Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…
I’ve been wondering this too. Extortion and terrorism seem similar in many ways except the latter involves physical harm. I’d asssume a company paying money to terrorists shouldn’t be acceptable. It also seems especially egregious to pay ransom as a “solution” to the failings that made the attack both possible and consequential in the first place. Might as well use a bank whose safe deposit boxes are made of cardboar…
You are paying an extra fee for not testing your own software and infrastructure. It was instead tested by a third party. Be glad it wasn't tested by a nation state actor or someone who wanted to do more harm to your customers than just asking for money.
Ideally they should now secure their infrastructure and take this as a gentle reminder that they should spend more on security.
>Might as well use a bank whose safe deposit boxes are made of cardboard… They can just bribe the thieves to give some things back.
You would hope they would then upgrade the cardboard.