Live data from Hacker News

Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

reuters.com

1–10 of 200 posts

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#2
>Neuberger told journalists a new “black list” will also be created by the US treasury department to identify and highlight digital wallets being used to deposit and move ransomware payments.

>The establishment of these information sharing platforms means that “if one country is attacked, others can quickly be defended”, Neuberger said.

pardon the dust whilst I apply my 14th century naval hammer to this clearly 21st century nail.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#5
post #4

So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?

An insurance fund that requires periodic air gapped backups. So you roll back to the last snapshot and get money to cover losses incurred.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#6
post #4

So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?

> What would stop them from paying the ransom

They can bring their systems back up and operational for less cost (both immediate, but also payroll during the fix, lost revenue from both downtown and reputationally after they're back, and opportunity cost off the top of my head).

Your only two options and rebuild on your own at significant cost or pay the ransom. There were long, heated discussions about what to do, and several people suggested paying the ransom but we ultimate decided not to and it ended up costing more than the ransom if you factor in payroll and lost revenue.

I still think out of principle you shouldn't pay the ransom, ever. Assume whatever the ransom would cost is already gone, if you can rebuild for less than that (you probably can't) it's a win.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#7
post #4

So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?

I was assuming that countries would make it illegal to pay these ransoms.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#8
post #7
post #4

So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?

I was assuming that countries would make it illegal to pay these ransoms.

The article doesn't seem to suggest that anywhere.

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#9
First of all, it's not a nation who pays in case of a breach. It's some company. Nation as countries do not have anything to do with it, unless they create some laws denying payments. Which would tight control of any businesses in hands of politicians signing off indulgences (exceptions to pay as "too big to fail").

Re: Alliance of 40 countries to vow not to pay ransom to cybercriminals, US says

#10
post #4

So let's imagine a company like Garmin experiences a ransomware attack. Their business is paralyzed. What would stop them from paying the ransom and what could possibly be an alternative to that?

An insurance fund that requires periodic air gapped backups. So you roll back to the last snapshot and get money to cover losses incurred.

There are a handful of problems with this approach, which is part of why these types of insurance policies are incredibly expensive. The entire MO of these operations is to infect a company's systems, and wait until most or all of the backups are affects before locking the system down. They will wait months or for bigger targets, years.
Post reply on HN