Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

251–260 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#251

Earlier quoted context omitted.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

>> But it only takes one person and these huge companies employ so many people.

No. It never takes only one employ clicking a bad link. It takes that click, plus a browser/email/os system that allow for random code to executed. It take an IT department that has allowed individual non-IT employees to use computers with elevated privileges. It requires a management structure that has failed to invest in proper off-site/cold backups. It requires an organization that doesn't have a proper business continuity plan.

And at the top of the incompetency pyramid, it requires a vendor that sells an email system that allows evil email messages to somehow infect entire operating systems. Want your email to connect to your office suite? Sure. Want to install random software based on clicked links? Sure thing. Want to update your firewall, install a new browsers and simultaneously backup all your encryption keys to a random server in the far east? Why not! Anything to make your operating system experience seamless.

Re: 80% of orgs that paid the ransom were hit again

#252
post #149

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

When they hit a hospital, what is the hospital supposed to do? Not negotiate, for some "greater good" and let patients die? https://threatpost.com/ransomware-hits-hospitals-hardest/162...

Yes.

Re: 80% of orgs that paid the ransom were hit again

#253

Earlier quoted context omitted.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

> where every single person in the entire company has to make 0 mistakes, and an attacker only has to get lucky once Good post. I don’t mean this criticism for you specifically. But, why is there an assumption among HN types that there are no bad-actors among the insiders? You can have all the safeguards you want, but if an insider deliberately installs something, you’re screwed. In some industries — armored trucks,…

I guess there's two questions:

- is protecting against internal sabotage actually different that protecting against external attack. I don't think it's all that different. It comes down to authenticating actions and enforcing the principle of least privilege. If you built a system that was actually secure (i.e. one that depends on reasonable inconveniences, rather than one that depends on people to be perfect all the time or is so inconvenient it inclines them to do the digital equivalent of jamming the door open) it is likely that it will be secure enough against most internal saboteurs.

- is protecting against internal sabotage going to pay off? Most people probably aren't inclined to deliberately target their own company. It's far more likely that there is a bad actor in the world who wants to target your company, than that there is in your company. And making a person's job secure less stable is probably going to make them more likely to be a saboteur, so you should carefully evaluate whether gratuitously adding stress to someone who might get behind on their mortgage is a good idea. (Which I suppose is what this kind of background check would cause.)

Re: 80% of orgs that paid the ransom were hit again

#255

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Were I an evil criminal, I'd include a backdoor in the restore image I gave them, so that I could attack the same people again.

Re: 80% of orgs that paid the ransom were hit again

#256
post #26

Earlier quoted context omitted.

Makes more sense if the group offered a subscription model for decrypting files encrypted by that group. Then you wouldn't have to keep paying the big lump sum.

...and if you pay for our Premium Level Service, we'll secure your systems against other criminal enterprises as well!

Some groups will actually tell you how they got in and help you patch your systems.

Some groups will hack you AND also uninstall viruses emanating from other groups, or they will hack you and patch other flaws so that other malwares cannot take their spot. It's all game theory.

Re: 80% of orgs that paid the ransom were hit again

#257

Earlier quoted context omitted.

> where every single person in the entire company has to make 0 mistakes, and an attacker only has to get lucky once Good post. I don’t mean this criticism for you specifically. But, why is there an assumption among HN types that there are no bad-actors among the insiders? You can have all the safeguards you want, but if an insider deliberately installs something, you’re screwed. In some industries — armored trucks,…

I guess there's two questions: - is protecting against internal sabotage actually different that protecting against external attack. I don't think it's all that different. It comes down to authenticating actions and enforcing the principle of least privilege. If you built a system that was actually secure (i.e. one that depends on reasonable inconveniences, rather than one that depends on people to be perfect all the…

Malware comes from the outside. Stealing company secrets and selling them is what I would be worried about from internal threats. Either way least access necessarily where possible is a good strategy.

Re: 80% of orgs that paid the ransom were hit again

#258

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

And let's not discount the moral of low paid, overworked employees, and companies that let low level managers run roughshod over lower level employees. My point is don't discount inside corporate espionage by disgruntled any level employees.

Thank goodness I didn't have access to a script that would lock up at least two of my past employers when coming up years ago? Then again, I personally haven't been that mad, but boy do I know employees who were.

I could say that we are all choir boys, but you piss on an employee, especially during a recession, well let's just say I have seen unpstanding guys rub magnets over hard drives over pure apathy. (The guy didn't know about strength of magnents, and it did not hurt anything.)

Plugging in a usb, or downloading a suspicious email is something I can see happening, especially to "those" companies.

I imagine Xfinity employees dream about it?

Re: 80% of orgs that paid the ransom were hit again

#259

Earlier quoted context omitted.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

A single computer should never have access to all the company's data. Neither should a single login. It's like compartmentalization on a battleship. A single hole won't sink it, in fact, many holes won't.

Most people's enterprise software is akin to an already waterlogged dingy.

Re: 80% of orgs that paid the ransom were hit again

#260

I don't see any discussion of typical entry points. How do these guys get into the system? Is it by having someone download a malicious file? If so what type of file? PDF? MS Office? If so Adobe and Microsoft should be held accountable for their security holes, only then will they have enough motivation to maybe consider rewriting some of their code in a safer language such as Rust.

The entry points are "whatever works". Typically: * Password spraying from previous data leaks * Good old-fashioned fishing * Bugs in anything that's common in enterprises, exposed to the Internet and not patched fast enough, including MS Exchange, various security/VPN products, vcenter, you name it. All of these had pretty critical pre-auth bugs exposed just this year * malicious browser plugins * malicious O365 app…

Lack of MFA, lack of hardware whitelisting, servers exposed directly to the Internet, lack of user privilege restrictions, allowing passwords that are known-compromised, ...
Post reply on HN