What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.
Or they overhauled the IT team.
80% of orgs that paid the ransom were hit again
341–350 of 386 posts
Re: 80% of orgs that paid the ransom were hit again
#342Earlier quoted context omitted.
If you believe banning cryptocurrencies will suddenly stop ransomware, then I have a bridge to sell you.
In the theoretical universe where banning crypto is possible, yes it would stop almost all ransomware of the scale we see reported in news today. There's just no other form of payment which would work for them. You can't easily go "can I have $50k worth of giftcards" and on the receiving side you can't easily validate or sell millions of them without tanking the value. Any kind of wire transfer would expose the sourc…
Re: 80% of orgs that paid the ransom were hit again
#343Re: 80% of orgs that paid the ransom were hit again
#344Earlier quoted context omitted.
I'd like to think security training can take care of it, that people can be careful and considerate and have a skeptical eye about every single message they receive. But it only takes one person and these huge companies employ so many people. So many times, even at companies with really strict security training I've seen people just walk away from their unlocked computers, click random links in emails, stuff like tha…
I genuinely don't put any faith in education. Every phishing education program I've seen has effectively said "look out for weird emails, (perhaps with misspellings) and if you see them report them to security!" I haven't seen any which went into the real specifics which might actually educate users: - A phishing email which can pwn you without user interaction is basically unheard of. - Even malicious sites generall…
Re: 80% of orgs that paid the ransom were hit again
#345> 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group
Why would victims pay them? Why would the attackers bother to reinfect? Just up the price on the original infection, after the first payment.
Re: 80% of orgs that paid the ransom were hit again
#346What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.
Untested backups and DR/BCP procedures aren't backups. Snapshots aren't backups. Backups that aren't physically-isolated, typically offsite, aren't backups.
Re: 80% of orgs that paid the ransom were hit again
#347Earlier quoted context omitted.
...and if you pay for our Premium Level Service, we'll secure your systems against other criminal enterprises as well!
Some groups will actually tell you how they got in and help you patch your systems. Some groups will hack you AND also uninstall viruses emanating from other groups, or they will hack you and patch other flaws so that other malwares cannot take their spot. It's all game theory.
Re: 80% of orgs that paid the ransom were hit again
#348Earlier quoted context omitted.
Untested backups and DR/BCP procedures aren't backups. Snapshots aren't backups. Backups that aren't physically-isolated, typically offsite, aren't backups.
Why are offsite write only continuously incremental snapshots from a full start not backups?
What OP tried to demonstrate that backups need to protect from bad changes, on physical, logical, and business layer, from data corruptions to 'oops' scenarios (i.e. drop table). Standard snapshots for sure don't protect from all those.
Also for a good backup strategy, you need - "a full start" once in a while, because corruption in "full backup" will invalid all incremental snapshots - regular restore of a backup for e2e validation
Re: 80% of orgs that paid the ransom were hit again
#349Earlier quoted context omitted.
Untested backups and DR/BCP procedures aren't backups. Snapshots aren't backups. Backups that aren't physically-isolated, typically offsite, aren't backups.
Well then, It’s starting to sound like backups aren’t what a business needs.
Re: 80% of orgs that paid the ransom were hit again
#350Earlier quoted context omitted.
Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.
Coming soon: ransomware with subscription business model