Live data from Hacker News

Confessions of a Ransomware Negotiator

theregister.com

21–30 of 56 posts

Re: Confessions of a Ransomware Negotiator

#21
post #9
post #8

I wonder about whether governments could make it illegal to pay ransomware. If a business from country X could not legally pay, then what would be the point of attacking any company from country X?

I believe it's already illegal ("know your customer", maybe they are terrorists). But ransom payments are tax-deductible nevertheless.

Ransom payments are tax-deductible? If true that is nuts! Do you have a source?

Re: Confessions of a Ransomware Negotiator

#22

Earlier quoted context omitted.

This is wildly incorrect. For criminal groups who intend on making money, that payment is needed on a certain subset of victims are they can’t stay in business.

I am a shady company who wants to take down a competitor. I can hire a hacker who'll do the dirty job for me and then get paid in cold hard cash. Or a nation state actor can decide to attack an enemy country's infrastructure.

So? If their goal is destruction what does that have to do with ransomware? They can do that whether paying the ransom is legal or not.

Re: Confessions of a Ransomware Negotiator

#24
post #9

Earlier quoted context omitted.

I believe it's already illegal ("know your customer", maybe they are terrorists). But ransom payments are tax-deductible nevertheless.

Ransom payments are tax-deductible? If true that is nuts! Do you have a source?

"Hit by a cyberattack? Your ransom payment to hackers may be tax deductible."

https://www.chicagotribune.com/business/ct-biz-ransomware-pa...

Re: Confessions of a Ransomware Negotiator

#26
post #22

Earlier quoted context omitted.

I am a shady company who wants to take down a competitor. I can hire a hacker who'll do the dirty job for me and then get paid in cold hard cash. Or a nation state actor can decide to attack an enemy country's infrastructure.

So? If their goal is destruction what does that have to do with ransomware? They can do that whether paying the ransom is legal or not.

Deception? It can confuse the target about the motives of the attack.

Re: Confessions of a Ransomware Negotiator

#27
post #11
post #10

Earlier quoted context omitted.

Then the payment will be done by "underground payment processors" with a hefty extra fee. It wouldn't solve the problem I think, only shift the path an organization has to take.

No it wouldn't, no executive at any company would risk federal time and money laundering charges if it was made illegal.

That's what throw-away shell companies are for...

Re: Confessions of a Ransomware Negotiator

#29
post #2

Ransomware obviously only works if people are paying. Just stop that and it will go away. Oh, and of course make sure it can't happen in the beginning.

That's victim blaming. Even if we don't pay up, people will still spread ransomware just for shits and giggles. The cat is out of the bag.

He’s not blaming the victims for getting attacked by ransomware. He’s blaming people who then pay the attackers. That’s a separate issue. People can be both victims and perpetrators of separate offenses, subject to criticism. I.e. being a victim of one thing does not render you blamless for all your subsequent actions.
Post reply on HN