Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

371–380 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#371

Earlier quoted context omitted.

As a business owner, I can tell you that having a “cyber” rider on a business E&O policy can be eye-wateringly expensive.

As an infosec practitioner, I can’t tell you how many times I’ve seen someone have insurance and their security posture be effectively nothing, or the insurance not pay out even with reasonable measures in place. Market failure in my opinion, needs more regulation.

Agreed.

I’ve done a lot of infrastructure work, so my home network is...robust. Quite unusual; even for many corporations.

Two DMZs, three routers, three WiFi networks, two NAS units, etc. Also lots of redundant backups.

Re: US travel firm $4.5M ransom negotiation open chat

#372
post #32

Earlier quoted context omitted.

I don't know about that. For one, travel margins are not exactly the same as SaaS margins. Secondly, there's the global pandemic and all, kinda hurts the free cash of most travel companies. I wouldn't be surprised if they genuinely would have trouble coughing up 10 million two days after the attack hit.

CWT is used by corporate travel systems. I'd expect their margins to be similar to enterprise software vendors, rather than other travel agencies.

theyr'e what we call a travel management company ( = travel agency + software solutions). Their margins are close to the travel agency though, that represents the vast majority of their revenue. They're particularly exposed to business travel, so even worse for them at the moment

Re: US travel firm $4.5M ransom negotiation open chat

#374

Earlier quoted context omitted.

>>democratizing large scale crime Ah give me a break, I am having a very hard time wrapping my mind around this obsession HN has for hating cryptocurrencies and blockchains. Solution to everything is to ban things we don't like, also while we are at it, lets ban credit cards too, credit-card fraud is close to 30Billion world wide[1]. People tend to focus on the bad about technology instead of all the good it can brin…

> everything can be used for both good and bad I'd love to hear from you about all the good that Bitcoin has brought. Please enlighten us.

Lots of downvotes, but no answer. I guess that's the answer then.

Re: US travel firm $4.5M ransom negotiation open chat

#375
post #361

Garmin, now this, in one week. I beleive it is much easier to pull a trick like this with the help from the inside. If so, with malicious insider's incentives in a ballpark of hundreds of thousands we are doomed :(

And yet, these hacks tend to be done with some social engineering and no insider knowledge. Many companies aren't well protected, you don't need an insider to hack them.

I think this is just a beginning. Word is out you can extort millions with internet connection and some scripts, no guns and police chase involved. And it looks like chances of getting away with the money are quite high. Compare it with Getty III ransom story.

Re: US travel firm $4.5M ransom negotiation open chat

#376
post #158

Earlier quoted context omitted.

Kinda funny to see 1BTC sent to check it worked before they sent the rest. Cant undo it like a wire transfer...

But why 1 BTC? That's worth more than 10k. Surely they could have sent a fraction? Or maybe they didn't know bitcoins can be split?

10k is not that much considering they are ready to pay out 5M

Re: US travel firm $4.5M ransom negotiation open chat

#378

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. It may also lead to companies paying for a more aggressive response. Uber has been known to deal with fraud by eventually finding the fraudster, even in Nigeria, and having them "visited".[1] [1]…

[deleted]

Re: US travel firm $4.5M ransom negotiation open chat

#379
post #344

Earlier quoted context omitted.

Nothing will change until they make it a felony to pay a ransom.

Isn’t it already a felony to attack computer systems and hold data for ransom? That doesn’t seem to be working flawlessly.

Yes, but the affected company is the one paying the ransom. Make that a felony and suddenly their choice is to invest in security or risk having their business halted for potentially months.

Re: US travel firm $4.5M ransom negotiation open chat

#380

Earlier quoted context omitted.

That analogy only works if banks were paying people to pretend to rob them all day every day and show them how they did it, and also underpaying them. so, no.

Actually, you're making my point for me. Banks don't typically hire physical pen testers at all, and yet our reaction to a bank robbery is not, "Well, that's just what you get for not taking security seriously." Nor is that our reaction when a gas station gets held up. In a perfect world, everyone can be trusted, and we don't need locks on our doors or passwords on our phones. In a dystopia, everyone has to carry a g…

Companies should be liable for negligence depending on the kind of hack. If they were hacked through use of an old package - defined by regulations - then they should be liable.

If it was a zero-day or something newer - defined by regulations - then the company is not liable.

Your analogies are cute but I want new laws, further making your analogies moot.

Post reply on HN