Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

301–310 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#301
post #3

Meaningless stat without a baseline to compare against. How many who didn't pay were hit again?

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

The attacks are likely automated. Like any computer virus.

Re: 80% of orgs that paid the ransom were hit again

#302

Earlier quoted context omitted.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

And let's not discount the moral of low paid, overworked employees, and companies that let low level managers run roughshod over lower level employees. My point is don't discount inside corporate espionage by disgruntled any level employees. Thank goodness I didn't have access to a script that would lock up at least two of my past employers when coming up years ago? Then again, I personally haven't been that mad, but…

I used to care for the security of my work machine. I was sole admin. No corporate crap- or spyware. I was responsible and I learned a lot.

We got bought. Big corp enforced Endpoint Management and a whole barrage of corporate spyware.

I am not an admin anymore. I can't even use an AdBlock solution anymore.

And guess what. I don't give a damn anymore. If the device enforces an update, so he it. If I have to double approve every external mail address when sending, so be it.

But I don't feel ownership or responsibility anymore. Should corporate overlords care. I am out.

Re: 80% of orgs that paid the ransom were hit again

#303

I don't see any discussion of typical entry points. How do these guys get into the system? Is it by having someone download a malicious file? If so what type of file? PDF? MS Office? If so Adobe and Microsoft should be held accountable for their security holes, only then will they have enough motivation to maybe consider rewriting some of their code in a safer language such as Rust.

The entry points are "whatever works". Typically: * Password spraying from previous data leaks * Good old-fashioned fishing * Bugs in anything that's common in enterprises, exposed to the Internet and not patched fast enough, including MS Exchange, various security/VPN products, vcenter, you name it. All of these had pretty critical pre-auth bugs exposed just this year * malicious browser plugins * malicious O365 app…

- VBA macros

- ActiveX for legacy ad-hoc software

Re: 80% of orgs that paid the ransom were hit again

#304

Earlier quoted context omitted.

If you believe banning cryptocurrencies will suddenly stop ransomware, then I have a bridge to sell you.

There is an easy fix here: make it illegal for companies to transact in crypt currencies. Then they would have no way of paying a ransom without engaging in illegal activities. This would destroy the ransomware business model.

(not saying I think this is a solution, but...)

If the goal is to stop companies from paying ransom, then why not just make that illegal?

Re: 80% of orgs that paid the ransom were hit again

#305
post #196

Earlier quoted context omitted.

They’re supposed to back up their data and set up proper contingencies. By failing to do so, they are already putting patients lives in the hands of the encryptors.

Yes. Of course they were supposed to do so, then . But they didn't, and now they've been hit. Now, in the real world, what are they supposed to do: pay, or hold out and let the patients die as punishment for the hospital's mistakes?

> Of course they were supposed to do so, then. But they didn't, and now they've been hit.

In order for this to be a useful tactic, there needs to be no defection. The only way there can be no defection is if the legislature prohibits defection.

At that point, the hospital is on notice that they have to apply adequate security measures against this kind of attack. For instance, hospitals normally have power supplies that are capable of getting them through foreseeable blackouts. If they're going to rely on computer systems in the treatment of patients, they had better make sure they're secure. Right now, today, it isn't a surprise.

And the hackers are on notice that they are effectively killing the patients. The hackers are after the money. If the threat of death will get them the money, they're all for it. If it won't, they'll move on to a country where it does work.

Re: 80% of orgs that paid the ransom were hit again

#306
This may be an impossible question to ask: does anybody know of organizations running entirely dark copies of infrastructure possibly using an entirely different stack up to the application layer? Rather than redundancy, which is an announced component of your infrastructure available for failover and thus known to attackers, this dark infrastructure exists unknown to all but a select few employees and can be engaged during a ransomware attack. Throw the old infrastructure away and rebuild new dark infra. I have heard at least one story of something like this earlier today when discussing this headline. Curious how common it is.

Re: 80% of orgs that paid the ransom were hit again

#308

Earlier quoted context omitted.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

I genuinely don't put any faith in education. Every phishing education program I've seen has effectively said "look out for weird emails, (perhaps with misspellings) and if you see them report them to security!" I haven't seen any which went into the real specifics which might actually educate users: - A phishing email which can pwn you without user interaction is basically unheard of. - Even malicious sites generall…

Can't wait for WebAuthN to proliferate.

Re: 80% of orgs that paid the ransom were hit again

#309

Earlier quoted context omitted.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

I genuinely don't put any faith in education. Every phishing education program I've seen has effectively said "look out for weird emails, (perhaps with misspellings) and if you see them report them to security!" I haven't seen any which went into the real specifics which might actually educate users: - A phishing email which can pwn you without user interaction is basically unheard of. - Even malicious sites generall…

> A phishing email which can pwn you without user interaction is basically unheard of.

If you extend from "email" to the other communication tools that companies use today (and do use for inter-company communications too), there actually have been a number of these in the past year.

Outlook [3] had one that didn't require downloading the file, exactly - the "Preview" window from just clicking the attachment once, was enough.

Microsoft Teams [0], Jabber [1] and Slack [2] were all hit by real 0-interaction RCEs.

[0] https://github.com/oskarsve/ms-teams-rce/blob/main/README.md

[1] https://nvd.nist.gov/vuln/detail/CVE-2020-3495

[2] https://hackerone.com/reports/783877

[3] https://nvd.nist.gov/vuln/detail/CVE-2020-1349

Re: 80% of orgs that paid the ransom were hit again

#310

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

What would be the incentive not to? Honor among thieves? You know they’re vulnerable to the attack (the hard part?) so why not keep doing it until they shore up their defenses.

Short term you benefit from the second random. Long term, you may make people less likely to pay your ransoms.
Post reply on HN