Earlier quoted context omitted.
The US needs to pass a Federal law making it personally (not just "corporately") illegal to pay ransom. That would stop them because it would kill the market. Historically it's how they stop kidnapping in countries where it's common. It REALLY sucks for the first few people after the law is passed, but after that things get better.
But wouldn't the payments just end up being passed through? For example, one way to get around that is you could sign a contract with a foreign consultant firm for "security services", say for 1 year, and they would take your money, and pay a portion of it to the ransomware authors and profit on the rest.
US travel firm $4.5M ransom negotiation open chat
51–60 of 480 posts
Re: US travel firm $4.5M ransom negotiation open chat
#52This story is going to be used by every security consultant selling their services for a long, long time.
When I started my career I'd always hear old greybeards talk about "oh this one time.. some certain thing happened, and everyone learnt a lesson" and I feel like I just witnessed one of those come into existence
$4 million once times the risk of getting hit vs. the up-front and ongoing costs of dealing with an overly paranoid IT guy.
Tough call.
Re: US travel firm $4.5M ransom negotiation open chat
#53For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…
Does that revenue include pass-through?
Re: US travel firm $4.5M ransom negotiation open chat
#54It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
I don’t know much about this travel agency. They may or may not have had a security team. What they did have was mentioned in this article: liability. They took steps to reduce or eliminate this liability. I think we all know that there’s no proof these attackers acted in good faith past the actual decryption, but now CWT can at least say they attempted to recover lost data.
I think we can only realistically hold companies liable for transactions like this when we have better government resourcing and oversight. Getting the FBI involved in stuff like this is difficult, as they’re over loaded with such cases.
I also feel we should never hold individuals liable for stuff like this. It’s unreasonable to expect people who aren’t security professionals to know how to defend or respond to threats like this given how rapidly the landscape changes.
Figuring out a good way to holistically deal with cyber criminals will probably be a problem we struggle with for years, if not decades.
Re: US travel firm $4.5M ransom negotiation open chat
#55We are truly in the age of rich data pirates. I dont see them becoming extinct any time soon with decent ROI like this. I would be curious to learn the % of origins for most attacks. [1] Incompetence by dumb employees [2] Insider attacks [3] Paid cybersecurity protection racket that take down strong systems with stolen tech [4] Unskilled or understaffed security employees
The US needs to pass a Federal law making it personally (not just "corporately") illegal to pay ransom. That would stop them because it would kill the market. Historically it's how they stop kidnapping in countries where it's common. It REALLY sucks for the first few people after the law is passed, but after that things get better.
Is this based in reality? What countries have banned ransom payments for human kidnapping and what people did it “suck” for?
My hunch is that if your spouse gets kidnapped and you have the means to get them back, you’ll risk it.
Re: US travel firm $4.5M ransom negotiation open chat
#56Earlier quoted context omitted.
I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?
In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.
Re: US travel firm $4.5M ransom negotiation open chat
#57It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.
Re: US travel firm $4.5M ransom negotiation open chat
#58It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
Isn't this likely short sighted in the same way that people talk about draconic enforcement of immigration laws? Criminalizing ransoms will result in victims doing it in secret, not in the elimination of ransoms. People won't be able to share information, and the financial incentive will continue to exist.
Re: US travel firm $4.5M ransom negotiation open chat
#59It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.
I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?
Re: US travel firm $4.5M ransom negotiation open chat
#60So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.