Earlier quoted context omitted.
Yeah, totally absurd. Would you sacrifice your life for the strangers on this forum? Let me guess, no? Huh, wild.
Wait, so you think that defending anonymous strangers from the internet is an exhaustive set of circumstances where one might risk their life?
80% of orgs that paid the ransom were hit again
201–210 of 386 posts
Re: 80% of orgs that paid the ransom were hit again
#202Earlier quoted context omitted.
Hardly. There are many philosophies that argue that the greatest good lies with how we interact with the other. And on a purely primal level it's common to prioritize one's offspring over one's self. I think most cultures recognize this intuitively.
I’m not arguing philosophy. I’m arguing how absurd the statement “it’s crazy hard to get people to sacrifice themselves for the better good” is, as if OP would sacrifice his or herself for anyone here they didn’t know. What a grand delusional statement, like the sibling comment here. It’s literally arguing moral superiority while ignoring pragmatic reality. Maybe you watch a little bit too much television, but there…
Re: 80% of orgs that paid the ransom were hit again
#203What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.
Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.
Re: 80% of orgs that paid the ransom were hit again
#204How long do major companies keep back ups? It seems like all of these companies that keep getting hit with ransomware Only have last weeks back up laying around. Why can’t you go back eight months? True the data is going to be lacking, but at least the structure is going to be there. I completely understand that a Trojan or a virus can get locked into a back up and it just keeps getting backed up, but if you go far e…
At my last place, they only kept 1 year and monthly, but the problem was it was hundreds of terabytes of data on lots of VMs. We tried to restore backups and it was going to take longer than the long weekend just for file transfer.
I don’t know what normal process is, but I believe I saw file locker Trojan that didn’t hit every byte of the drive; but rather crawled the file system and did a bit on every file header for speed. So I imagine it’s still faster to pay and fix than restore from backups for some.
Re: 80% of orgs that paid the ransom were hit again
#205Earlier quoted context omitted.
Many people’s backup routines aren’t good enough. Some of these guys encrypt over a period of time which is long enough to exceed the backup rotation. Their code decrypts on request, until the trigger day, when it posts the banners and deletes itself.
Maybe corporations should make it standard practice to have cold storage backups that are physically disconnected from the network (by humans) in a rotated fashion. Backup A is physically disconnected on B days and backup B is physically disconnected on A days.
Re: 80% of orgs that paid the ransom were hit again
#206I don't see any discussion of typical entry points. How do these guys get into the system? Is it by having someone download a malicious file? If so what type of file? PDF? MS Office? If so Adobe and Microsoft should be held accountable for their security holes, only then will they have enough motivation to maybe consider rewriting some of their code in a safer language such as Rust.
There is much confusion and many bad analogies surrounding this issue.
Some claim - without evidence - that nation states are behind it. Which, with a moments reflection, is absurd; nation states may have an interest in disabling certain systems for military purposes (at the appropriate time), but no nation state needs ransom money. Easier ways for a government to get money; namely, just print some.
Others liken it to the mafia or cartel or other well-organized criminal organizations. This too misses the mark.
Like most business crimes, the culprit is almost always an insider. Period. As the tools to pull this off are trivial to come by on the internet, the obvious suspect would be some disgruntled IT person within the company.
It’s as if — after a bank robbery — everyone claims it must have been some crack team of Russians flown in under radar in helicopters. Instead, they should be looking at the numerous employees who have access to the security system and the safe.
But, it’s much more exciting to pretend that Putin is sponsoring hackers to get trivial amounts of money from companies across the globe. Ha.
I’m not even an IT guy, but at my last job, even I had access sufficient to destroy or corrupt all the data. That was before cryptocurrency and the like... I assume assembling a ransomware set of tools off the internet is no more or less difficult than it was to assemble a set of tools to make pirated copies of AdobePhotshop back in the day.
Re: 80% of orgs that paid the ransom were hit again
#207Earlier quoted context omitted.
https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.
The privately owned fire brigades in NYC 100 years ago weren't much better. The free market at work: https://www.youtube.com/watch?v=9zoXk1vnmcg The real Bowery Boys would sometimes sabotage other companies' insured buildings by setting the fires. https://en.wikipedia.org/wiki/Bowery_Boys
Re: 80% of orgs that paid the ransom were hit again
#208The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!
Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.
I think these negotiations are fine, if you're just buying time to gather your backups; I've assumed the payouts were made by insurance companies, so go ahead - buy a zero-value promise from a gang of crooks, if you want.
But your org has been rooted (at best, you can't prove it hasn't). Compromised systems can't be really be cleaned, they have to be reinstalled from scratch, if you want to have confidence in them.
And an attack can be stored in data - which you're about to restore from backup. That's a problem I have faced, and I chose to ignore that threat. No choice - I didn't know how to address it then, and I still don't now.
My half-baked opinions about ransomware are largely based on watching this documentary: https://www.bbc.co.uk/programmes/w172wx9056p6bd6
Re: 80% of orgs that paid the ransom were hit again
#209I mean they just proved that they are willing to pay the ransom. If they are also unwilling or unable to clean up their shop and keep it from happening again, it surely will.
It is almost like the groups hacking them are providing a good service. If they get hacked once, shit happens. But if it happens multiple times then someone should probably answer for it.
Re: 80% of orgs that paid the ransom were hit again
#210Earlier quoted context omitted.
Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.
Makes more sense if the group offered a subscription model for decrypting files encrypted by that group. Then you wouldn't have to keep paying the big lump sum.