Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

281–290 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#281

Earlier quoted context omitted.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

>> But it only takes one person and these huge companies employ so many people. No. It never takes only one employ clicking a bad link. It takes that click, plus a browser/email/os system that allow for random code to executed. It take an IT department that has allowed individual non-IT employees to use computers with elevated privileges. It requires a management structure that has failed to invest in proper off-site…

that's what I'm saying. Just training isn't enough the system has to be hardened.

Re: 80% of orgs that paid the ransom were hit again

#282

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

There are many steps in the chain between a phish message and a ransomware attack - the user opening a phish is just one of them. You might prevent lateral movement afterwards, you may detect the attack in time (there often are days or even weeks between the phish and the ransom) to protect it, you might prevent the payload from reaching the user, etc. So yes, you're right, the solution is not just better backups but stepping up the whole security game - however that takes will, money and quite some time.

Re: 80% of orgs that paid the ransom were hit again

#283
The standard business solution to solve security issues - for example like having all your database in a public folder - is to get a guy to implement "security" (whatever that means) who is 40 years old and is really confident he knows what he is doing. He will go configure some firewalls and stuff that has absolutely nothing to do with preventing any real risk aside from automated attacks. Every time someone still gets the files from some 90's vuln, everyone is surprised that some sooper dooper hacker wizard was able to own their fortune 500 company.

> The least deployed solutions post-attack included web scanning (40%), endpoint detection and response (EDR) and extended detection and response (XDR) technologies (38%), antivirus software (38%), mobile and SMS security solutions (36%), and managed security services provider (MSSP) or managed detection and response (MDR) provider (34%). Only 3% of respondents said they did not make any new security investments after a ransomware attack.

uh huh. uh huh. uh huh. uh huh.

Meanwhile, for example, earlier today: a web search for "cat /etc/passwd" blocks my IP. What even is the point of this article? _Of course_ if you don't patch they will just hack you again. _Of course_ if your company follows terrible 90's practices, it will get owned again.

Re: 80% of orgs that paid the ransom were hit again

#284
post #283

The standard business solution to solve security issues - for example like having all your database in a public folder - is to get a guy to implement "security" (whatever that means) who is 40 years old and is really confident he knows what he is doing. He will go configure some firewalls and stuff that has absolutely nothing to do with preventing any real risk aside from automated attacks. Every time someone still g…

So, what age must one be to supervise implementing security practices at an organization?

Re: 80% of orgs that paid the ransom were hit again

#285
post #12

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

You sure some ransomware crooks don't provide contracts to their clients?

Re: 80% of orgs that paid the ransom were hit again

#286
post #283

The standard business solution to solve security issues - for example like having all your database in a public folder - is to get a guy to implement "security" (whatever that means) who is 40 years old and is really confident he knows what he is doing. He will go configure some firewalls and stuff that has absolutely nothing to do with preventing any real risk aside from automated attacks. Every time someone still g…

Did you choose 40 year old because it’s too old, or because it’s too young? I genuinely can’t tell

Re: 80% of orgs that paid the ransom were hit again

#287
post #18

I mean they just proved that they are willing to pay the ransom. If they are also unwilling or unable to clean up their shop and keep it from happening again, it surely will.

The responsibility lies at the nation-state level, and the clear decision is for Governments to ban the formal exchange of cryptocurrencies. As soon as this occurs, ransomware events will collapse since the ransoms will become unpayable. The negatives of cryptocurrencies (ransomware enablement, chip and electricity shortages, scams) clearly outweigh the positives at this point.

Ah yes, we should outlaw the ability for people to send money to each other and have civilization take the burden of incompetent corporations that can't be bothered to follow basic infosec practices (let alone whatever product they are selling in the first place is probably garbage and has no value beyond monopoly).

Re: 80% of orgs that paid the ransom were hit again

#288
post #18

I mean they just proved that they are willing to pay the ransom. If they are also unwilling or unable to clean up their shop and keep it from happening again, it surely will.

The responsibility lies at the nation-state level, and the clear decision is for Governments to ban the formal exchange of cryptocurrencies. As soon as this occurs, ransomware events will collapse since the ransoms will become unpayable. The negatives of cryptocurrencies (ransomware enablement, chip and electricity shortages, scams) clearly outweigh the positives at this point.

The ransom side is already a crime, and it being labeled a crime doesn't stop it from happening. Laws don't prevent crime.

Re: 80% of orgs that paid the ransom were hit again

#289

Earlier quoted context omitted.

There is an easy fix here: make it illegal for companies to transact in crypt currencies. Then they would have no way of paying a ransom without engaging in illegal activities. This would destroy the ransomware business model.

Then you hire the services of brokers that don't have the same compunctions about transacting in crypto. And even if you were to magically erase all cryptocurrency from the earth, it wouldn't still stop ransomware, or the same state sponsored actors would gravitate towards even worse things. It's like nobody has learned a thing from the war on drugs, my point being: you deal with the root cause of the disease (infose…

The root cause is the blackmailers/thieves committing the crime, not that the crime was easy. Addressing the root cause might include things like improving education and reducing poverty. That in combination with a bam on paying ransoms would likely reduce these crimes.

Re: 80% of orgs that paid the ransom were hit again

#290

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Or they overhauled the IT team.
Post reply on HN