on your ass should a decent deterrent.

Just take a look at how hard FBI came down on cartels and individuals who were involved in killing Enrique Camarena. Cartel leaders were arrested in Mexico and several individual in the US.

Re: 80% of orgs that paid the ransom were hit again

#57
post #31
post #23

Anyone else think we should make it illegal to pay ransom? These people are just financing the next generation of cyber criminals. Once people stop paying, people will stop attacking.

It is already illegal in the US as of late 2020. But we know nothing really happens when corporations break the law. https://cisomag.eccouncil.org/paying-ransom-is-now-illegal-u...

Only for sanctioned parties I believe — which would apply for any money transfers regardless of purpose. Most random criminal rw attackers are not going to be on a sanction list.

Re: 80% of orgs that paid the ransom were hit again

#58
post #43

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

Never negotiate with terrorists is only a thing because it puts you in a stronger negotiation position.

And it's just posturing. I'm sure the US negotiates with groups it labels as terrorists through backchannels.

Re: 80% of orgs that paid the ransom were hit again

#60
post #54

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

From another comment, it looks that mantra will become law in the US https://cisomag.eccouncil.org/paying-ransom-is-now-illegal-u...

Isn't that just applying existing sanction law to ransomware?
Post reply on HN