Doesnt this just mean that 80% of orgs that were hit with ransomware attacks just didn't bother to fix their infosec, and got hit again because they left the same holes open to be exploited? Fool me once, shame on you. Fool me twice, shame on me.
80% of orgs that paid the ransom were hit again
151–160 of 386 posts
Re: 80% of orgs that paid the ransom were hit again
#152The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!
Re: 80% of orgs that paid the ransom were hit again
#153Earlier quoted context omitted.
If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.
I'm sorry but I have to ask: why assume the attacker is female?
Re: 80% of orgs that paid the ransom were hit again
#154Earlier quoted context omitted.
Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.
If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.
This is commonly suggested, and entirely useless.
What the ransomware groups do is put a time bomb on the computer, then leave it to trigger on a future condition. Your backup will backup the time bomb, and the second you restore it, it also goes boom. And therefore your backup is a perfect copy of your data but entirely useless.
Re: 80% of orgs that paid the ransom were hit again
#155Earlier quoted context omitted.
From the perspective of the individual, there is no greater good than defending one’s self.
What an absurd statement, to just say unequivocally, ignoring the plenty of philosophies and ethical systems have disagreed entirely with that.
Re: 80% of orgs that paid the ransom were hit again
#156Earlier quoted context omitted.
If only there were organizations who weren't criminals at all and who could be paid by a company to maintain backups of the company's data.
If only managers would perceive the money spent to pay such organizations as a necessity rather than burned cash
Re: 80% of orgs that paid the ransom were hit again
#157Earlier quoted context omitted.
If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.
If only organizations would backup their own data. Then they could just restore and avoid paying. This is commonly suggested, and entirely useless. What the ransomware groups do is put a time bomb on the computer, then leave it to trigger on a future condition. Your backup will backup the time bomb, and the second you restore it, it also goes boom. And therefore your backup is a perfect copy of your data but entirely…
Re: 80% of orgs that paid the ransom were hit again
#158“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…
Re: 80% of orgs that paid the ransom were hit again
#159Earlier quoted context omitted.
Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.
https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.
edit: Actually, Plutarch wrote that Crassus did buy the burning buildings.
Re: 80% of orgs that paid the ransom were hit again
#160Doesnt this just mean that 80% of orgs that were hit with ransomware attacks just didn't bother to fix their infosec, and got hit again because they left the same holes open to be exploited? Fool me once, shame on you. Fool me twice, shame on me.