Live data from Hacker News

UCSF admits it paid NetWalker more than $1M ransom

databreaches.net

21–30 of 68 posts

Re: UCSF admits it paid NetWalker more than $1M ransom

#22
post #19
post #12

Earlier quoted context omitted.

How about kidnapping insurance? Should that be illegal?

There is already Cyberinsurance for this kind of scenario... so unless poster would like to make that illegal too...

Well cyberinsurance can be spent on things besides paying a ransom, such as hiring a security firm to investigate and a data recovery firm to try to recover data from backups. It can also cover revenue losses due to outages, and payout damages to your users if your users' data was stolen.

I guess theoretically kidnapping insurance might be spent on things besides a ransom as well, such as hiring mercenaries to recover the kidnapped person. But I doubt that's very likely.

Re: UCSF admits it paid NetWalker more than $1M ransom

#23
post #21

Earlier quoted context omitted.

That is not a reasonable comparison.

It's insurance that negotiates and pays ransom. How is that not comparable?

One has to do with a human life.

The other has to do with ones and zeroes on a hard drive.

Re: UCSF admits it paid NetWalker more than $1M ransom

#25
post #5

Always been curious about the tax accounting for ransoms. Does anyone know how it is reported usually? Going public must make it harder I guess? How do you explain a bitcoin purchase from a business account without an invoice to the taxman otherwise?

You don't usually have to report money you spend, at least if you're an individual. You only have to report money you make. If you're a victim you don't make any money. I doubt the attacker is reporting the income for tax purposes, so the attacker is breaking tax law most likely.

Re: UCSF admits it paid NetWalker more than $1M ransom

#26

The poor IT guys there probably asked for a couple thousand for backups instead and were previously denied. Ransomeware first rose to prominence three years ago. Yet seemingly little has been learned?

Having personally dealt with UCSF IT, I'd say that they don't deserve sympathy.

Re: UCSF admits it paid NetWalker more than $1M ransom

#27
post #9

Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

Agreed - paying ransom is funding and facilitating a criminal operation.

Re: UCSF admits it paid NetWalker more than $1M ransom

#28
post #9

Paying ransoms should be a criminal offense. That's the only way to remove the incentives for ransomware attacks. If that means some businesses fail or government agencies get temporarily shut down then that's acceptable collateral damage and will serve as an object lesson to others about the importance of IT security.

Saying that paying ransoms should be a criminal offense should be a criminal offense

Re: UCSF admits it paid NetWalker more than $1M ransom

#29

Earlier quoted context omitted.

What if they threaten to release the data? Is it really preferable to let personal info flood the net rather than pay?

Of course not. But if it was illegal to pay a ransom, the frequency of the crime would go down.

More likely the _reporting_ of the crime would go down. This hurts everyone

Re: UCSF admits it paid NetWalker more than $1M ransom

#30

Earlier quoted context omitted.

What if they threaten to release the data? Is it really preferable to let personal info flood the net rather than pay?

Of course not. But if it was illegal to pay a ransom, the frequency of the crime would go down.

But it would still happen. With this policy idea you are doubling the amount of criminals.
Post reply on HN