I bought some candy from Amazon that was shipped by Royal Mail, and it never arrived. Amazon told me to take up the refund with Royal Mail, with no instructions how to do so. Anyone know how I can get a refund from Amazon/Royal Mail for the candy they never sent?
Email jeff@amazon.com pleading your case.
Royal Mail dismisses ‘absurd’ $80M ransom demand
91–100 of 108 posts
Re: Royal Mail dismisses ‘absurd’ $80M ransom demand
#92Re: Royal Mail dismisses ‘absurd’ $80M ransom demand
#93If Russia were to physically disrupt a country's social services by force, it would be an act of war. Here they have disrupted a British social service without force by state sponsored hacker terrorists, rendering harm in the physical world. The line gets blurrier.
Since it was privatised it's no longer a social service, but a private corporation.
Re: Royal Mail dismisses ‘absurd’ $80M ransom demand
#94Earlier quoted context omitted.
Royal Mail is still a very large corporation and could have paid. BUT they simply did not think the amount was worth paying, I suspect both in term of the direct consequence if the data were published (which the hackers apparently did in the end) and in term of PR, reputation, etc because they couldn't have kept the payment secret (too big). So IMHO the issue was miscalculating leverage.
There is one more point: by not paying they develop a reputation that they are not worth attacking. The next criminal org might just skip attacking them. If everyone follows this examples the criminals will give up.
the hackers already threatened going nuclear by releasing files and letting Europe fines their 0.5% which is more then 80M.
This is not over and Royal Mail is in a lose/lose situation here
Re: Royal Mail dismisses ‘absurd’ $80M ransom demand
#95Why is ransomware still a problem? Is it that difficult to make off-site backups every hour? Storage is cheap. There are many air gapping options for backups, too. It sounds like a case of normalized deviance, for which the management should be held accountable. As much as I don’t like victim blaming, I think it’s beyond incompetent to still not backup your data in 2023 as a government org.
They're not a government organization. Haven't been for almost 10 years
Though I think it’s even worse if a publicly traded company fails to protect its data and falls prey to the extortion. Don’t they have a fiduciary responsibility to their shareholders? It seems wrong to waste their money due to incompetence at such basic infosec.
Government orgs are more difficult to hold accountable for losses than PLCs.
Re: Royal Mail dismisses ‘absurd’ $80M ransom demand
#96Why is ransomware still a problem? Is it that difficult to make off-site backups every hour? Storage is cheap. There are many air gapping options for backups, too. It sounds like a case of normalized deviance, for which the management should be held accountable. As much as I don’t like victim blaming, I think it’s beyond incompetent to still not backup your data in 2023 as a government org.
>Is it that difficult to make off-site backups every hour? Storage is cheap. There are many air gapping options for backups, too. I'd imagine that often your backups get encrypted as well, early enough that the data loss to the last good backup becomes unacceptable.
Re: Royal Mail dismisses ‘absurd’ $80M ransom demand
#97Earlier quoted context omitted.
It’s not your problem. The seller is legally responsible for the delivery. Chat with Amazon again and remind them. Or consult with Citizens Advice if you need help. Amazon support eventually refunds basically anything if you are persistent enough.
Maybe, but in one specific occasion I know of, the client was told not to contact support anymore for a refund. I think it's a different retail landscape now to what it was in 2020-2022.
I’ve gotten refunds for parcels lost in 2020-22 even if I was denied them initially. It’s Amazon’s strategy to deny initially.
Re: Royal Mail dismisses ‘absurd’ $80M ransom demand
#98How is it even legal to pay ransoms? Surely this is transferring money to criminal enterprises. If it is not illegal it needs to be made illegal.
It's also orders of magnitude cheaper to just restore from backup. I can't imagine their S3 bill is above 80 millions...
Re: Royal Mail dismisses ‘absurd’ $80M ransom demand
#99Why is ransomware still a problem? Is it that difficult to make off-site backups every hour? Storage is cheap. There are many air gapping options for backups, too. It sounds like a case of normalized deviance, for which the management should be held accountable. As much as I don’t like victim blaming, I think it’s beyond incompetent to still not backup your data in 2023 as a government org.
It is crazy the number of companies that do not have appropriate visibility of what they're backing up. If the backups are immutable and if they have ever tested their ability to recover the environment.
And when I say the environment I mean all necessary components of the environment, not just applications, but their databases, Active Directory/Domain, DNS, DHCP, File servers, virtual infrastructure (VMware/HyperV).
In a virtualized environment the backup of these components is made easier, but you still need to understand what makes up your environment in order ensure you're backing it up appropriately.
Sometimes they have backups, but once they're forced to test them, realise they weren't backing up the right components or simply couldn't recover from those backups.
It's a big, risky exercise to perform, but important.
Re: Royal Mail dismisses ‘absurd’ $80M ransom demand
#100Why is ransomware still a problem? Is it that difficult to make off-site backups every hour? Storage is cheap. There are many air gapping options for backups, too. It sounds like a case of normalized deviance, for which the management should be held accountable. As much as I don’t like victim blaming, I think it’s beyond incompetent to still not backup your data in 2023 as a government org.
Many ransoms now are for the leaking of the info, not the destruction of the info. With huge GDPR fines for data leaks in Europe, the criminals are using the legal system as their 'threat'.
GDPR fines come from not following basic data protection practices, not for the breach itself. Also, a lot of reputational damage of the leak comes from bad infosec (case study: LastPass). If the customer data is reasonably protected, there isn’t much motivation to pay ransoms.
Companies have data breaches all the time. Even a start-up I worked in in GDPR times had a data breach, and an extortion attempt. But all customer PI data was encrypted and only ever in plaintext on our end in an ephemeral way. The data was worthless, we never paid ransoms. We bought some darknet monitoring service for some fake canary user data, but nothing ever came up in 4 years after the breach. No ransom was ever paid and honestly, the data breach was on our minds for 10 days max.
This is not hard to do, it was done by two business guys who listened to infosec podcasts and read infosec articles online. Specialists in the area that I’m sure all of these ransomed big businesses can afford can definitely do much better data protection.
I don’t think companies are sued/prosecuted for GDPR non-compliance or any damage done to their customers if hashed blobs get leaked. Assuming the hackers even bother to leak them, because what are they going to say in the forums they sell the data on? “I have unknown encrypted data about some hashed usernames from company X”? Maybe one day in the far future that data will hold some value, but not today. I would more easily see investors suing the management for paying ransoms instead of doing even rudimentary data protection.