Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

351–360 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#351
post #143

Earlier quoted context omitted.

No, but the people operating in Russia like to travel elsewhere, and do. Also, the US and allies can enforce Russian AML laws as written on paper. If, say, the UK freezes all of Oleg Deripaska's assets there, Vova will absolutely get the message. We're not going to bring down the Russian government with military force for a million different reasons, but doing it with sanctions and prosecution is a totally different…

When they do US gets them. That happens from time to time, if you watch the news, you notice there are guys caught periodically who thought it's time for a nice vacation in Spain resting from their criminal activities... only to be picked up in the airport. However, the smarter ones stay put inside Russia and those are hard to get.

Yup, for example that credit card frauder who went to the Maldives..

Re: 80% of orgs that paid the ransom were hit again

#352

Earlier quoted context omitted.

I have a direct A/B experiment on this: I have one work laptop which is centrally managed by big-corp IT (I'm not the admin), and one laptop which is a project machine which I manage and admin. Guess what? The big-corp IT managed computer which I only use to check email and edit Word docs is almost unusably slow, weighed down as it is with antivirus, surveillance software, centralized updates, etc. The project machin…

Preach! I have the same issues,but my last place had me as IT for the whole (small) shop, and when they outsouced IT ('we need you on important_thing') they had me install all of the Corp Spyware (because 'why would we ask them to send their own techs, then we would have to wait for them to schedule us in, you do it- it'll be faster!) and I watched with Despair as all resources went to AV (gotta love that Norton 360,…

> The owner refused to admit he made a bad decision and stayed with that 'IT' 'company' for over a year, and didn't get rid of them until I'd left and no one was available who could triage, and they saw just how little that 'company' did, and just how much I was made to cover for them

That last part leaps out at me as particularly interesting: highlighting behind-the-scenes firefighting work is always tricky. Management doesn't want to acknowledge that it's necessary, while engineering maybe shies away from managerial caricaturization of what ultimately amounts to implementational minutiae. How'd you end up conveying the behind-the-scenes work you did in these kinds of situations?

Re: 80% of orgs that paid the ransom were hit again

#353
post #336

Earlier quoted context omitted.

"I have seen unpstanding guys rub magnets over hard drives over pure apathy." Open up a spinning rust hard drive and you will find two very strong magnets inside, positioned opposite each other.

This isn't why it didn't work though: disks tolerate smooth magnetic field gradients just fine. To wipe them you want a chaotic, noisy electromagnet.

Wow, interesting. How does that work?!

Re: 80% of orgs that paid the ransom were hit again

#354

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups. Another issue with backups, is are you restoring to an already infected / immediately infectable state? I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

> Most of these start as phishes to lower level employees.

They used to (and probably still) do this. But more recently these folk are paying access brokers. A bit like bank robbers teaming up with criminal locksmiths.

> It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups.

You'll ideally need:

- Better security awareness training to cover human weakness such as spotting dodgy email and what to do if you click a link

- Patch vulnerabilities quickly as this will reduce risk considerably

- Company wide tested and sufficient backup strategy (most companies fail on this) to protect key identified data assets

- Regularly pen-test both your internal and external environments

Obviously it doesn't stop there, but those are key.

Re: 80% of orgs that paid the ransom were hit again

#355
This is a good case of the prisoners dilemma. If the groups of attackers don’t hit the same victims twice, it would increase their chances of getting paid for each attack. Whilst also everyone is tempted to re-hit a victim who has already proved their willingness to pay, but this decreases the willingness for each victim to pay because they have seen that it won’t actually protect against a new attack.

Re: 80% of orgs that paid the ransom were hit again

#356
post #336

Earlier quoted context omitted.

This isn't why it didn't work though: disks tolerate smooth magnetic field gradients just fine. To wipe them you want a chaotic, noisy electromagnet.

Wow, interesting. How does that work?!

Basically it's the transition in field strength, not the field, which flips a bit. So you need a moving magnetic field, and you need to cause a lot of changes because HDDs have all sorts of error correction.

Re: 80% of orgs that paid the ransom were hit again

#357
post #256

Earlier quoted context omitted.

Some groups will actually tell you how they got in and help you patch your systems. Some groups will hack you AND also uninstall viruses emanating from other groups, or they will hack you and patch other flaws so that other malwares cannot take their spot. It's all game theory.

isn't that just plain strategy?

Game theory is more or less “plain strategy.”

Re: 80% of orgs that paid the ransom were hit again

#358

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

It’s not really about sacrificing people for the greater good. Negotiating has high externalities that include future murders. Like all externalities, the involved people don’t give a shit.

Re: 80% of orgs that paid the ransom were hit again

#359

Earlier quoted context omitted.

Why are offsite write only continuously incremental snapshots from a full start not backups?

"Off-site write only continuously incremental snapshots from a full start", that can be interpreted as a backup strategy (i.e. a DB would do something like that with full/diff/log backups), but you just changed what snapshots means. What OP tried to demonstrate that backups need to protect from bad changes, on physical, logical, and business layer, from data corruptions to 'oops' scenarios (i.e. drop table). Standard…

Alright, was curious as this is how I have been handling my third layer of backups for quite a while now, regular incremental encrypted zfs snapshots to an offsite storage provider using API keys that only have write priveleges. Wanted to make sure it wasn't something about "snapshots" which made this a bad idea in a way I hadn't thought of. Doesn't seem that's the case.

Re: 80% of orgs that paid the ransom were hit again

#360

Earlier quoted context omitted.

In the theoretical universe where banning crypto is possible, yes it would stop almost all ransomware of the scale we see reported in news today. There's just no other form of payment which would work for them. You can't easily go "can I have $50k worth of giftcards" and on the receiving side you can't easily validate or sell millions of them without tanking the value. Any kind of wire transfer would expose the sourc…

Suitcase full of gold coins delivered somewhere in Russia would be an easy replacement for crypto coins.

That doesn't sound easy at all.
Post reply on HN