Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

81–90 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#81
There's a somewhat better article about the survey here [1], including which countries were surveyed.

It looks like you can download the full report by filling out a form [2]. (So I didn't.)

[1] https://www.zdnet.com/article/most-firms-face-second-ransomw... [2] https://www.cybereason.com/ebook-ransomware-the-true-cost-to...

Re: 80% of orgs that paid the ransom were hit again

#82
post #78

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

The US government has negotiated with the Taliban (a formally designated terrorist group) for prisoner exchanges. https://www.bbc.com/news/world-asia-50471186

The "don't negotiate with terrorists" is itself a negotiation tactic meant to lower the attack surface of any entity.

It's the sort of thing you say publicly, but then privately you settle with your adversary.

Absolutism is never a useful tactic.

Re: 80% of orgs that paid the ransom were hit again

#83
Rudyard Kipling explained this:

---

But we've proved it again and again, / That if once you have paid him the Dane-geld / You never get rid of the Dane.

--- https://www.poetryloverspage.com/poets/kipling/dane_geld.htm....

By paying, you’ve just proven that you are a profitable target to hit.

Re: 80% of orgs that paid the ransom were hit again

#84
post #58
post #43

Earlier quoted context omitted.

Never negotiate with terrorists is only a thing because it puts you in a stronger negotiation position.

And it's just posturing. I'm sure the US negotiates with groups it labels as terrorists through backchannels.

Literally every government says this publicly, and then negotiates privately.

Re: 80% of orgs that paid the ransom were hit again

#85
post #18

I mean they just proved that they are willing to pay the ransom. If they are also unwilling or unable to clean up their shop and keep it from happening again, it surely will.

The responsibility lies at the nation-state level, and the clear decision is for Governments to ban the formal exchange of cryptocurrencies.

As soon as this occurs, ransomware events will collapse since the ransoms will become unpayable.

The negatives of cryptocurrencies (ransomware enablement, chip and electricity shortages, scams) clearly outweigh the positives at this point.

Re: 80% of orgs that paid the ransom were hit again

#86

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

I think they can start calling themselves the corporate IT department.

Perhaps the red team, there is more to IT than backups

Re: 80% of orgs that paid the ransom were hit again

#87

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

Taxation works exactly like this.

You might even want to establish an isolated society, but if you try, good luck dealing with the IRS.

Re: 80% of orgs that paid the ransom were hit again

#88

Looks like ransomware criminals are going for the subscription model.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

> they can successfully call themselves a mob

Or Backblaze's evil twin.

Re: 80% of orgs that paid the ransom were hit again

#89
post #52

Looks like ransomware criminals are going for the subscription model.

I wonder if this hurts their reputation. If they earn a reputation of coming back for seconds... Two things: People fix things faster to prevent double dipping. People opt to not pay the initial ransom if they’re going to be taken hostage again. It’s a kind of tragedy of the commons where the commons are the potential victims.

It doesn’t even have to be the same attacker. The attacker could just as easily sell the info to another attacker.

Plus, if the original vuln used to gain access is still open, there’s no reason why somebody else doesn’t find it later.

Post reply on HN