Live data from Hacker News

UCSF admits it paid NetWalker more than $1M ransom

databreaches.net

11–20 of 68 posts

Re: UCSF admits it paid NetWalker more than $1M ransom

#11

The poor IT guys there probably asked for a couple thousand for backups instead and were previously denied. Ransomeware first rose to prominence three years ago. Yet seemingly little has been learned?

I know the university I attended has learned nothing at all. State university in a wealthy US area with over 30,000 students. They still think security is forcing everyone to change passwords once every 6 months. No offer of 2fa of any sort for any service.

I stopped using my email address between transcript requests because the whole student/faculty directory is rampant with student employees of local businesses sending spam within the system.

A permanent link is a complete mystery of a concept to them as well. Every time sun shines on an article in public media for them the glory is sure to be short lived, because google's link will be broken in 6 months tops.

Re: UCSF admits it paid NetWalker more than $1M ransom

#12
post #9

Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

How about kidnapping insurance? Should that be illegal?

Re: UCSF admits it paid NetWalker more than $1M ransom

#13
post #11

The poor IT guys there probably asked for a couple thousand for backups instead and were previously denied. Ransomeware first rose to prominence three years ago. Yet seemingly little has been learned?

I know the university I attended has learned nothing at all. State university in a wealthy US area with over 30,000 students. They still think security is forcing everyone to change passwords once every 6 months. No offer of 2fa of any sort for any service. I stopped using my email address between transcript requests because the whole student/faculty directory is rampant with student employees of local businesses sen…

> A permanent link is a complete mystery of a concept to them as well. Every time sun shines on an article in public media for them the glory is sure to be short lived, because google's link will be broken in 6 months tops.

I am baffled that universities (and so many others) don't just use WordPress for publishing their media.

Re: UCSF admits it paid NetWalker more than $1M ransom

#14
post #12
post #9

Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

How about kidnapping insurance? Should that be illegal?

That is not a reasonable comparison.

Re: UCSF admits it paid NetWalker more than $1M ransom

#15
post #9

Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

What if they threaten to release the data? Is it really preferable to let personal info flood the net rather than pay?

Re: UCSF admits it paid NetWalker more than $1M ransom

#17
post #9

Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

What if they threaten to release the data? Is it really preferable to let personal info flood the net rather than pay?

Of course not.

But if it was illegal to pay a ransom, the frequency of the crime would go down.

Re: UCSF admits it paid NetWalker more than $1M ransom

#19
post #12
post #9

Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

How about kidnapping insurance? Should that be illegal?

There is already Cyberinsurance for this kind of scenario... so unless poster would like to make that illegal too...

Re: UCSF admits it paid NetWalker more than $1M ransom

#20
post #18

I'm imagining a scenario where a UCSF insider could coordinate this with someone by deliberately getting their system infected and then splitting the money with whoever is behind that NetWalker instance. Do you guys think that would work?

They had better had well though out plans to make a new life in France...
Post reply on HN