Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

341–350 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#341

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Or they overhauled the IT team.

I'd say chances are somebody brought up concerns at most of these places but management told them not to worry for one reason or another.

Re: 80% of orgs that paid the ransom were hit again

#342

Earlier quoted context omitted.

If you believe banning cryptocurrencies will suddenly stop ransomware, then I have a bridge to sell you.

In the theoretical universe where banning crypto is possible, yes it would stop almost all ransomware of the scale we see reported in news today. There's just no other form of payment which would work for them. You can't easily go "can I have $50k worth of giftcards" and on the receiving side you can't easily validate or sell millions of them without tanking the value. Any kind of wire transfer would expose the sourc…

Suitcase full of gold coins delivered somewhere in Russia would be an easy replacement for crypto coins.

Re: 80% of orgs that paid the ransom were hit again

#344

Earlier quoted context omitted.

I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…

I genuinely don't put any faith in education. Every phishing education program I've seen has effectively said "look out for weird emails, (perhaps with misspellings) and if you see them report them to security!" I haven't seen any which went into the real specifics which might actually educate users: - A phishing email which can pwn you without user interaction is basically unheard of. - Even malicious sites generall…

Bluecoat proxies are amazing at creating the wrong user behaviour, since when spegno fails all the ones I've seen fallback to basic auth asking for your company network credentials in a basic auth box on the browser.

Re: 80% of orgs that paid the ransom were hit again

#345
Note that,

> 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group

Why would victims pay them? Why would the attackers bother to reinfect? Just up the price on the original infection, after the first payment.

Re: 80% of orgs that paid the ransom were hit again

#346

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Untested backups and DR/BCP procedures aren't backups. Snapshots aren't backups. Backups that aren't physically-isolated, typically offsite, aren't backups.

Why are offsite write only continuously incremental snapshots from a full start not backups?

Re: 80% of orgs that paid the ransom were hit again

#347
post #256

Earlier quoted context omitted.

...and if you pay for our Premium Level Service, we'll secure your systems against other criminal enterprises as well!

Some groups will actually tell you how they got in and help you patch your systems. Some groups will hack you AND also uninstall viruses emanating from other groups, or they will hack you and patch other flaws so that other malwares cannot take their spot. It's all game theory.

isn't that just plain strategy?

Re: 80% of orgs that paid the ransom were hit again

#348

Earlier quoted context omitted.

Untested backups and DR/BCP procedures aren't backups. Snapshots aren't backups. Backups that aren't physically-isolated, typically offsite, aren't backups.

Why are offsite write only continuously incremental snapshots from a full start not backups?

"Off-site write only continuously incremental snapshots from a full start", that can be interpreted as a backup strategy (i.e. a DB would do something like that with full/diff/log backups), but you just changed what snapshots means.

What OP tried to demonstrate that backups need to protect from bad changes, on physical, logical, and business layer, from data corruptions to 'oops' scenarios (i.e. drop table). Standard snapshots for sure don't protect from all those.

Also for a good backup strategy, you need - "a full start" once in a while, because corruption in "full backup" will invalid all incremental snapshots - regular restore of a backup for e2e validation

Re: 80% of orgs that paid the ransom were hit again

#349

Earlier quoted context omitted.

Untested backups and DR/BCP procedures aren't backups. Snapshots aren't backups. Backups that aren't physically-isolated, typically offsite, aren't backups.

Well then, It’s starting to sound like backups aren’t what a business needs.

Backups are there to provide a business continuity in wide range of disruptions. What you want to protect your business from is up to you, but typically you need protection from all things OP mentioned.

Re: 80% of orgs that paid the ransom were hit again

#350
post #185
post #12

Earlier quoted context omitted.

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Coming soon: ransomware with subscription business model

Yeah, the data remains permanently encrypted but you can access it. You pay X dollars per month for that access. They even provide protection against other gangs as well as offsite "backup" themselves. Plus your business can be an infection vector for other enterprises and individuals. The actual fees start low...
Post reply on HN