Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

151–160 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#151

Doesnt this just mean that 80% of orgs that were hit with ransomware attacks just didn't bother to fix their infosec, and got hit again because they left the same holes open to be exploited? Fool me once, shame on you. Fool me twice, shame on me.

So ransomware already means they got into the system, they could open a new secret backdoor or completely tear down your security if they wanted to. Plus it takes time to identify the ransomware to undo/remove it, so in that time they could attack again. paying ransomware ransoms is just saying "pretty please don't do this again".

Re: 80% of orgs that paid the ransom were hit again

#152

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

I would leave a backdoor too if I was them (maybe not what they did)... I wonder how many paid for a 2nd and 3rd time...

Re: 80% of orgs that paid the ransom were hit again

#153
post #16

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

I'm sorry but I have to ask: why assume the attacker is female?

To preempt criticism.

Re: 80% of orgs that paid the ransom were hit again

#154

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

If only organizations would backup their own data. Then they could just restore and avoid paying.

This is commonly suggested, and entirely useless.

What the ransomware groups do is put a time bomb on the computer, then leave it to trigger on a future condition. Your backup will backup the time bomb, and the second you restore it, it also goes boom. And therefore your backup is a perfect copy of your data but entirely useless.

Re: 80% of orgs that paid the ransom were hit again

#155
post #144

Earlier quoted context omitted.

From the perspective of the individual, there is no greater good than defending one’s self.

What an absurd statement, to just say unequivocally, ignoring the plenty of philosophies and ethical systems have disagreed entirely with that.

Yeah, totally absurd. Would you sacrifice your life for the strangers on this forum? Let me guess, no? Huh, wild.

Re: 80% of orgs that paid the ransom were hit again

#156

Earlier quoted context omitted.

If only there were organizations who weren't criminals at all and who could be paid by a company to maintain backups of the company's data.

If only managers would perceive the money spent to pay such organizations as a necessity rather than burned cash

As randomware attacks become more prevalent I suspect managers’ impressions will change!

Re: 80% of orgs that paid the ransom were hit again

#157
post #154

Earlier quoted context omitted.

If only organizations would backup their own data. Then they could just restore and avoid paying. I have a backup device of my own at home and that's the one I have to use. The company I work relies on some MSFT service that is pretty inflexible and won't back up the entire machine.

If only organizations would backup their own data. Then they could just restore and avoid paying. This is commonly suggested, and entirely useless. What the ransomware groups do is put a time bomb on the computer, then leave it to trigger on a future condition. Your backup will backup the time bomb, and the second you restore it, it also goes boom. And therefore your backup is a perfect copy of your data but entirely…

One should still be able to just mount the disk and not boot the OS associated to browse through the files? Not fully automated but at least some solution and maybe worthwhile for smaller businesses

Re: 80% of orgs that paid the ransom were hit again

#158

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

Until your own child or spouse is held hostage or sequestrated. You will negotiate.

Re: 80% of orgs that paid the ransom were hit again

#159
post #50

Earlier quoted context omitted.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

https://en.wikipedia.org/wiki/History_of_firefighting#Rome Fire fighting in Rome had a similar premise.

I think wikipedia got the details wrong there. Crassus didn't offer to buy the burning buildings, he offered to put fires out. At least, that's how I understood it years ago and that's what Wiki's own source shows-- http://www.trivia-library.com/b/richest-people-in-history-ma... .

edit: Actually, Plutarch wrote that Crassus did buy the burning buildings.

Re: 80% of orgs that paid the ransom were hit again

#160

Doesnt this just mean that 80% of orgs that were hit with ransomware attacks just didn't bother to fix their infosec, and got hit again because they left the same holes open to be exploited? Fool me once, shame on you. Fool me twice, shame on me.

Yes, but even more importantly it means they don’t have proper backups and disaster recovery.
Post reply on HN