Live data from Hacker News

80% of orgs that paid the ransom were hit again

venturebeat.com

71–80 of 386 posts

Re: 80% of orgs that paid the ransom were hit again

#72

Looks like ransomware criminals are going for the subscription model.

Once the criminals start maintaining their own backups of victims data and helping them restore from rival attacks, they can successfully call themselves a mob. Somehow, that's a quite believable scenario.

I think they can start calling themselves the corporate IT department.

Re: 80% of orgs that paid the ransom were hit again

#75
I wish this said how many of those hit again also paid again. I find it easy to believe that you could be hit twice in a row despite your best intentions, but hard to believe that you'd need to pay the second time if you had established a backup solution.

Re: 80% of orgs that paid the ransom were hit again

#76
post #12

The most important line: > 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. The same group!

Makes sense to me. From what I've read, it's pretty clear the ransom payment is for a one-time ability to get your data back. It's not advertised as some sort of permanent opt-out.

Different groups have different policies. I believe some do actually add you to a whitelist if you pay and grant you at least a year or two before your immunity expires. (Maybe some do permanent whitelists? Not sure.)

Re: 80% of orgs that paid the ransom were hit again

#77
post #56

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

I mean couldn't government pay the ransom and then go great lengths to track the suspects and send special forces after them? Surely US govt. has the ability to track almost anyone. Having US govt. on your ass should a decent deterrent. Just take a look at how hard FBI came down on cartels and individuals who were involved in killing Enrique Camarena. Cartel leaders were arrested in Mexico and several individual in t…

That introduces a scale problem. Even for the US.

Re: 80% of orgs that paid the ransom were hit again

#78

“Never negotiate with terrorists” is a simple and clear mantra, and as most clear and simple concepts it hides a lot of assumptions. One of them is you are ready to lose the hostage in the worst case scenario. That’s how the police sees it, because the society benefits more from being firm in individual cases than losing a few of its members that might not come back anyway. That’s a hard one to swallow, hard enough t…

The US government has negotiated with the Taliban (a formally designated terrorist group) for prisoner exchanges.

https://www.bbc.com/news/world-asia-50471186

Re: 80% of orgs that paid the ransom were hit again

#79
post #16

Earlier quoted context omitted.

If the attacker isn't paid for the first attack, why would she attack again? She's not doing it for the lulz! I do agree with you that there should be more visibility for the "silent majority" of firms who operate their businesses responsibly, and therefore don't ever need to pay ransom.

I'm sorry but I have to ask: why assume the attacker is female?

The first time I saw this (using female pronouns for an unidentified person instead of "him/her" or "they") was in RMS's writings. So instead of using the indefinite/singular they, RMS would just say she/her. I thought it was an interesting way to hack language to break assumptions we have about gender, especially in technology.
Post reply on HN