Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

231–240 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#231

Earlier quoted context omitted.

I think it is, actually. Well, not advertised; but these big ransoms, they can be negotiated. And one of the victim company's requirements will be that if I pay, then you agree to leave me alone. I think these negotiations are fine, if you're just buying time to gather your backups; I've assumed the payouts were made by insurance companies, so go ahead - buy a zero-value promise from a gang of crooks, if you want. Bu…

> And one of the victim company's requirements will be that if I pay, then you agree to leave me alone. I'm curious how one would enforce that. From the fact that the ransom got paid in the first place, we can establish that there's no legal body that's able and willing to exercise any authority over the ransomware group. So it's not like you can sue them for breach of contract. Perhaps you can rely on the honor syst…

It's a matter of reputation.

If a ransomware group has a reputation of not actually delivering the unlock upon payment, or of re-infection shortly afterwards, the decision to pay them becomes harder to defend.

Re: 80% of orgs that paid the ransom were hit again

#232

Why not just criminalize paying ransoms? Remove incentives and don't fund criminals.

Because in the short term, this could have some pretty nasty consequences for some companies that are hit the hardest, and few politicians want to take that hit.

Re: 80% of orgs that paid the ransom were hit again

#234
post #185
post #12

Earlier quoted context omitted.

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Coming soon: ransomware with subscription business model

“Up next on ‘You Won’t Believe It’, viruses were created by the antivirus industry”

Re: 80% of orgs that paid the ransom were hit again

#235

Rudyard Kipling explained this: --- But we've proved it again and again, / That if once you have paid him the Dane-geld / You never get rid of the Dane. --- https://www.poetryloverspage.com/poets/kipling/dane_geld.htm... . By paying, you’ve just proven that you are a profitable target to hit.

I'm from Dublin. We didn't pay the Danegeld, and in retaliation they built a city.

Re: 80% of orgs that paid the ransom were hit again

#236

I don't see any discussion of typical entry points. How do these guys get into the system? Is it by having someone download a malicious file? If so what type of file? PDF? MS Office? If so Adobe and Microsoft should be held accountable for their security holes, only then will they have enough motivation to maybe consider rewriting some of their code in a safer language such as Rust.

The entry points are "whatever works".

Typically:

* Password spraying from previous data leaks

* Good old-fashioned fishing

* Bugs in anything that's common in enterprises, exposed to the Internet and not patched fast enough, including MS Exchange, various security/VPN products, vcenter, you name it. All of these had pretty critical pre-auth bugs exposed just this year

* malicious browser plugins

* malicious O365 apps

... and so on.

Re: 80% of orgs that paid the ransom were hit again

#237

Earlier quoted context omitted.

> And one of the victim company's requirements will be that if I pay, then you agree to leave me alone. I'm curious how one would enforce that. From the fact that the ransom got paid in the first place, we can establish that there's no legal body that's able and willing to exercise any authority over the ransomware group. So it's not like you can sue them for breach of contract. Perhaps you can rely on the honor syst…

It's a matter of reputation. If a ransomware group has a reputation of not actually delivering the unlock upon payment, or of re-infection shortly afterwards, the decision to pay them becomes harder to defend.

A sticky problem indeed. I'm sure their sock puppet budgets must run into the tens of dollars.

Re: 80% of orgs that paid the ransom were hit again

#238
post #18

I mean they just proved that they are willing to pay the ransom. If they are also unwilling or unable to clean up their shop and keep it from happening again, it surely will.

The responsibility lies at the nation-state level, and the clear decision is for Governments to ban the formal exchange of cryptocurrencies. As soon as this occurs, ransomware events will collapse since the ransoms will become unpayable. The negatives of cryptocurrencies (ransomware enablement, chip and electricity shortages, scams) clearly outweigh the positives at this point.

If you believe banning cryptocurrencies will suddenly stop ransomware, then I have a bridge to sell you.

Re: 80% of orgs that paid the ransom were hit again

#239
Security is impossible. As long as there are incentives, nothing will be secure. It’s just a matter of incentive/difficulty. With enough incentive stuxnet or solar winds or omb are possible. Bitcoin values are causing this equilibrium to be disrupted, making this appear as though it were a new problem.

Re: 80% of orgs that paid the ransom were hit again

#240

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

"“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions"

The word 'terrorists', for one. It's mostly used to mean 'my opponents' these days.

What we are facing with ransomware is not insurrectionists or protestors, but gangsters. They make their living by stealing from people, cheating them, and threatening them. Many insurrectionists are honourable people that you can safely make a deal with. There is no gangster with that property.

Take backups, test the recovery procedure, don't make bargains with gangsters.

Post reply on HN