Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

121–130 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#121

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

I'm shocked at such unethical practices by the hackers. I expected better from a group of terrorists.

Re: 80% of orgs that paid the ransom were hit again

#122
post #108

Earlier quoted context omitted.

No, because for better or worse “he” is the default for a plurality or unknown gender in most (all?) romance languages, including English. Times and sensitivities change but “she” still connotes more knowledge than “he” so it’s bound to cause some confusion.

what was true centuries ago is no longer true. "he" is not gender neutral in English, in any sense of the term. it's only used as such in historical writing - languages evolve over time. "she" connotes as much knowledge as "he".

Language changes over time, yes, but also over space. Something other than 'he' might be default where you are, but not where I am.

Re: 80% of orgs that paid the ransom were hit again

#123

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

Backup is only part of the picture, one needs a proper disaster recovery strategy that is tested and updated. Otherwise it could turn out that backups exist, but it'd take half a year to bootstrap the company back into function using them. Backing up and restoring one PC is trivial, doing the same to 10000 PCs and another 1000 of interconnected software systems is a whole different business.

Re: 80% of orgs that paid the ransom were hit again

#124

Doesnt this just mean that 80% of orgs that were hit with ransomware attacks just didn't bother to fix their infosec, and got hit again because they left the same holes open to be exploited? Fool me once, shame on you. Fool me twice, shame on me.

Most likely.

Re: 80% of orgs that paid the ransom were hit again

#125
post #78

Earlier quoted context omitted.

The US government has negotiated with the Taliban (a formally designated terrorist group) for prisoner exchanges. https://www.bbc.com/news/world-asia-50471186

The "don't negotiate with terrorists" is itself a negotiation tactic meant to lower the attack surface of any entity. It's the sort of thing you say publicly, but then privately you settle with your adversary. Absolutism is never a useful tactic.

> Absolutism is never a useful tactic.

That sounds pretty absolutest.

Re: 80% of orgs that paid the ransom were hit again

#126
Makes sense. We have a company with bad security practices (not easy to fix), inadequate disaster recovery strategy (not easy to fix) and willing to pay money to criminals to make problems go away. Of course it's an ideal target. I wonder if by now the criminals compile and trade the list of easy target companies.

Re: 80% of orgs that paid the ransom were hit again

#127
post #56

Earlier quoted context omitted.

I mean couldn't government pay the ransom and then go great lengths to track the suspects and send special forces after them? Surely US govt. has the ability to track almost anyone. Having US govt. on your ass should a decent deterrent. Just take a look at how hard FBI came down on cartels and individuals who were involved in killing Enrique Camarena. Cartel leaders were arrested in Mexico and several individual in t…

It appears that some of the major ransomware gangs are operating from Russia and are tolerated by the government, as long as they don't hit domestic targets. The US cannot really send special forces there without risking a massive escalation.

No, but the people operating in Russia like to travel elsewhere, and do.

Also, the US and allies can enforce Russian AML laws as written on paper. If, say, the UK freezes all of Oleg Deripaska's assets there, Vova will absolutely get the message. We're not going to bring down the Russian government with military force for a million different reasons, but doing it with sanctions and prosecution is a totally different story.

Re: 80% of orgs that paid the ransom were hit again

#128
post #12

Earlier quoted context omitted.

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Everyone knows that once you find a loose slots machine, you keeping playing it.

You might come back next week, but if it just jackpotted it's empty right now.

Re: 80% of orgs that paid the ransom were hit again

#129
post #12

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

It's right there in the small print. These companies sure know about that.

Re: 80% of orgs that paid the ransom were hit again

#130

Looks like ransomware criminals are going for the subscription model.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

For a second there, I thought you were going to say they can call themselves a backup service.
Post reply on HN