LOL that's some super heavy duty optics framing on what basically amounts to "we paid out a ransom but don't worry the bad guys assured us things were okay"
I thought it was illegal to pay ransom to hackers. I guess it is legal or maybe it isn't very clear? I thought that there were certain conditions that the company had to check together with law enforcement so that at least the ransom money doesn't go to a hacker group that is on a government payments sanctions list. Also, does anyone know the root cause of the attack? I read a rumor online (but it's not really confir…
Instructure pays ransom to Canvas hackers
11–20 of 257 posts
Re: Instructure pays ransom to Canvas hackers
#12Re: Instructure pays ransom to Canvas hackers
#13Given they were hacked multiple times, couldn’t they just be targeted again by the same or different group? Why would it stop here?
Re: Instructure pays ransom to Canvas hackers
#14LOL that's some super heavy duty optics framing on what basically amounts to "we paid out a ransom but don't worry the bad guys assured us things were okay"
I thought it was illegal to pay ransom to hackers. I guess it is legal or maybe it isn't very clear? I thought that there were certain conditions that the company had to check together with law enforcement so that at least the ransom money doesn't go to a hacker group that is on a government payments sanctions list. Also, does anyone know the root cause of the attack? I read a rumor online (but it's not really confir…
Re: Instructure pays ransom to Canvas hackers
#15Given they were hacked multiple times, couldn’t they just be targeted again by the same or different group? Why would it stop here?
A different group? Certainly. I wouldn't want to be in the shoes of the infosec guys at Canvas right now.
Re: Instructure pays ransom to Canvas hackers
#16LOL that's some super heavy duty optics framing on what basically amounts to "we paid out a ransom but don't worry the bad guys assured us things were okay"
Even other bad guys have an incentive to stop these bad guys from leaking the info after getting paid.
Re: Instructure pays ransom to Canvas hackers
#17on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…
Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom.
This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing the individual victim to not pay, otherwise they will always be incentivized to pay and ransoms will continue to be profitable.
Re: Instructure pays ransom to Canvas hackers
#18Earlier quoted context omitted.
I thought it was illegal to pay ransom to hackers. I guess it is legal or maybe it isn't very clear? I thought that there were certain conditions that the company had to check together with law enforcement so that at least the ransom money doesn't go to a hacker group that is on a government payments sanctions list. Also, does anyone know the root cause of the attack? I read a rumor online (but it's not really confir…
Not only is it not illegal, there are insurance policies set up to take care of this very scenario. It's almost always handled by a third party, not the company themselves, that would deal with any such concerns.
Re: Instructure pays ransom to Canvas hackers
#19on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…
We'd either end up with a Discworld "Ransomware Guild" that you pay "insurance" to and they murdicate anyone who dares do extracurricular data ransoming, or you'd have systems build on end-to-end encryption where the data is worthless.