Live data from Hacker News

Royal Mail dismisses ‘absurd’ $80M ransom demand

theguardian.com

31–40 of 108 posts

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#31

Earlier quoted context omitted.

Why would it not be legal? If I was a hacker, the existence of a law prohibiting businesses from paying cyber ransoms would not deter me. If a company wanted to follow the law and refused to pay the ransom the hackers asked of them, the hackers could follow through and delete or irreparably corrupt their files. The potential upside, that they pay the ransom, is significant, while the downside, that they don't, doesn'…

If paying ransoms become illegal in many countries, it would be very hard to find targets willing to break the law and pay ransom, making it less attractive of an attack.

Companies and people pay bribes all the time. But since it's illegal to it's kept secret.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#33
post #15

Earlier quoted context omitted.

The argument seems implausible as it assumes that hackers would persist in deleting data, whereas in reality, they would probably shift their focus to other targets such as private companies that lack similar prohibitions. It is unclear what incentive they would have to continue hacking public companies if they cannot profit from that?

> It is unclear what incentive they would have to continue hacking public companies if they cannot profit from that. The intent would be to put pressure on national legislatures to repeal laws that make paying ransoms illegal. Smart ransomware groups don't care about targets that can't afford to pay. So any "inability" to pay is either the result of stubbornness or a law, both of which can change if enough pressure i…

Note too that the threat of the law may be enough motivation to stop payment. Insurance in particular is already starting to look at how hardened your IT systems are as part of your coverage.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#34

I bought some candy from Amazon that was shipped by Royal Mail, and it never arrived. Amazon told me to take up the refund with Royal Mail, with no instructions how to do so. Anyone know how I can get a refund from Amazon/Royal Mail for the candy they never sent?

> Amazon told me to take up the refund with Royal Mail

In most jurisdictions, at least in Europe (and I think the US, but feel free to correct me if I'm wrong), you take it up with the merchant as they're the ones who hire the delivery service. Your contract is with the merchant, and if they fail to provide the product for whatever reason—such as the delivery service not following through—then they're the ones who are responsible for making you whole.

If Amazon refuse to refund, then your recourse if to take them to court. It sounds like it's a small enough purchase that small claims would handle it.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#35
post #11

How is it even legal to pay ransoms? Surely this is transferring money to criminal enterprises. If it is not illegal it needs to be made illegal.

Sure, that would be fine if the govt. is willing to help cover the loss of business. This is not without precedent, like 2008 and 2021 bailouts.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#36

I bought some candy from Amazon that was shipped by Royal Mail, and it never arrived. Amazon told me to take up the refund with Royal Mail, with no instructions how to do so. Anyone know how I can get a refund from Amazon/Royal Mail for the candy they never sent?

It’s not your problem. The seller is legally responsible for the delivery. Chat with Amazon again and remind them. Or consult with Citizens Advice if you need help.

Amazon support eventually refunds basically anything if you are persistent enough.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#37

Earlier quoted context omitted.

Why would it not be legal? If I was a hacker, the existence of a law prohibiting businesses from paying cyber ransoms would not deter me. If a company wanted to follow the law and refused to pay the ransom the hackers asked of them, the hackers could follow through and delete or irreparably corrupt their files. The potential upside, that they pay the ransom, is significant, while the downside, that they don't, doesn'…

If paying ransoms become illegal in many countries, it would be very hard to find targets willing to break the law and pay ransom, making it less attractive of an attack.

I don't think this is correct. There is very little cost, and risk, in conducting ransomware attacks. So even the odd chance of finding a target willing to break the law and pay up would be worth it. And in the long term, black hat groups could put pressure on national legislatures to amend the law by following through on their threats and deleting or releasing the files they've encrypted. One can imagine a not so far fetched scenario where entire industries are held hostage by a small group of anonymous individuals demanding to be paid or else, and legislatures capitulating and amending the law, because the alternative, to lose - lose, as in, complete bankruptcy - entire industries and corporations would be too costly in comparison. Black hats could even compel legislative changes by credibly threatening to compromise the personal data of politicians themselves.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#38
post #18

Earlier quoted context omitted.

Royal Mail was privatised because 1st world state postal systems have to subsidise the postal systems of 3rd world countries. Its an international agreement which has come back to bite the UK because China is still classed as a 3rd world country. Lets just say the globalist's who set the rule's are finding their rules are now not so good.

The US has a similar agreement with China. "The new 1969 agreement included terminal dues, the receiving postal agencies would charge the country of origin for delivering the post on by-weight basis. To be blunt, shipping from China to USA (and most of the rest of the world) is much cheaper than shipping domestically in USA because the terminal-dues are much too low and account only for the total weight of the post,…

> China would pay less than 8 cents to have this wristband delivered anywhere in USA

lol why even bother? After recent inflation, 8 cents is so close to zero we may as well give them free delivery.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#39

lol this is Royal Mail, not Google. It's not like it has $80 million sitting around. Maybe they should have been more flexible. That's usually how you negotiate: start with a lot and work to something smaller that the counterparty will agree on. Done-in by greed and got $0, which they deserve. Shows how even the rules of negotiation applies to dark markets.

Royal Mail is still a very large corporation and could have paid. BUT they simply did not think the amount was worth paying, I suspect both in term of the direct consequence if the data were published (which the hackers apparently did in the end) and in term of PR, reputation, etc because they couldn't have kept the payment secret (too big). So IMHO the issue was miscalculating leverage.

There is one more point: by not paying they develop a reputation that they are not worth attacking. The next criminal org might just skip attacking them. If everyone follows this examples the criminals will give up.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#40

Earlier quoted context omitted.

If paying ransoms become illegal in many countries, it would be very hard to find targets willing to break the law and pay ransom, making it less attractive of an attack.

Companies and people pay bribes all the time. But since it's illegal to it's kept secret.

True - but if it's made directly illegal it will still have some effect on the number of victims willing to. It won't solve it, of course.
Post reply on HN