Live data from Hacker News

Royal Mail dismisses ‘absurd’ $80M ransom demand

theguardian.com

91–100 of 108 posts

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#91
post #54

I bought some candy from Amazon that was shipped by Royal Mail, and it never arrived. Amazon told me to take up the refund with Royal Mail, with no instructions how to do so. Anyone know how I can get a refund from Amazon/Royal Mail for the candy they never sent?

Email jeff@amazon.com pleading your case.

[deleted]

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#92
Well, this sucks. I'm waiting for medicine to be delivered to continental Europe from Scotland through Royal Mail. Apparently their international packages are being delayed by a lot right now. Really hope this doesn't affect the operations too much and they'll be able to continue delivering in full capacity ASAP.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#93

If Russia were to physically disrupt a country's social services by force, it would be an act of war. Here they have disrupted a British social service without force by state sponsored hacker terrorists, rendering harm in the physical world. The line gets blurrier.

Since it was privatised it's no longer a social service, but a private corporation.

Not true. It's a privately run and public-service. Another example is electricity.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#94
post #39

Earlier quoted context omitted.

Royal Mail is still a very large corporation and could have paid. BUT they simply did not think the amount was worth paying, I suspect both in term of the direct consequence if the data were published (which the hackers apparently did in the end) and in term of PR, reputation, etc because they couldn't have kept the payment secret (too big). So IMHO the issue was miscalculating leverage.

There is one more point: by not paying they develop a reputation that they are not worth attacking. The next criminal org might just skip attacking them. If everyone follows this examples the criminals will give up.

It depends because the costs of running the malware operation are way less than 80M. At this point they are just going for the lulz.

the hackers already threatened going nuclear by releasing files and letting Europe fines their 0.5% which is more then 80M.

This is not over and Royal Mail is in a lose/lose situation here

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#95
post #44

Why is ransomware still a problem? Is it that difficult to make off-site backups every hour? Storage is cheap. There are many air gapping options for backups, too. It sounds like a case of normalized deviance, for which the management should be held accountable. As much as I don’t like victim blaming, I think it’s beyond incompetent to still not backup your data in 2023 as a government org.

They're not a government organization. Haven't been for almost 10 years

Ah, that’s true, looks like it has been privatized. But the government originally retained a significant stake in the company even after it was made publicly traded. Not sure about it today. Interesting point.

Though I think it’s even worse if a publicly traded company fails to protect its data and falls prey to the extortion. Don’t they have a fiduciary responsibility to their shareholders? It seems wrong to waste their money due to incompetence at such basic infosec.

Government orgs are more difficult to hold accountable for losses than PLCs.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#96
post #68
post #44

Why is ransomware still a problem? Is it that difficult to make off-site backups every hour? Storage is cheap. There are many air gapping options for backups, too. It sounds like a case of normalized deviance, for which the management should be held accountable. As much as I don’t like victim blaming, I think it’s beyond incompetent to still not backup your data in 2023 as a government org.

>Is it that difficult to make off-site backups every hour? Storage is cheap. There are many air gapping options for backups, too. I'd imagine that often your backups get encrypted as well, early enough that the data loss to the last good backup becomes unacceptable.

Yes, there would still be minimal loss. But not enough to be extorted over.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#97
post #36

Earlier quoted context omitted.

It’s not your problem. The seller is legally responsible for the delivery. Chat with Amazon again and remind them. Or consult with Citizens Advice if you need help. Amazon support eventually refunds basically anything if you are persistent enough.

Maybe, but in one specific occasion I know of, the client was told not to contact support anymore for a refund. I think it's a different retail landscape now to what it was in 2020-2022.

It doesn’t matter what they were told. It’s Amazon’s legal responsibility. And with enough reminding, they would refund eventually.

I’ve gotten refunds for parcels lost in 2020-22 even if I was denied them initially. It’s Amazon’s strategy to deny initially.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#98
post #11

How is it even legal to pay ransoms? Surely this is transferring money to criminal enterprises. If it is not illegal it needs to be made illegal.

It's also orders of magnitude cheaper to just restore from backup. I can't imagine their S3 bill is above 80 millions...

Crazy that none of the major companies hit by ransomware haven't thought of that...

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#99
post #44

Why is ransomware still a problem? Is it that difficult to make off-site backups every hour? Storage is cheap. There are many air gapping options for backups, too. It sounds like a case of normalized deviance, for which the management should be held accountable. As much as I don’t like victim blaming, I think it’s beyond incompetent to still not backup your data in 2023 as a government org.

I do auditing of backups and recovery.

It is crazy the number of companies that do not have appropriate visibility of what they're backing up. If the backups are immutable and if they have ever tested their ability to recover the environment.

And when I say the environment I mean all necessary components of the environment, not just applications, but their databases, Active Directory/Domain, DNS, DHCP, File servers, virtual infrastructure (VMware/HyperV).

In a virtualized environment the backup of these components is made easier, but you still need to understand what makes up your environment in order ensure you're backing it up appropriately.

Sometimes they have backups, but once they're forced to test them, realise they weren't backing up the right components or simply couldn't recover from those backups.

It's a big, risky exercise to perform, but important.

Re: Royal Mail dismisses ‘absurd’ $80M ransom demand

#100
post #44

Why is ransomware still a problem? Is it that difficult to make off-site backups every hour? Storage is cheap. There are many air gapping options for backups, too. It sounds like a case of normalized deviance, for which the management should be held accountable. As much as I don’t like victim blaming, I think it’s beyond incompetent to still not backup your data in 2023 as a government org.

Many ransoms now are for the leaking of the info, not the destruction of the info. With huge GDPR fines for data leaks in Europe, the criminals are using the legal system as their 'threat'.

In this case it’s encryption but interesting point.

GDPR fines come from not following basic data protection practices, not for the breach itself. Also, a lot of reputational damage of the leak comes from bad infosec (case study: LastPass). If the customer data is reasonably protected, there isn’t much motivation to pay ransoms.

Companies have data breaches all the time. Even a start-up I worked in in GDPR times had a data breach, and an extortion attempt. But all customer PI data was encrypted and only ever in plaintext on our end in an ephemeral way. The data was worthless, we never paid ransoms. We bought some darknet monitoring service for some fake canary user data, but nothing ever came up in 4 years after the breach. No ransom was ever paid and honestly, the data breach was on our minds for 10 days max.

This is not hard to do, it was done by two business guys who listened to infosec podcasts and read infosec articles online. Specialists in the area that I’m sure all of these ransomed big businesses can afford can definitely do much better data protection.

I don’t think companies are sued/prosecuted for GDPR non-compliance or any damage done to their customers if hashed blobs get leaked. Assuming the hackers even bother to leak them, because what are they going to say in the forums they sell the data on? “I have unknown encrypted data about some hashed usernames from company X”? Maybe one day in the far future that data will hold some value, but not today. I would more easily see investors suing the management for paying ransoms instead of doing even rudimentary data protection.

Post reply on HN