Earlier quoted context omitted.
Then the payment will be done by "underground payment processors" with a hefty extra fee. It wouldn't solve the problem I think, only shift the path an organization has to take.
No it wouldn't, no executive at any company would risk federal time and money laundering charges if it was made illegal.
Confessions of a Ransomware Negotiator
31–40 of 56 posts
Re: Confessions of a Ransomware Negotiator
#32That if once you have paid him the Danegeld, you never get rid of the Dane. — Dane-Geld, Rudyard Kipling https://en.wikipedia.org/wiki/Dane-geld_(poem)
I expect the 80% figure to be rather inflated, unless they are talking about attempted attacks and not just successful second attacks, but paying the ransom in no way means you won't be attacked again.
Though thinking about it, if it were only attempted attacks I'd expect the figure to be 100% - criminal types are not known for leaving a potential easy mark alone! If they don't re-attack themselves then they could at least sell or swap to another group information about the potential target (or another group could just catch news on the grapevine).
Re: Confessions of a Ransomware Negotiator
#33Re: Confessions of a Ransomware Negotiator
#34Earlier quoted context omitted.
That's victim blaming. Even if we don't pay up, people will still spread ransomware just for shits and giggles. The cat is out of the bag.
He’s not blaming the victims for getting attacked by ransomware. He’s blaming people who then pay the attackers . That’s a separate issue. People can be both victims and perpetrators of separate offenses, subject to criticism. I.e. being a victim of one thing does not render you blamless for all your subsequent actions.
Re: Confessions of a Ransomware Negotiator
#35Earlier quoted context omitted.
He’s not blaming the victims for getting attacked by ransomware. He’s blaming people who then pay the attackers . That’s a separate issue. People can be both victims and perpetrators of separate offenses, subject to criticism. I.e. being a victim of one thing does not render you blamless for all your subsequent actions.
Those who pay the attackers might have no other choice. Sure they should have taken backups. But right now they don't have any. What else can they do? Maybe government can enact laws asking to maintain backups regularly in critical industries.
They can take the hit and live without their data, thereby making the world safer for the rest of us. Focusing only on their own personal problem is the definition of selfishness.
Re: Confessions of a Ransomware Negotiator
#36I wonder about whether governments could make it illegal to pay ransomware. If a business from country X could not legally pay, then what would be the point of attacking any company from country X?
Re: Confessions of a Ransomware Negotiator
#37Re: Confessions of a Ransomware Negotiator
#38Earlier quoted context omitted.
ha! That is brilliant idea, how come nobody ever though of it before?
I don't know. Seems to be easier (read "cheaper") to run shitty software and not train people well, so this doesn't happen in the first place. It's not like Ransomware is some god-given thing that just happens. There's a case in Germany right now where the critical Confluence bug was simply not patched for two weeks after the notice that there's a critical bug/exploit. Now the systems are down and everybody's wonderi…
You can't get rid of the Marthas because the Marthas have been here 30 years and hangs out with everyone from the company on weekends, and probably knows more about the business than anyone even if you wanted to get rid of her.
Re: Confessions of a Ransomware Negotiator
#39I wonder about whether governments could make it illegal to pay ransomware. If a business from country X could not legally pay, then what would be the point of attacking any company from country X?
Partly already true. You can’t pay criminals in OFAC listed countries ( https://sanctionssearch.ofac.treas.gov/ ) Now, the issue becomes how do you know? And what happens when it’s your businesses existence vs breaking the law?
Corporate accountability is laughable. So just break the law, get your small little fine, accept no wrong doing, and move on.
Re: Confessions of a Ransomware Negotiator
#40> unless you're critical to national security, the bottom line is: you're on your own here Ransomware attacks are now pervasive. I'd argue that even though most individual victims are not critical to national security, society as a whole is under attack. This makes it a national security emergency in my view.