Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

91–100 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#92
post #70
post #23

Anyone else think we should make it illegal to pay ransom? These people are just financing the next generation of cyber criminals. Once people stop paying, people will stop attacking.

Yes, because criminals definitely follow the law.

No, you become a criminal by paying. You continue not being a criminal by not paying.

Re: 80% of orgs that paid the ransom were hit again

#94

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

> they can successfully call themselves a mob Or Backblaze's evil twin.

Ablaze?

Re: 80% of orgs that paid the ransom were hit again

#95

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

I don’t think this mantra was ever anything more than a meme. LE always negotiate, this mantra is designed to just better their negotiating position

Re: 80% of orgs that paid the ransom were hit again

#96

According to a study by Cybereason, which sells endpoint protection software.

One has to wonder if Cybereason measured the 80% figure from their own clients - endpoint protection is the lowest form of security.

Alternatively, Cybereason are probably in a really good position to snarf passwords and then parallel construct an attack from a third party who gives a few major individual shareholders a kickback.

Does endpoint security even work?

Re: 80% of orgs that paid the ransom were hit again

#97

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

> because the society benefits

That's the theory. But much like war on drugs or TSA, whether its real-world outcomes match the theoretical ones is debatable.

https://www.newamerica.org/international-security/policy-pap...

Re: 80% of orgs that paid the ransom were hit again

#98
post #3

Meaningless stat without a baseline to compare against. How many who didn't pay were hit again?

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

That's not for us to intellectually deduce, give the numbers. They have it. Is it 79%? 99? 1?

Maybe it's all automated shotgun based attacks and they don't close the holes and so the act of paying the ransom is statistically meaningless

This is shoddy journalism. Might as well just say "X%". It implies you shouldn't pay lest you fall victim again but they don't actually say that.

Things that implicate what they refuse to say is kind of suspect

Re: 80% of orgs that paid the ransom were hit again

#99
Seems like the ones with the payloads distribute it to more than one affiliate. Or at least a previously hit target does not get a mark that is globally respected.

The fast growth desires lead to a lot of vulnerabilities, yesterday I signed up to a service and they emailed me my own username and password, simple plain text. Incredible.

Re: 80% of orgs that paid the ransom were hit again

#100
post #3

Meaningless stat without a baseline to compare against. How many who didn't pay were hit again?

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

The whole point of gathering statistics is that making up logic for what could be the case is generally a massive waste of time.
Post reply on HN