Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

201–210 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#201
post #181

Earlier quoted context omitted.

Yeah, totally absurd. Would you sacrifice your life for the strangers on this forum? Let me guess, no? Huh, wild.

Wait, so you think that defending anonymous strangers from the internet is an exhaustive set of circumstances where one might risk their life?

Oh, of course.

Re: 80% of orgs that paid the ransom were hit again

#202
post #67

Earlier quoted context omitted.

Hardly. There are many philosophies that argue that the greatest good lies with how we interact with the other. And on a purely primal level it's common to prioritize one's offspring over one's self. I think most cultures recognize this intuitively.

I’m not arguing philosophy. I’m arguing how absurd the statement “it’s crazy hard to get people to sacrifice themselves for the better good” is, as if OP would sacrifice his or herself for anyone here they didn’t know. What a grand delusional statement, like the sibling comment here. It’s literally arguing moral superiority while ignoring pragmatic reality. Maybe you watch a little bit too much television, but there…

If you don't see the chasm between "people should sacrifice themselves for the greater good" (which I'd generally disagree with, particularly if you're not defining what the greater good is) and "there is no greater good than defending one’s self" then I can't help you.

Re: 80% of orgs that paid the ransom were hit again

#203

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like that. People are always the first line of defense but it's one of those one-sided battles, where every single person in the entire company has to make 0 mistakes, and an attacker only has to get lucky once.

Re: 80% of orgs that paid the ransom were hit again

#204

How long do major companies keep back ups? It seems like all of these companies that keep getting hit with ransomware Only have last weeks back up laying around. Why can’t you go back eight months? True the data is going to be lacking, but at least the structure is going to be there. I completely understand that a Trojan or a virus can get locked into a back up and it just keeps getting backed up, but if you go far e…

I have yearly backups for three years. Right now, we could use one of those.

At my last place, they only kept 1 year and monthly, but the problem was it was hundreds of terabytes of data on lots of VMs. We tried to restore backups and it was going to take longer than the long weekend just for file transfer.

I don’t know what normal process is, but I believe I saw file locker Trojan that didn’t hit every byte of the drive; but rather crawled the file system and did a bit on every file header for speed. So I imagine it’s still faster to pay and fix than restore from backups for some.

Re: 80% of orgs that paid the ransom were hit again

#205
post #166

Earlier quoted context omitted.

Many people’s backup routines aren’t good enough. Some of these guys encrypt over a period of time which is long enough to exceed the backup rotation. Their code decrypts on request, until the trigger day, when it posts the banners and deletes itself.

Maybe corporations should make it standard practice to have cold storage backups that are physically disconnected from the network (by humans) in a rotated fashion. Backup A is physically disconnected on B days and backup B is physically disconnected on A days.

Or stored an a cloud storage provider that supports S3-style object lock.

Re: 80% of orgs that paid the ransom were hit again

#206

I don't see any discussion of typical entry points. How do these guys get into the system? Is it by having someone download a malicious file? If so what type of file? PDF? MS Office? If so Adobe and Microsoft should be held accountable for their security holes, only then will they have enough motivation to maybe consider rewriting some of their code in a safer language such as Rust.

Agree.

There is much confusion and many bad analogies surrounding this issue.

Some claim - without evidence - that nation states are behind it. Which, with a moments reflection, is absurd; nation states may have an interest in disabling certain systems for military purposes (at the appropriate time), but no nation state needs ransom money. Easier ways for a government to get money; namely, just print some.

Others liken it to the mafia or cartel or other well-organized criminal organizations. This too misses the mark.

Like most business crimes, the culprit is almost always an insider. Period. As the tools to pull this off are trivial to come by on the internet, the obvious suspect would be some disgruntled IT person within the company.

It’s as if — after a bank robbery — everyone claims it must have been some crack team of Russians flown in under radar in helicopters. Instead, they should be looking at the numerous employees who have access to the security system and the safe.

But, it’s much more exciting to pretend that Putin is sponsoring hackers to get trivial amounts of money from companies across the globe. Ha.

I’m not even an IT guy, but at my last job, even I had access sufficient to destroy or corrupt all the data. That was before cryptocurrency and the like... I assume assembling a ransomware set of tools off the internet is no more or less difficult than it was to assemble a set of tools to make pirated copies of AdobePhotshop back in the day.

Re: 80% of orgs that paid the ransom were hit again

#207
post #164
post #50

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.

The privately owned fire brigades in NYC 100 years ago weren't much better. The free market at work: https://www.youtube.com/watch?v=9zoXk1vnmcg The real Bowery Boys would sometimes sabotage other companies' insured buildings by setting the fires. https://en.wikipedia.org/wiki/Bowery_Boys

Setting fires on other peoples' property is not "the free market at work".

Re: 80% of orgs that paid the ransom were hit again

#208
post #12

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

I think it is, actually. Well, not advertised; but these big ransoms, they can be negotiated. And one of the victim company's requirements will be that if I pay, then you agree to leave me alone.

I think these negotiations are fine, if you're just buying time to gather your backups; I've assumed the payouts were made by insurance companies, so go ahead - buy a zero-value promise from a gang of crooks, if you want.

But your org has been rooted (at best, you can't prove it hasn't). Compromised systems can't be really be cleaned, they have to be reinstalled from scratch, if you want to have confidence in them.

And an attack can be stored in data - which you're about to restore from backup. That's a problem I have faced, and I chose to ignore that threat. No choice - I didn't know how to address it then, and I still don't now.

My half-baked opinions about ransomware are largely based on watching this documentary: https://www.bbc.co.uk/programmes/w172wx9056p6bd6

Re: 80% of orgs that paid the ransom were hit again

#209
post #66
post #18

I mean they just proved that they are willing to pay the ransom. If they are also unwilling or unable to clean up their shop and keep it from happening again, it surely will.

It is almost like the groups hacking them are providing a good service. If they get hacked once, shit happens. But if it happens multiple times then someone should probably answer for it.

[deleted]

Re: 80% of orgs that paid the ransom were hit again

#210
post #26
post #12

Earlier quoted context omitted.

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Makes more sense if the group offered a subscription model for decrypting files encrypted by that group. Then you wouldn't have to keep paying the big lump sum.

...and if you pay for our Premium Level Service, we'll secure your systems against other criminal enterprises as well!
Post reply on HN