Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

81–90 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#81

What are the chances this is a $4.5m transfer to North Korea?

Low. The hackers are likely European, since there are telltales like European number formatting ("10.000.000$") and awkward phrases like "make a step forward" (perhaps Italian fare un passo avanti?).

Re: US travel firm $4.5M ransom negotiation open chat

#83
post #33

Earlier quoted context omitted.

Take backups, practice restoring them, invest in a security program.

Just having backups isn't enough. It's ransomware 101 to wait and try to encrypt all of their online backups and any recent offline backups. You really need comprehensive, air-gapped backups that date to years back.

> It's ransomware 101 to wait

Not really. A sister company of my previous company had ransomware incident, and as far as I've heard this was not the case. They had just purged local backups. The attack was stopped quite early by an engineer noticing abnormally high IO activity and shutting the whole infrastructure down as soon as they realized what's going on - while a lot of data was lost and had to be restored from backups, most of the files were untouched. Still, the recovery took really long while to audit every machine before they could be even powered on again.

Poisoning backups requires backup systems receiving encrypted data for a while. Which means live systems running off the encrypted data (and most ransomware encrypts at the file level, which is much harder to do transparently, compared to the block device level). Which requires effort to make sure this is extremely transparent and goes unnoticed. Doubt that attackers do expend their resources unless they see a necessity.

Re: US travel firm $4.5M ransom negotiation open chat

#84

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

It definitely makes the costs of bad security immediately obvious to the company, rather than just taking the data and selling it, which externalizes the cost to the user.

Re: US travel firm $4.5M ransom negotiation open chat

#85

Earlier quoted context omitted.

So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.

> let any company that doesn't have the budget to have a proper cybersecurity team just die? Are you implying that without a cybersecurity team, you'll fall victim to ransomware and be forced to pay up to stay in business? Because that's a false dichotomy - the simplest of backup solutions would have prevented this. And if a company can't manage the most basic offline redundancy for their critical business operations…

> the simplest of backup solutions would have prevented this

A big part of the threat is the disclosure of sensitive data that they exfiltrated. Backups don't help this.

Not to mention that the pros delay encryption until they've managed to screw up backups, too.

Re: US travel firm $4.5M ransom negotiation open chat

#86
post #21

Earlier quoted context omitted.

But wouldn't the payments just end up being passed through? For example, one way to get around that is you could sign a contract with a foreign consultant firm for "security services", say for 1 year, and they would take your money, and pay a portion of it to the ransomware authors and profit on the rest.

Wouldn't that be extremely obvious though?

Not when it's done through several layers of employees and then potentially multiple layers of foreign companies.

It's very hard to find individuals to hold criminally liable for things like this. When was the last time you saw a CEO go to jail when their company killed someone?

Re: US travel firm $4.5M ransom negotiation open chat

#87

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

The folks like this should actually do a startup. Hardening security is often just keeping up with and following checklists, installing proper monitoring, backup and audit software however for large majority of company it is impossible to hire competitive security specialists. These guys can scale up by hiring 100s of employees who they train on different aspects and contract with small firms like these at annual subscription. That would enable them making much more than $10M. With their current approach they will almost certainly get traced eventually and end up in jail.

Re: US travel firm $4.5M ransom negotiation open chat

#88
post #10

We are truly in the age of rich data pirates. I dont see them becoming extinct any time soon with decent ROI like this. I would be curious to learn the % of origins for most attacks. [1] Incompetence by dumb employees [2] Insider attacks [3] Paid cybersecurity protection racket that take down strong systems with stolen tech [4] Unskilled or understaffed security employees

The US needs to pass a Federal law making it personally (not just "corporately") illegal to pay ransom. That would stop them because it would kill the market. Historically it's how they stop kidnapping in countries where it's common. It REALLY sucks for the first few people after the law is passed, but after that things get better.

What countries are you talking about? Because kidnap insurance is still a moderate size business

Re: US travel firm $4.5M ransom negotiation open chat

#89
post #19

For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…

Is the ransom tax deductible?
Post reply on HN