Meaningless stat without a baseline to compare against. How many who didn't pay were hit again?
If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.
80% of orgs that paid the ransom were hit again
301–310 of 386 posts
Re: 80% of orgs that paid the ransom were hit again
#302Earlier quoted context omitted.
Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.
And let's not discount the moral of low paid, overworked employees, and companies that let low level managers run roughshod over lower level employees. My point is don't discount inside corporate espionage by disgruntled any level employees. Thank goodness I didn't have access to a script that would lock up at least two of my past employers when coming up years ago? Then again, I personally haven't been that mad, but…
We got bought. Big corp enforced Endpoint Management and a whole barrage of corporate spyware.
I am not an admin anymore. I can't even use an AdBlock solution anymore.
And guess what. I don't give a damn anymore. If the device enforces an update, so he it. If I have to double approve every external mail address when sending, so be it.
But I don't feel ownership or responsibility anymore. Should corporate overlords care. I am out.
Re: 80% of orgs that paid the ransom were hit again
#303I don't see any discussion of typical entry points. How do these guys get into the system? Is it by having someone download a malicious file? If so what type of file? PDF? MS Office? If so Adobe and Microsoft should be held accountable for their security holes, only then will they have enough motivation to maybe consider rewriting some of their code in a safer language such as Rust.
The entry points are "whatever works". Typically: * Password spraying from previous data leaks * Good old-fashioned fishing * Bugs in anything that's common in enterprises, exposed to the Internet and not patched fast enough, including MS Exchange, various security/VPN products, vcenter, you name it. All of these had pretty critical pre-auth bugs exposed just this year * malicious browser plugins * malicious O365 app…
- ActiveX for legacy ad-hoc software
Re: 80% of orgs that paid the ransom were hit again
#304Earlier quoted context omitted.
If you believe banning cryptocurrencies will suddenly stop ransomware, then I have a bridge to sell you.
There is an easy fix here: make it illegal for companies to transact in crypt currencies. Then they would have no way of paying a ransom without engaging in illegal activities. This would destroy the ransomware business model.
If the goal is to stop companies from paying ransom, then why not just make that illegal?
Re: 80% of orgs that paid the ransom were hit again
#305Earlier quoted context omitted.
They’re supposed to back up their data and set up proper contingencies. By failing to do so, they are already putting patients lives in the hands of the encryptors.
Yes. Of course they were supposed to do so, then . But they didn't, and now they've been hit. Now, in the real world, what are they supposed to do: pay, or hold out and let the patients die as punishment for the hospital's mistakes?
In order for this to be a useful tactic, there needs to be no defection. The only way there can be no defection is if the legislature prohibits defection.
At that point, the hospital is on notice that they have to apply adequate security measures against this kind of attack. For instance, hospitals normally have power supplies that are capable of getting them through foreseeable blackouts. If they're going to rely on computer systems in the treatment of patients, they had better make sure they're secure. Right now, today, it isn't a surprise.
And the hackers are on notice that they are effectively killing the patients. The hackers are after the money. If the threat of death will get them the money, they're all for it. If it won't, they'll move on to a country where it does work.
Re: 80% of orgs that paid the ransom were hit again
#306Re: 80% of orgs that paid the ransom were hit again
#307Re: 80% of orgs that paid the ransom were hit again
#308Earlier quoted context omitted.
I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…
I genuinely don't put any faith in education. Every phishing education program I've seen has effectively said "look out for weird emails, (perhaps with misspellings) and if you see them report them to security!" I haven't seen any which went into the real specifics which might actually educate users: - A phishing email which can pwn you without user interaction is basically unheard of. - Even malicious sites generall…
Re: 80% of orgs that paid the ransom were hit again
#309Earlier quoted context omitted.
I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…
I genuinely don't put any faith in education. Every phishing education program I've seen has effectively said "look out for weird emails, (perhaps with misspellings) and if you see them report them to security!" I haven't seen any which went into the real specifics which might actually educate users: - A phishing email which can pwn you without user interaction is basically unheard of. - Even malicious sites generall…
If you extend from "email" to the other communication tools that companies use today (and do use for inter-company communications too), there actually have been a number of these in the past year.
Outlook [3] had one that didn't require downloading the file, exactly - the "Preview" window from just clicking the attachment once, was enough.
Microsoft Teams [0], Jabber [1] and Slack [2] were all hit by real 0-interaction RCEs.
[0] https://github.com/oskarsve/ms-teams-rce/blob/main/README.md
[1] https://nvd.nist.gov/vuln/detail/CVE-2020-3495
Re: 80% of orgs that paid the ransom were hit again
#310The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!
What would be the incentive not to? Honor among thieves? You know they’re vulnerable to the attack (the hard part?) so why not keep doing it until they shore up their defenses.