Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

111–120 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#113

Looks like ransomware criminals are going for the subscription model.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

The criminals already do often recommend firms to manage the payment and recovery process.

Re: 80% of orgs that paid the ransom were hit again

#114
post #52

Earlier quoted context omitted.

I wonder if this hurts their reputation. If they earn a reputation of coming back for seconds... Two things: People fix things faster to prevent double dipping. People opt to not pay the initial ransom if they’re going to be taken hostage again. It’s a kind of tragedy of the commons where the commons are the potential victims.

It doesn’t even have to be the same attacker. The attacker could just as easily sell the info to another attacker. Plus, if the original vuln used to gain access is still open, there’s no reason why somebody else doesn’t find it later.

Which vulnerability did the attackers use to gain initial access? Do the attackers disclose this along with decrypting the data? And are you sure they didn't leave a sleeper Trojan behind for later?

Re: 80% of orgs that paid the ransom were hit again

#115
post #78

Earlier quoted context omitted.

The US government has negotiated with the Taliban (a formally designated terrorist group) for prisoner exchanges. https://www.bbc.com/news/world-asia-50471186

The "don't negotiate with terrorists" is itself a negotiation tactic meant to lower the attack surface of any entity. It's the sort of thing you say publicly, but then privately you settle with your adversary. Absolutism is never a useful tactic.

Yes, but getting your opponent to believe you will take an absolute position is often the most useful tactic.

Re: 80% of orgs that paid the ransom were hit again

#117

Looks like ransomware criminals are going for the subscription model.

They're becoming a file encryption service. No one can steal your files either because they will just get encrypted trash. Though I suppose those thieves could also pay for the encryption key, or just go directly to the "service provider" for a paid copy.

“Data escrow service”

Re: 80% of orgs that paid the ransom were hit again

#118
post #18

I mean they just proved that they are willing to pay the ransom. If they are also unwilling or unable to clean up their shop and keep it from happening again, it surely will.

The responsibility lies at the nation-state level, and the clear decision is for Governments to ban the formal exchange of cryptocurrencies. As soon as this occurs, ransomware events will collapse since the ransoms will become unpayable. The negatives of cryptocurrencies (ransomware enablement, chip and electricity shortages, scams) clearly outweigh the positives at this point.

Cryptocurrencies are decentralized. It would have to be banned literally every country in the world for them not to be able to use it and convert to a non-digital currency. Good luck with that.

And I'm sure they'd just invent or go back to some other method -- possibly riskier and more violent -- so they can continue to ransom money from people.

Re: 80% of orgs that paid the ransom were hit again

#120

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

That's not for us to intellectually deduce, give the numbers. They have it. Is it 79%? 99? 1? Maybe it's all automated shotgun based attacks and they don't close the holes and so the act of paying the ransom is statistically meaningless This is shoddy journalism. Might as well just say "X%". It implies you shouldn't pay lest you fall victim again but they don't actually say that. Things that implicate what they refus…

The "journalism" has been shoddy from the start. This entire "Russians are pwning the electric company" meme has always been motivated more by politics, CYA, PR, and marketing than it has by anything real. TFA itself is a mail-it-in, paraphrase-the-press-release "effort". They actually link to the press release rather than the original marketing document; it's possible TFA's authors haven't read the latter! There's no guarantee the marketing document answers your question, but if you have an email address you don't mind getting spammed you could find out for yourself. [0] I don't have such an email address.

[0] https://www.cybereason.com/ebook-ransomware-the-true-cost-to...

Post reply on HN