Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

181–190 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#181
post #144

Earlier quoted context omitted.

What an absurd statement, to just say unequivocally, ignoring the plenty of philosophies and ethical systems have disagreed entirely with that.

Yeah, totally absurd. Would you sacrifice your life for the strangers on this forum? Let me guess, no? Huh, wild.

Wait, so you think that defending anonymous strangers from the internet is an exhaustive set of circumstances where one might risk their life?

Re: 80% of orgs that paid the ransom were hit again

#182

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Wonder what percentage of those that were hit had someone actively looking to get back in. Maybe 20% learned their lesson and improved their security. I wonder how many iterations of this will it take for most companies to learn that leaving your doors unlocked in a shady neighborhood/the internet is a bad idea.

Re: 80% of orgs that paid the ransom were hit again

#184
post #131
post #50

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.

Free market in action.

Free market requires strong property rights, as private property is a legal fiction which otherwise does not exist enough to sustain a market.

This is instead a dysfunctional government approaching anarcho-individualism.

Re: 80% of orgs that paid the ransom were hit again

#185
post #12

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Coming soon: ransomware with subscription business model

Re: 80% of orgs that paid the ransom were hit again

#186

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Wonder what percentage of those that were hit had someone actively looking to get back in. Maybe 20% learned their lesson and improved their security. I wonder how many iterations of this will it take for most companies to learn that leaving your doors unlocked in a shady neighborhood/the internet is a bad idea.

if it were me, I'd leave webshells or other backdoors to let myself back in if they didn't do proper cleanup. Especially if they paid, I have a "known good" customer.

Re: 80% of orgs that paid the ransom were hit again

#188

Looks like ransomware criminals are going for the subscription model.

I wonder if there are like Russian mob investors in these cybercrime "startups" and they also have to make decks that show YoY revenue / user growth. Lmao!

Well, to my understanding, fronting money in drug deals for a cut and interest is a common model crime already, so I would say it's more likely than you think. The only difference between VC funding and bankrolling the mob is one is legal.

Re: 80% of orgs that paid the ransom were hit again

#189

Earlier quoted context omitted.

The responsibility lies at the nation-state level, and the clear decision is for Governments to ban the formal exchange of cryptocurrencies. As soon as this occurs, ransomware events will collapse since the ransoms will become unpayable. The negatives of cryptocurrencies (ransomware enablement, chip and electricity shortages, scams) clearly outweigh the positives at this point.

Cryptocurrencies are decentralized. It would have to be banned literally every country in the world for them not to be able to use it and convert to a non-digital currency. Good luck with that. And I'm sure they'd just invent or go back to some other method -- possibly riskier and more violent -- so they can continue to ransom money from people.

> Cryptocurrencies are decentralized. It would have to be banned literally every country in the world for them not to be able to use it and convert to a non-digital currency. Good luck with that.

The effect would not come from the criminals being able to cash out, it would come from the company not being able to cash in. If cryptocurrency were to be banned and public exchanges were closed purchasing cryptocurrency to the tune of millions of dollars worth becomes practically impossible for a regular company without connections in the space. If the company is not able to pay the ransom, the entire venture is pointless.

> And I'm sure they'd just invent or go back to some other method -- possibly riskier and more violent -- so they can continue to ransom money from people.

Sure, there will be other methods of transferring some amount of money. To the tune of millions of dollars, though? Unlikely. Cryptocurrency enables these companies to pay ransoms of this amount. Without cryptocurrency you might be able to ask for a 50K ransom instead of a 5M ransom, but that reduces your payout by 100X. 5M is enough to retire from. 50K is less than the yearly wage these people can make.

It's not like ransomware didn't exist before cryptocurrency, we know what ransomware without cryptocurrency looks like. What cryptocurrency changed is the scale of the payout. Instead of getting a few thousand dollars in gift cards the hackers are now rewarded with millions in bitcoins. It is hard to deny that the change in incentives caused by cryptocurrency is the primary driver behind the huge increase in ransomware attacks in the last few years.

Re: 80% of orgs that paid the ransom were hit again

#190

Doesnt this just mean that 80% of orgs that were hit with ransomware attacks just didn't bother to fix their infosec, and got hit again because they left the same holes open to be exploited? Fool me once, shame on you. Fool me twice, shame on me.

It can just as easily mean that the attacker found a second exploit after the first was resolved.

Since so many were hit by the very same ransomware group, it's likely that the attacker spotted a second exploit during the first attack. It's easier to spot things when you've already busted your way in and have the run of the place.

i.e. An attacker breaks into a system using one vulnerability, spots a few more vulnerabilities while snooping for data, files them away for future reference, extracts a ransom, and then repeats the process later after the victim fixes the first vulnerability but fails to address the others.

The takeaway lesson appears to be that, if you are hacked and fix the vulnerability that made it possible, you shouldn't stop there. You're marked as a target that pays and detailed information on your system is now out there. Even having fixed the first hack, you're more vulnerable than ever.

Post reply on HN