Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

241–250 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#242
post #23

Anyone else think we should make it illegal to pay ransom? These people are just financing the next generation of cyber criminals. Once people stop paying, people will stop attacking.

No. Not with profit margins that high compared to operational cost, it would not be an effective deterrent. They will just continue to hit as many targets as possible. You would end up punishing the victims. What if they target some really critical infrastructure, where it would be rational to just pay and then fix the holes? Seek exemptions from law for each?

But it would be very interesting to see if the ransomware gangs can devise a scheme that gives the payer plausible deniability.

Re: 80% of orgs that paid the ransom were hit again

#243

Earlier quoted context omitted.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

> where every single person in the entire company has to make 0 mistakes, and an attacker only has to get lucky once

Good post. I don’t mean this criticism for you specifically. But, why is there an assumption among HN types that there are no bad-actors among the insiders? You can have all the safeguards you want, but if an insider deliberately installs something, you’re screwed.

In some industries — armored trucks, banks, military stuff — there is a huge emphasis on background checks, security clearances, and the like to weed out bad actors. (And, even then, it often fails.)

I sense there is nothing similar for employees handling the company’s data. Obviously, there might be background checks and the like — hell, McDonalds has background checks. But, I’m not aware of the intensive FBI-style screening you see in the aforementioned realms.

Am I wrong?

How many thousands of people, for instance, could corrupt or lock the data at, say, Amazon? Are these people scrutinized to the same level as standard Brinks Armored Truck driver? I doubt it.

Re: 80% of orgs that paid the ransom were hit again

#244
post #26

Earlier quoted context omitted.

Makes more sense if the group offered a subscription model for decrypting files encrypted by that group. Then you wouldn't have to keep paying the big lump sum.

...and if you pay for our Premium Level Service, we'll secure your systems against other criminal enterprises as well!

What Hackers Can Learn From The Sopranos.

Re: 80% of orgs that paid the ransom were hit again

#245
post #66

Earlier quoted context omitted.

It is almost like the groups hacking them are providing a good service. If they get hacked once, shit happens. But if it happens multiple times then someone should probably answer for it.

"We don't have money in the budget for backups. But we do have money in a different budget for ransom payments!"

"how much you got?"

Re: 80% of orgs that paid the ransom were hit again

#246
post #185
post #12

Earlier quoted context omitted.

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Coming soon: ransomware with subscription business model

That's already a thing

"SCHWIRTZ: What DarkSide does is they're a ransomware creator. So they create the program that is uploaded into a victim's computer system that locks down their data. But what they do is they basically contract out to these affiliates who are other hackers. And these are the people that are responsible for actually penetrating the victim's computer services. And what they do is operate basically on a subscription service. You, as an affiliate, can sign on to DarkSide services, in which case you get access to their malware, their ransomware to use for a fee that operates on a sliding scale depending upon the size of the ransom."

https://www.npr.org/2021/06/10/1005093802/inner-workings-of-...

Re: 80% of orgs that paid the ransom were hit again

#247
post #154

Earlier quoted context omitted.

If only organizations would backup their own data. Then they could just restore and avoid paying. This is commonly suggested, and entirely useless. What the ransomware groups do is put a time bomb on the computer, then leave it to trigger on a future condition. Your backup will backup the time bomb, and the second you restore it, it also goes boom. And therefore your backup is a perfect copy of your data but entirely…

That assumes the backup couples the data and compute together, like a system image or something. If the backup is just data and is somewhere else, you can just rebuild the compute infrastructure from a known secure state (which arguably may require rebuilding the entire compute environment). Even if your backup does couple the data and compute together, if it's simply time based (not sure what other event you could u…

First of all the goal is to make people not trust their backups. So they study and target the systems that do backups and restores. If you are separating data from systems, they have a number of tricks. One is to have the backup system corrupt data in subtle ways. Sure, you have a backup. But you can't trust it. And they make sure that you KNOW you can't trust it by pointing you at some easily verifiable corruption...and not letting you know what ELSE they changed.

But as for an event to use, what they can do is have the machine check a remote URI to see whether it should let the system run, and if it should then set itself up to lock things at a specified time. In order to restore that you need to have it starting on a network with networking to a system that has the attacker's private key to sign the request. This is not an environment that you are able to create.

Re: 80% of orgs that paid the ransom were hit again

#248
post #154

Earlier quoted context omitted.

If only organizations would backup their own data. Then they could just restore and avoid paying. This is commonly suggested, and entirely useless. What the ransomware groups do is put a time bomb on the computer, then leave it to trigger on a future condition. Your backup will backup the time bomb, and the second you restore it, it also goes boom. And therefore your backup is a perfect copy of your data but entirely…

This is not entirely useless as you still have a backup of the data, you just need to restore it without the "time bomb".

Good luck finding the time bomb. See also my above comments about ways that they can corrupt data.

Re: 80% of orgs that paid the ransom were hit again

#249

Earlier quoted context omitted.

> And one of the victim company's requirements will be that if I pay, then you agree to leave me alone. I'm curious how one would enforce that. From the fact that the ransom got paid in the first place, we can establish that there's no legal body that's able and willing to exercise any authority over the ransomware group. So it's not like you can sue them for breach of contract. Perhaps you can rely on the honor syst…

It's a matter of reputation. If a ransomware group has a reputation of not actually delivering the unlock upon payment, or of re-infection shortly afterwards, the decision to pay them becomes harder to defend.

I don't know that you can even reliably identify what ransomware group you're dealing with. They seem to use similar software, wallet addresses can change, people can claim to be some group they aren't, etc. And they probably identify potential victims with similar methods and tools.

Re: 80% of orgs that paid the ransom were hit again

#250

Doesnt this just mean that 80% of orgs that were hit with ransomware attacks just didn't bother to fix their infosec, and got hit again because they left the same holes open to be exploited? Fool me once, shame on you. Fool me twice, shame on me.

> Fool me once, shame on you. Fool me twice, you're not going to fool me twice.

- These Companies (probably)

Post reply on HN