Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

131–140 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#131
post #50

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.

Free market in action.

Re: 80% of orgs that paid the ransom were hit again

#132

Looks like ransomware criminals are going for the subscription model.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

If only there were organizations who weren't criminals at all and who could be paid by a company to maintain backups of the company's data.

Re: 80% of orgs that paid the ransom were hit again

#133

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

> “Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions.

This has nothing to do with that idea.

The reason the orgs paid the random once was because they had a severe lack of backup and other data safety protocols in combination with a vector to be infected (from all what we know, the latter is common and difficult to avoid): paying the ransom is likely their only choice to maintain the business.

It is not surprising at all that these orgs can and will be infected again, and will continue to show a lack in the security and data safety departments, and so they will continue to pay ransoms.

It's sort of an inverse survivorship bias: if you get infected once because you're susceptible, you're likely to get infected again unless you fix your susceptibility.

Re: 80% of orgs that paid the ransom were hit again

#134
post #26
post #12

Earlier quoted context omitted.

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Makes more sense if the group offered a subscription model for decrypting files encrypted by that group. Then you wouldn't have to keep paying the big lump sum.

A referral revenue sharing program for jaded employees would probably do well also.

Re: 80% of orgs that paid the ransom were hit again

#135

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

If only there were organizations who weren't criminals at all and who could be paid by a company to maintain backups of the company's data.

It's a crowded marketplace, anybody who wants to succeed in there needs some growth hacking. Where in this case "growth hacking" hacking literally means hacking.

Re: 80% of orgs that paid the ransom were hit again

#136

Earlier quoted context omitted.

It appears that some of the major ransomware gangs are operating from Russia and are tolerated by the government, as long as they don't hit domestic targets. The US cannot really send special forces there without risking a massive escalation.

I'm sure the US has hundreds of spies and personnel in Russia at any point in time. But sending a spy to a software developers house and assassinating them probably isn't going to stop the problem - more people will spring up doing the same.

We might not though. We don't even have a main diplomat there.

Russia has always been notoriously hard to spy on.

I would not be surprised if there was only a handful of well placed assets and most of the spying being done electronically.

Re: 80% of orgs that paid the ransom were hit again

#138

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

Many people’s backup routines aren’t good enough.

Some of these guys encrypt over a period of time which is long enough to exceed the backup rotation. Their code decrypts on request, until the trigger day, when it posts the banners and deletes itself.

Re: 80% of orgs that paid the ransom were hit again

#139

Earlier quoted context omitted.

It doesn’t even have to be the same attacker. The attacker could just as easily sell the info to another attacker. Plus, if the original vuln used to gain access is still open, there’s no reason why somebody else doesn’t find it later.

Which vulnerability did the attackers use to gain initial access? Do the attackers disclose this along with decrypting the data? And are you sure they didn't leave a sleeper Trojan behind for later?

A few months ago one chat between hackers and the company was leaked. The hacker actually explained how to fix the vulnerabilities. On mobile but it should show up in google (think it was posted here on hn also)

Re: 80% of orgs that paid the ransom were hit again

#140

Doesnt this just mean that 80% of orgs that were hit with ransomware attacks just didn't bother to fix their infosec, and got hit again because they left the same holes open to be exploited? Fool me once, shame on you. Fool me twice, shame on me.

It can just as easily mean that the attacker found a second exploit after the first was resolved.
Post reply on HN