Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

141–150 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#141
post #116

Looks like ransomware criminals are going for the subscription model.

How the hell do people got hit with ransomware anyway? Do they not have offline nightly backups of critical data?

See my post in the peer thread.

Re: 80% of orgs that paid the ransom were hit again

#142

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

I'm shocked at such unethical practices by the hackers. I expected better from a group of terrorists.

I'm kind of reminded of the mafia and their protection rackets. Obviously, you never could trust criminal organizations. At the same time, if you're a medium-sized corporation or small business and they have your important data, and you know you could pay to get it back, what do you do? I can imagine they really have some people by the balls, metaphorically speaking. They could drive you bankrupt.

I hope the authorities find a way to go after these people, but it's obviously got to be difficult, because they might well be in China or Russia. It would take some international cooperation that's probably impossible right now.

In the meantime... Switch to Linux, have a competent offsite backup strategy...?

Re: 80% of orgs that paid the ransom were hit again

#143

Earlier quoted context omitted.

It appears that some of the major ransomware gangs are operating from Russia and are tolerated by the government, as long as they don't hit domestic targets. The US cannot really send special forces there without risking a massive escalation.

No, but the people operating in Russia like to travel elsewhere, and do. Also, the US and allies can enforce Russian AML laws as written on paper. If, say, the UK freezes all of Oleg Deripaska's assets there, Vova will absolutely get the message. We're not going to bring down the Russian government with military force for a million different reasons, but doing it with sanctions and prosecution is a totally different…

When they do US gets them. That happens from time to time, if you watch the news, you notice there are guys caught periodically who thought it's time for a nice vacation in Spain resting from their criminal activities... only to be picked up in the airport. However, the smarter ones stay put inside Russia and those are hard to get.

Re: 80% of orgs that paid the ransom were hit again

#144

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

From the perspective of the individual, there is no greater good than defending one’s self.

What an absurd statement, to just say unequivocally, ignoring the plenty of philosophies and ethical systems have disagreed entirely with that.

Re: 80% of orgs that paid the ransom were hit again

#145
I don't see any discussion of typical entry points. How do these guys get into the system? Is it by having someone download a malicious file? If so what type of file? PDF? MS Office? If so Adobe and Microsoft should be held accountable for their security holes, only then will they have enough motivation to maybe consider rewriting some of their code in a safer language such as Rust.

Re: 80% of orgs that paid the ransom were hit again

#146

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Unless the attackers revealed their exploit, it probably wasn't fixed and they just got in again the same way.

Re: 80% of orgs that paid the ransom were hit again

#147

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

There is also the threat of leaking private data. Companies which collect PII could be liable if it's proven they were negligent.

Re: 80% of orgs that paid the ransom were hit again

#149

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

When they hit a hospital, what is the hospital supposed to do? Not negotiate, for some "greater good" and let patients die?

https://threatpost.com/ransomware-hits-hospitals-hardest/162...

Re: 80% of orgs that paid the ransom were hit again

#150

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

If only there were organizations who weren't criminals at all and who could be paid by a company to maintain backups of the company's data.

If only managers would perceive the money spent to pay such organizations as a necessity rather than burned cash
Post reply on HN