Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

191–200 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#191

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

> “Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. This has nothing to do with that idea. The reason the orgs paid the random once was because they had a severe lack of backup and other data safety protocols in combination with a vector to be infected (from all what we know, the latter is common and difficult to avoid): paying the ran…

I think that mantra does work here.

I would be totally fine with legislation making it illegal to pay in the case of ransomware attacks. Some companies might be completely destroyed by an attack that they can't pay off, but that is for the greater good of society: if criminals know companies have a low probability of paying since they're legally barred from doing so, they're less likely to target them.

Re: 80% of orgs that paid the ransom were hit again

#192
How long do major companies keep back ups? It seems like all of these companies that keep getting hit with ransomware Only have last weeks back up laying around. Why can’t you go back eight months? True the data is going to be lacking, but at least the structure is going to be there. I completely understand that a Trojan or a virus can get locked into a back up and it just keeps getting backed up, but if you go far enough back you will find a clean copy.

Re: 80% of orgs that paid the ransom were hit again

#193

Earlier quoted context omitted.

The "don't negotiate with terrorists" is itself a negotiation tactic meant to lower the attack surface of any entity. It's the sort of thing you say publicly, but then privately you settle with your adversary. Absolutism is never a useful tactic.

> Absolutism is never a useful tactic. That sounds pretty absolutest.

I absolutely never always disagree, most of the time.

Re: 80% of orgs that paid the ransom were hit again

#194

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

What would be the incentive not to? Honor among thieves?

You know they’re vulnerable to the attack (the hard part?) so why not keep doing it until they shore up their defenses.

Re: 80% of orgs that paid the ransom were hit again

#195

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

I mean, of course! This is like classic sales book play. Your previous "costumers" are almost always less effort to dollar than new prospects.

Re: 80% of orgs that paid the ransom were hit again

#196
post #149

Earlier quoted context omitted.

When they hit a hospital, what is the hospital supposed to do? Not negotiate, for some "greater good" and let patients die? https://threatpost.com/ransomware-hits-hospitals-hardest/162...

They’re supposed to back up their data and set up proper contingencies. By failing to do so, they are already putting patients lives in the hands of the encryptors.

Yes. Of course they were supposed to do so, then. But they didn't, and now they've been hit. Now, in the real world, what are they supposed to do: pay, or hold out and let the patients die as punishment for the hospital's mistakes?

Re: 80% of orgs that paid the ransom were hit again

#197
post #144

Earlier quoted context omitted.

What an absurd statement, to just say unequivocally, ignoring the plenty of philosophies and ethical systems have disagreed entirely with that.

Yeah, totally absurd. Would you sacrifice your life for the strangers on this forum? Let me guess, no? Huh, wild.

[deleted]

Re: 80% of orgs that paid the ransom were hit again

#198

What I suspect: the first ransom was paid by insurance, therefore it didn't hurt them, therefore they didn't bother protect themselves for the second. Now just wait to see what will happen to your insurance rate after you pay the third ransom. They certainly will begin to understand the need for backups.

Most of these start as phishes to lower level employees. It makes sense to me that’ll happen again and I’m not sure I can say the solution is better backups.

Another issue with backups, is are you restoring to an already infected / immediately infectable state?

I think the better closer is “The certainly will begin to take security, training, and best practices seriously”.

Re: 80% of orgs that paid the ransom were hit again

#199
post #144

Earlier quoted context omitted.

What an absurd statement, to just say unequivocally, ignoring the plenty of philosophies and ethical systems have disagreed entirely with that.

Yeah, totally absurd. Would you sacrifice your life for the strangers on this forum? Let me guess, no? Huh, wild.

Yawn.

Re: 80% of orgs that paid the ransom were hit again

#200
post #185
post #12

Earlier quoted context omitted.

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Coming soon: ransomware with subscription business model

I up voted you for the lulz, but I'm actually unsure if this isn't the basic "legitimate" business model for everyone anyway.
Post reply on HN