Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

221–230 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#221

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

[deleted]

Re: 80% of orgs that paid the ransom were hit again

#222
post #12

Earlier quoted context omitted.

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

I think it is, actually. Well, not advertised; but these big ransoms, they can be negotiated. And one of the victim company's requirements will be that if I pay, then you agree to leave me alone. I think these negotiations are fine, if you're just buying time to gather your backups; I've assumed the payouts were made by insurance companies, so go ahead - buy a zero-value promise from a gang of crooks, if you want. Bu…

> And one of the victim company's requirements will be that if I pay, then you agree to leave me alone.

I'm curious how one would enforce that. From the fact that the ransom got paid in the first place, we can establish that there's no legal body that's able and willing to exercise any authority over the ransomware group. So it's not like you can sue them for breach of contract.

Perhaps you can rely on the honor system? Though, given this is a group of professional extortionists we're talking about, if you choose to go that route, you may be at elevated risk of getting what you deserve.

Re: 80% of orgs that paid the ransom were hit again

#223
Ransomware is actually a net benefit. They force information security into the business agenda in a way that we haven’t really been able to accomplish before. You can now quantify the cost of getting pwned. It’s a bit like the immune system needing pathogens every once in a while.

Re: 80% of orgs that paid the ransom were hit again

#224
post #21
post #2

Once you pay 'em the Danegeld You'll never be rid of the Dane

I don't see why you have to pick on the Danes :) But the similarities are there, although the person's behind the ransomware attacks are probably not vikings.

The ancestors of the Russians were themselves Vikings. Their kingdom of Rus is where the name came from.

Re: 80% of orgs that paid the ransom were hit again

#225

Earlier quoted context omitted.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

A single computer should never have access to all the company's data. Neither should a single login.

It's like compartmentalization on a battleship. A single hole won't sink it, in fact, many holes won't.

Re: 80% of orgs that paid the ransom were hit again

#226
post #200
post #185

Earlier quoted context omitted.

Coming soon: ransomware with subscription business model

I up voted you for the lulz, but I'm actually unsure if this isn't the basic "legitimate" business model for everyone anyway.

I'm not so unsure - that's what make's it funny

Re: 80% of orgs that paid the ransom were hit again

#227
post #212

Earlier quoted context omitted.

Setting fires on other peoples' property is not "the free market at work".

But the rest of it was. The part in the first half of my message and the linked video is entirely free-market. Also, please do the work to expound on your claim.

> do the work to expound on your claim

A free market system requires protection of property rights. Arson violates property rights, and so is not free market.

Re: 80% of orgs that paid the ransom were hit again

#228

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

You have to have backup. You can't trust professional crooks, because - well - they're crooks.

If you are penetrated, it's not so easy as just restoring your data from backup. You have to sterilise the machines you are restoring to. And you have to sterilise the data you want to restore. CM automation can deal with the system sterlisation, but I don't know how to sterilise data without using human judgement.

Don't get penetrated.

Re: 80% of orgs that paid the ransom were hit again

#230
post #66
post #18

I mean they just proved that they are willing to pay the ransom. If they are also unwilling or unable to clean up their shop and keep it from happening again, it surely will.

It is almost like the groups hacking them are providing a good service. If they get hacked once, shit happens. But if it happens multiple times then someone should probably answer for it.

"We don't have money in the budget for backups. But we do have money in a different budget for ransom payments!"
Post reply on HN