Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

131–140 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#131

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

How is it not a violation of AML laws to pay a ransom like this? Surely they didn't verify that the recipient (a criminal) isn't sanctioned or associated with sanctioned organizations.

Even if it already is, the DoJ can exercise discretion in choosing who to prosecute. There has to be political will to threaten an org who has just suffered from an attack with further consequences if they make a payment.

Re: Instructure pays ransom to Canvas hackers

#132

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

That operates on the idea that hacker organizations use long term strategic thinking, something the US government and a good number of corporations don’t even practice. I wouldn’t put my money on that.

Re: Instructure pays ransom to Canvas hackers

#133
post #97
post #65

Earlier quoted context omitted.

What's to say they didn't copy the data then shred a copy, or hell even just fabricate some shred logs.

In the abstract, it’s hilarious to imagine the hackers keeping the data, then some time from now leaking it accidentally (or another hacker group hacks them) then them having to issue a public apology for not having kept the stolen data secure and having lied about shredding it.

However, they could use it as a last resort or as a final "gift" before getting arrested or switching identities.

They might be considered "trustworthy" right now to get companies to pay them money, but no one will know what will happen in a few years when this strategy won't work anymore.

Anyway, I hope this doesn't come at all, or as late as possible.

Re: Instructure pays ransom to Canvas hackers

#134

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

There's one more piece that matters.

If no one pays the ransoms, but people believe that large ransoms are paid-- you still have the crime.

Re: Instructure pays ransom to Canvas hackers

#135
post #108

How does things like this work in terms of bookkeeping? How do they label the expense? Can a company send huge amounts of money to an unknown crypto account without needing to explain anything to the tax authorities?

It's the insurance company paying the ransom and I assume they tie the payment to the insurance policy they are fulfilling, I don't know what the tax implications would be, I am not in finance or an accountant

Re: Instructure pays ransom to Canvas hackers

#136
post #102

Earlier quoted context omitted.

Depends on what they actually got. Names and email addresses? Considered public and are not so valuable. Universities usually publish those in a directory anyway. Messages between students and instructors? Likely pretty boring, but possibly embarassing or confidential for a given individual. Grades? Could be a FERPA violation. Critical PII such as SSNs? Probably not in the LMS to begin with.

I just spoke with a K-12 teacher I know, and she confirmed SSNs in the Canvas instance. Yikes.

They already have your SSN, as does anyone else who wants it.

Re: Instructure pays ransom to Canvas hackers

#137

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Isn't there still incentive because the data itself is valuable so attacks would continue?

Maybe, but it’s harder to profit from it. A firm may be reputationally damaged, but what’s the incentive to cause that damage?

I think the Bloomberg Odd Lots guy wrote a blog post on this: you could attempt to short the stock but a) this leaves a paper trail b) the market might not know about the breach or believe you if you post you’ve done it. IIRC some hackers have tried to tell companies that they are legally required to disclose the breach to their shareholders to force market movements.

Re: Instructure pays ransom to Canvas hackers

#139

Earlier quoted context omitted.

> As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If you’re sending a large sum of money to $anonymoushacker, how do you ensure they’re not on some OFAC list? Or do your AML checks? Or make sure you’re not on the wrong side of Foreign Corrupt Practices act? The third party probably turns a blind eye to that cuz there’s no way of really check…

Cryptocurrency mitigates most of those concerns. That's why the flourishing of crypto payment systems has been an unalloyed blessing for cybercriminals.

It can at a technical level but not at a legal level.

Your BigCo accounting department is not going to be very understanding about acquiring cryptocurrency to send to ??? for a ransom.

Re: Instructure pays ransom to Canvas hackers

#140
post #58
post #5

LOL that's some super heavy duty optics framing on what basically amounts to "we paid out a ransom but don't worry the bad guys assured us things were okay"

They said “received digital confirmation of data destruction (shred logs)” - is this supposed to fool users into thinking the hackers didn’t keep any of the data?

The criminals did not share the logs of them making a copy of the data before shredding it; so obviously that didn't happen.
Post reply on HN