Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

201–210 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#201

I found it interesting none of these sites actually provided the alleged bitcoin wallet address. I found it @ https://www.blockchain.com/btc/address/13nmJ3SsNB5pSyQrmX3e6...

Can the money be followed here? How they are going to spend it if it’s marked as stolen?

Re: US travel firm $4.5M ransom negotiation open chat

#202
post #19

For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…

It might over time. If I was deploying ransomware, the first thing I would do after receiving a ransom payment from a company would be to try them again in a month or two.

Re: US travel firm $4.5M ransom negotiation open chat

#203

I found it interesting none of these sites actually provided the alleged bitcoin wallet address. I found it @ https://www.blockchain.com/btc/address/13nmJ3SsNB5pSyQrmX3e6...

clicked through the transactions and found this wallet: https://www.blockchain.com/btc/address/17A16QmavnUfCW11DAApi...

a balance of 16m and over 1.4 trillon usd has passed through this account.

the oldest transaction i could find was 2019-11-02 14:19: https://www.blockchain.com/btc/address/17A16QmavnUfCW11DAApi...

Re: US travel firm $4.5M ransom negotiation open chat

#204
post #87

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

The folks like this should actually do a startup. Hardening security is often just keeping up with and following checklists, installing proper monitoring, backup and audit software however for large majority of company it is impossible to hire competitive security specialists. These guys can scale up by hiring 100s of employees who they train on different aspects and contract with small firms like these at annual sub…

Even just hiring one guy whose only job is to take backups would solve ransomware for much cheaper.

Re: US travel firm $4.5M ransom negotiation open chat

#205
post #143

Earlier quoted context omitted.

The entire thing relies on several things: nearly always-on connectivity, ability to convert to USD, crummy UX, and legit cover. A ban would do serious harm to 2, 3 and 4. If no one could pay legitimately and it would become (ever more) difficult to launder, the ransomware demands would die. The first (connectivity) could be impacted as well. What would happen when traffic shaping makes sync take longer and when ever…

This isn’t a defense of Bitcoin. I’m often quite critical of cryptocurrency and believe the world would be better off without it. However, “banning” it won’t have the effects you’ve described, and you seem have some misunderstandings about how Bitcoin works, especially as it pertains to the criminal world. 1. Bitcoin transactions don’t require access to the internet at the time the transaction takes place. There have…

1. Passing keys around risks the original sender (or anyone listening in) grabbing the money after 'payment', and voids any guarantees Bitcoin etc. might be able to make - the transaction isn't even listed on the chain.

This would turn a 'trustless blockchain' to a 'non-blockchain relying on trust'. Assuming this transition can even be done (what would be the point of cryptocurrency in that case?), the result would be like the known hawala networks, which at least do not enable so much criminal activity and have some decent uses.

2,4. Bitcoin had an aura around it. Something experimental not really concerned with money or big crime, maybe a way to buy light drugs. Later on as a magnet for speculation. Remove the official cover, and laundering would become way more difficult.

3. There's terrible UX, and there's 'terrible horrible UX when one could easily lose money because the ISP closes your lightening connection'.

So I think this is possible to enforce, not completely, but there's no need for 100% enforcement to have a positive effect.

Re: US travel firm $4.5M ransom negotiation open chat

#206
post #144

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Cryptocurrency_tumbler

What happens when crypto tumblers run away with the money

it seems logical to me a sophisticated syndicate would run their own tumbler. I'd assume there is some kind of OSS wordpress for mixing out there. And I don't think it'd be that hard to get other people to use it to get liquidity (just offer it as a free service).

Re: US travel firm $4.5M ransom negotiation open chat

#207
post #159

Earlier quoted context omitted.

500 unrelated accounts all deposit money into a single shared account. From that shared account, payments are made to 1,000 other accounts. None of the amounts match the original deposits, even when summed. Whose money is whose? This is an oversimplification, but it should give you a rough idea of how difficult it is to trace Bitcoin.

Authorities might already know mixers service providers and a subpoena will give them all info they need. Not sure tho, I haven't used bitcoin but there always be weak link somewhere

How are you going to identify them? When they cash out, all their Bitcoin has already been laundered.

Granted, this is all theoretical. In practice, it’s not unusual for such people to make mistakes that reveal their identity; however, there’s nothing inherent to Bitcoin that ensures they can be de-anonymized.

Usually they attempt to go after hosting providers, but when the services are only accessible by Tor and they’re using bulletproof hosting—hosting providers who do their best to avoid law enforcement—that’s no easy feat. It’s not impossible, but it can be both a technical and diplomatic nightmare.

Re: US travel firm $4.5M ransom negotiation open chat

#208

What are the chances this is a $4.5m transfer to North Korea?

Low. The hackers are likely European, since there are telltales like European number formatting ("10.000.000$") and awkward phrases like "make a step forward" (perhaps Italian fare un passo avanti ?).

Google translate seems to jump to "take a step" for most languages I've tried that usually say "make/do a step". So this is likely someone with a little English but not knowing the idioms. Might have done better with Google translate.

Re: US travel firm $4.5M ransom negotiation open chat

#209
post #164

Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. This kind of attack would be almost impossible in the pre-bitcoin era. The difficulty of receiving that volume of money in that short of a period of time in a difficult to trace manner is a new thing. We are entering a new era where crime can pay in very large sums with orders of magnitude less complexity…

>This kind of attack would be almost impossible in the pre-bitcoin era. Is it? VIPs are regularly held for ransom in unstable countries, so much so that ransom insurance is a thing[1]. If those ransoms can be safely received, why can't it be the case for ransomware ransoms? [1] https://en.wikipedia.org/wiki/Kidnap_and_ransom_insurance

I don't see how the two are similar, because traditional kidnapping/ransom requires someone to somehow take physical delivery of a ransom in cash or highly portable, dense valuables (gold bars etc), which is risky. They're certainly not going to do it by ACH or SWIFT. The bitcoin part makes it non tangible and could be done from anywhere in the world.

Re: US travel firm $4.5M ransom negotiation open chat

#210
post #176

Earlier quoted context omitted.

is there a market for ransomware insurance?

If there were, the prices to unlock would skyrocket.... Unlike most kinds of insurance, the cost here is not a set thing.... It's arbitrary.

Can't you apply the same logic to regular ransoms? They say life is priceless, but there's clearly a limit. Also, unlike a human lie, there is a substitute for the unlock key... rebuilding your business from scratch.
Post reply on HN