Earlier quoted context omitted.
If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.
If only organizations would backup their own data. Then they could just restore and avoid paying. This is commonly suggested, and entirely useless. What the ransomware groups do is put a time bomb on the computer, then leave it to trigger on a future condition. Your backup will backup the time bomb, and the second you restore it, it also goes boom. And therefore your backup is a perfect copy of your data but entirely…
80% of orgs that paid the ransom were hit again
161–170 of 386 posts
Re: 80% of orgs that paid the ransom were hit again
#162Earlier quoted context omitted.
From the perspective of the individual, there is no greater good than defending one’s self.
Hardly. There are many philosophies that argue that the greatest good lies with how we interact with the other. And on a purely primal level it's common to prioritize one's offspring over one's self. I think most cultures recognize this intuitively.
What a grand delusional statement, like the sibling comment here. It’s literally arguing moral superiority while ignoring pragmatic reality.
Maybe you watch a little bit too much television, but there are plenty of spouses out there who would, for example, not want their wife to die in childbirth if they had the option.
Re: 80% of orgs that paid the ransom were hit again
#163“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…
> “Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. This has nothing to do with that idea. The reason the orgs paid the random once was because they had a severe lack of backup and other data safety protocols in combination with a vector to be infected (from all what we know, the latter is common and difficult to avoid): paying the ran…
Re: 80% of orgs that paid the ransom were hit again
#164Earlier quoted context omitted.
Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.
https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.
https://www.youtube.com/watch?v=9zoXk1vnmcg
The real Bowery Boys would sometimes sabotage other companies' insured buildings by setting the fires.
Re: 80% of orgs that paid the ransom were hit again
#165Earlier quoted context omitted.
If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.
If only organizations would backup their own data. Then they could just restore and avoid paying. This is commonly suggested, and entirely useless. What the ransomware groups do is put a time bomb on the computer, then leave it to trigger on a future condition. Your backup will backup the time bomb, and the second you restore it, it also goes boom. And therefore your backup is a perfect copy of your data but entirely…
Even if your backup does couple the data and compute together, if it's simply time based (not sure what other event you could use really, perhaps some pure probabilistic function), then it seems like you can just trick the environment that the time is something else to get back in.
The real underpinning issue is that this stuff breaks the state of the infrastructure and the business can't afford the downtime to go around and repair these issues.
If you have your infrastructure build out mostly automated, that automation is backed up, and critical data is backed up, then you can reasonably sidestep these issues (I supposed a real thorough breach might integrate the ransomware in this very automation system but it should be reasonable to root out). The other issue is of course if the intruders threaten to release private data (empkoyee and customer PII, financials, so on). There's also business integrity but that doesn't really seem to matter anymore.
Re: 80% of orgs that paid the ransom were hit again
#166Earlier quoted context omitted.
If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.
Many people’s backup routines aren’t good enough. Some of these guys encrypt over a period of time which is long enough to exceed the backup rotation. Their code decrypts on request, until the trigger day, when it posts the banners and deletes itself.
Re: 80% of orgs that paid the ransom were hit again
#167Looks like ransomware criminals are going for the subscription model.
Hardest part is to find subscribers, from then on the milking process is easy. Leaving the joke aside, does this mean that the systems remained unprotected after the initial ransom was paid or that they continued to threat leaking sensitive data? Paying the ransom a second time would guarantee nothing. Neither was paying the first time either.
Like, is a company who runs its IT infra on Windows XP and pays the ransom likely to switch to the latest and greatest, no expenses spared, in a total and utter overhaul of all their systems? Or will they only try to patch the holes that were already revealed and gloss over the rest? Blame it on the intern, all that.
Re: 80% of orgs that paid the ransom were hit again
#168“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…
When they hit a hospital, what is the hospital supposed to do? Not negotiate, for some "greater good" and let patients die? https://threatpost.com/ransomware-hits-hospitals-hardest/162...
Re: 80% of orgs that paid the ransom were hit again
#169Looks like ransomware criminals are going for the subscription model.
Ransom gangs are business oriented.
Re: 80% of orgs that paid the ransom were hit again
#170Earlier quoted context omitted.
Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.
If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.