Looks like ransomware criminals are going for the subscription model.
How the hell do people got hit with ransomware anyway? Do they not have offline nightly backups of critical data?
80% of orgs that paid the ransom were hit again
141–150 of 386 posts
Re: 80% of orgs that paid the ransom were hit again
#142The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!
I'm shocked at such unethical practices by the hackers. I expected better from a group of terrorists.
I hope the authorities find a way to go after these people, but it's obviously got to be difficult, because they might well be in China or Russia. It would take some international cooperation that's probably impossible right now.
In the meantime... Switch to Linux, have a competent offsite backup strategy...?
Re: 80% of orgs that paid the ransom were hit again
#143Earlier quoted context omitted.
It appears that some of the major ransomware gangs are operating from Russia and are tolerated by the government, as long as they don't hit domestic targets. The US cannot really send special forces there without risking a massive escalation.
No, but the people operating in Russia like to travel elsewhere, and do. Also, the US and allies can enforce Russian AML laws as written on paper. If, say, the UK freezes all of Oleg Deripaska's assets there, Vova will absolutely get the message. We're not going to bring down the Russian government with military force for a million different reasons, but doing it with sanctions and prosecution is a totally different…
Re: 80% of orgs that paid the ransom were hit again
#144“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…
From the perspective of the individual, there is no greater good than defending one’s self.
Re: 80% of orgs that paid the ransom were hit again
#145Re: 80% of orgs that paid the ransom were hit again
#146The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!
Re: 80% of orgs that paid the ransom were hit again
#147Earlier quoted context omitted.
Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.
If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.
Re: 80% of orgs that paid the ransom were hit again
#148What percent of orgs that did not pay the ransom get hit again?
Re: 80% of orgs that paid the ransom were hit again
#149“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…
https://threatpost.com/ransomware-hits-hospitals-hardest/162...
Re: 80% of orgs that paid the ransom were hit again
#150Earlier quoted context omitted.
Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.
If only there were organizations who weren't criminals at all and who could be paid by a company to maintain backups of the company's data.