Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

291–300 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#291

Earlier quoted context omitted.

If you believe banning cryptocurrencies will suddenly stop ransomware, then I have a bridge to sell you.

In the theoretical universe where banning crypto is possible, yes it would stop almost all ransomware of the scale we see reported in news today. There's just no other form of payment which would work for them. You can't easily go "can I have $50k worth of giftcards" and on the receiving side you can't easily validate or sell millions of them without tanking the value. Any kind of wire transfer would expose the sourc…

>...theoretical universe where banning crypto is possible...

Money grows on trees, there, too.

I'll bet you dollars to donuts that if you made crypto illegal, there's still a whole lot of countries that won't give a shit and the problem will only get worse.

All these situations are nebulous and complicated, something as simple as legally banning crypto is not going to solve the problems.

Re: 80% of orgs that paid the ransom were hit again

#292
post #283

The standard business solution to solve security issues - for example like having all your database in a public folder - is to get a guy to implement "security" (whatever that means) who is 40 years old and is really confident he knows what he is doing. He will go configure some firewalls and stuff that has absolutely nothing to do with preventing any real risk aside from automated attacks. Every time someone still g…

Did you choose 40 year old because it’s too old, or because it’s too young? I genuinely can’t tell

The essential point is that he's 40 and still doesn't know what he's doing (a common problem in any technical field).

Re: 80% of orgs that paid the ransom were hit again

#293

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

> who already screw the public day in day out

And then everyone clapped at the high-brow analysis.

Re: 80% of orgs that paid the ransom were hit again

#294

Earlier quoted context omitted.

Which vulnerability did the attackers use to gain initial access? Do the attackers disclose this along with decrypting the data? And are you sure they didn't leave a sleeper Trojan behind for later?

A few months ago one chat between hackers and the company was leaked. The hacker actually explained how to fix the vulnerabilities. On mobile but it should show up in google (think it was posted here on hn also)

This assumes the blackmailer is trustworthy.

Re: 80% of orgs that paid the ransom were hit again

#295
post #196

Earlier quoted context omitted.

They’re supposed to back up their data and set up proper contingencies. By failing to do so, they are already putting patients lives in the hands of the encryptors.

Yes. Of course they were supposed to do so, then . But they didn't, and now they've been hit. Now, in the real world, what are they supposed to do: pay, or hold out and let the patients die as punishment for the hospital's mistakes?

Let the patients die. That’s on the hackers hands, not the hospital. Additionally, you’re making a huge assumption that the hackers are willing to escalate themselves to mass murders, which is a big leap most criminals aren’t willing to take.

Re: 80% of orgs that paid the ransom were hit again

#296

Earlier quoted context omitted.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

There are many steps in the chain between a phish message and a ransomware attack - the user opening a phish is just one of them. You might prevent lateral movement afterwards, you may detect the attack in time (there often are days or even weeks between the phish and the ransom) to protect it, you might prevent the payload from reaching the user, etc. So yes, you're right, the solution is not just better backups but…

>... however that takes will, money and quite some time.

And the accounting folks will not be fans of anything that costs money. They will just say "But we haven't been attacked a second time, why should we pay for mitigation services and implementations??"

Re: 80% of orgs that paid the ransom were hit again

#297

Earlier quoted context omitted.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

> where every single person in the entire company has to make 0 mistakes, and an attacker only has to get lucky once Good post. I don’t mean this criticism for you specifically. But, why is there an assumption among HN types that there are no bad-actors among the insiders? You can have all the safeguards you want, but if an insider deliberately installs something, you’re screwed. In some industries — armored trucks,…

Yeah this is a great point, you gotta figure that armored trucks, banks, military stuff, they all have functional physical access control, clearly defined risks, established value, etc. The person wheeling the dolly full of cash and the driver of the truck... well you know those two people are going to be handling bulk cash. The MP guarding the nukes is standing at the checkpoint. Check em' because you can just move on to the next person.

But in the corporate world, theres gotta be huge variance, but so many don't give a flying flamingo who's scoping out what, unless somebody is forcing the issue (and also auditing and reporting to the compliance department, whatever thats for).

They know the people in the NOC/SOC, the C-suite has equity, there may be physical access control, cameras and proxcards out the wazoo, but when Marge from bizdev needs those emails for the marketing newsletter or whatever, she is gonna get them immediately and hand them right over to the intern or vendor or Doug, whatever his job is.

For all the obscene value that the data and access represents, its encrypted, right? What could go wrong? Want to background check the sales people? But... look at this guy's resume! He's only asking 80% of the market rate! These dialysis machines sure won't renew their support contract by themselves.

Best case scenario is that the costs mount even higher into the stratosphere and people start demanding a second look. It's been a while, Maersk, JP Morgan, TransUnion, Colonial Pipeline, Beef, Hospitals, Schools, the OPM (for god's sake...) billions or trillions of dollars. It doesn't seem to be a priority.

Re: 80% of orgs that paid the ransom were hit again

#298
post #260

Earlier quoted context omitted.

Lack of MFA, lack of hardware whitelisting, servers exposed directly to the Internet, lack of user privilege restrictions, allowing passwords that are known-compromised, ...

If so, it doesn't make sense to blame Putin. The blame lies on US lawmakers, for not incentivizing US businesses to have a budget for fixing these sorts of issues. For example, when companies such as Equifax are hacked because of poor security practices do they pay a penalty? No. That's the problem.

There is a lot of blame to go around.

Re: 80% of orgs that paid the ransom were hit again

#299
post #183

Hey guys - I know security is hard to justify cost-wise but if you get hit by ransomware then shape up and actually do some due-diligence around your data stewardship. Wait - is this how the market fixes poor security practices?

More like a hostile and unregulated environment adding costs to doing business.

Re: 80% of orgs that paid the ransom were hit again

#300
post #273

Earlier quoted context omitted.

There is an easy fix here: make it illegal for companies to transact in crypt currencies. Then they would have no way of paying a ransom without engaging in illegal activities. This would destroy the ransomware business model.

There was ransomware before crypto currencies. There will be ransomware after crypto currencies.

There was? How did it work? Bank transfers?
Post reply on HN