Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

271–280 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#271

Earlier quoted context omitted.

If you believe banning cryptocurrencies will suddenly stop ransomware, then I have a bridge to sell you.

There is an easy fix here: make it illegal for companies to transact in crypt currencies. Then they would have no way of paying a ransom without engaging in illegal activities. This would destroy the ransomware business model.

Then you hire the services of brokers that don't have the same compunctions about transacting in crypto. And even if you were to magically erase all cryptocurrency from the earth, it wouldn't still stop ransomware, or the same state sponsored actors would gravitate towards even worse things.

It's like nobody has learned a thing from the war on drugs, my point being: you deal with the root cause of the disease (infosec in most companies and even government offices is a joke and bad people have taken notice), not playing whack-a-mole with the symptoms (crypto use) that hint towards systemic decay.

Re: 80% of orgs that paid the ransom were hit again

#272

Earlier quoted context omitted.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

I genuinely don't put any faith in education. Every phishing education program I've seen has effectively said "look out for weird emails, (perhaps with misspellings) and if you see them report them to security!" I haven't seen any which went into the real specifics which might actually educate users:

- A phishing email which can pwn you without user interaction is basically unheard of.

- Even malicious sites generally can't do anything bad simply by visiting them. (and yes, I'm aware browser exploitation exists, but it is exceedingly rare)

- Ultimately, it's entering your credentials in a malicious site which is what puts users at risk. A user must click a malicious link (sometimes two) and then intentionally enter their credentials into the malicious site.

Between this, and the fact that users must read emails, visit sites, and enter their credentials over and over, just to get through their workday, I believe the outcome is that user education doesn't amount to much. It would be much better if a normal user's workflow didn't usually require clicking on email links and then entering their credentials. The fact that this is required means that even a savvy users will eventually be tired / rushed / working on automatic and get owned.

Re: 80% of orgs that paid the ransom were hit again

#273

Earlier quoted context omitted.

If you believe banning cryptocurrencies will suddenly stop ransomware, then I have a bridge to sell you.

There is an easy fix here: make it illegal for companies to transact in crypt currencies. Then they would have no way of paying a ransom without engaging in illegal activities. This would destroy the ransomware business model.

There was ransomware before crypto currencies. There will be ransomware after crypto currencies.

Re: 80% of orgs that paid the ransom were hit again

#274

Earlier quoted context omitted.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

I genuinely don't put any faith in education. Every phishing education program I've seen has effectively said "look out for weird emails, (perhaps with misspellings) and if you see them report them to security!" I haven't seen any which went into the real specifics which might actually educate users: - A phishing email which can pwn you without user interaction is basically unheard of. - Even malicious sites generall…

Which is why basic stuff like MFA and MDM (block sign-ins coming from non compliant devices) works wonders against ransomware attacks.

Re: 80% of orgs that paid the ransom were hit again

#275

Earlier quoted context omitted.

The responsibility lies at the nation-state level, and the clear decision is for Governments to ban the formal exchange of cryptocurrencies. As soon as this occurs, ransomware events will collapse since the ransoms will become unpayable. The negatives of cryptocurrencies (ransomware enablement, chip and electricity shortages, scams) clearly outweigh the positives at this point.

If you believe banning cryptocurrencies will suddenly stop ransomware, then I have a bridge to sell you.

In the theoretical universe where banning crypto is possible, yes it would stop almost all ransomware of the scale we see reported in news today.

There's just no other form of payment which would work for them. You can't easily go "can I have $50k worth of giftcards" and on the receiving side you can't easily validate or sell millions of them without tanking the value. Any kind of wire transfer would expose the source immediately at that scale. There's only so much money you can move through services that give you kickbacks of various kinds. What else is left?

Basically unless ransomware teams know of a new really good way of laundering money without a trail, or are happy to take a massive pay cut, that would be the end of most of their operations.

Re: 80% of orgs that paid the ransom were hit again

#276
post #143

Earlier quoted context omitted.

No, but the people operating in Russia like to travel elsewhere, and do. Also, the US and allies can enforce Russian AML laws as written on paper. If, say, the UK freezes all of Oleg Deripaska's assets there, Vova will absolutely get the message. We're not going to bring down the Russian government with military force for a million different reasons, but doing it with sanctions and prosecution is a totally different…

When they do US gets them. That happens from time to time, if you watch the news, you notice there are guys caught periodically who thought it's time for a nice vacation in Spain resting from their criminal activities... only to be picked up in the airport. However, the smarter ones stay put inside Russia and those are hard to get.

Best example was when VW's Oliver Schmidt was arrested in Miami as he was changing planes. He was in trouble from the emissions fraud scheme.

Re: 80% of orgs that paid the ransom were hit again

#277
post #18

I mean they just proved that they are willing to pay the ransom. If they are also unwilling or unable to clean up their shop and keep it from happening again, it surely will.

The responsibility lies at the nation-state level, and the clear decision is for Governments to ban the formal exchange of cryptocurrencies. As soon as this occurs, ransomware events will collapse since the ransoms will become unpayable. The negatives of cryptocurrencies (ransomware enablement, chip and electricity shortages, scams) clearly outweigh the positives at this point.

This view is similar to saying things like "The terrorists and the media have a symbiotic relationship and the media is responsible for enabling terrorist attacks, therefore let's ban the media".

Re: 80% of orgs that paid the ransom were hit again

#279
post #249

Earlier quoted context omitted.

It's a matter of reputation. If a ransomware group has a reputation of not actually delivering the unlock upon payment, or of re-infection shortly afterwards, the decision to pay them becomes harder to defend.

I don't know that you can even reliably identify what ransomware group you're dealing with. They seem to use similar software, wallet addresses can change, people can claim to be some group they aren't, etc. And they probably identify potential victims with similar methods and tools.

How would the statistics then be gathered that half were hit by the same?

Re: 80% of orgs that paid the ransom were hit again

#280

Earlier quoted context omitted.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

And let's not discount the moral of low paid, overworked employees, and companies that let low level managers run roughshod over lower level employees. My point is don't discount inside corporate espionage by disgruntled any level employees. Thank goodness I didn't have access to a script that would lock up at least two of my past employers when coming up years ago? Then again, I personally haven't been that mad, but…

"I have seen unpstanding guys rub magnets over hard drives over pure apathy."

Open up a spinning rust hard drive and you will find two very strong magnets inside, positioned opposite each other.

Post reply on HN