Negotiating Ransom: To Pay Or Not?

Ransomware is one of the key cyber security threats that faces business and the cyber criminals behind it are becoming more dangerousOver the past eighteen months there has been a surge of ransomware attacks, made more disruptive by the complications of Coronavirus.  

From the criminals’ point of view, ransomware is massively profitable and a relatively easy exploit to accomplish. According to the European Union Agency for Cybersecurity (ENISA) 45 percent of victim organisations pay the ransom.

In December 2020, the acting head of the US Cybersecurity and Infrastructure Security Agency (CISA) said that ransomware was “quickly becoming a national emergency,” and it now effects most countries and corporates. In Britain, Lindy Cameron, newly appointed the chief of the British National Cyber Security Centre (NCSC) says her agency is committed to tackling the threat of ransomware and "supports victims of ransomware every day" but that a coordinated response is required to combat the growing threat. 

Speaking earlier this month, Lindy Cameron said "For the vast majority of UK citizens and businesses, and indeed for the vast majority of critical national infrastructure providers and government service providers, the primary key threat is not state actors but cyber criminals." She also noted that the ecosystem is evolving through the Ransomware as a Service (RaaS) model, whereby ransomware variants and commodity listings are available off the shelf for a one-off payment or a share of the profits.

Many analysts were surprised at how quickly the attack victim paid the $4.4 million ransom demanded when the US Colonial Pipeline was struck with ransomware recently, although much of the money extorted has since been recovered by the FBI.

The Colonial Pipeline CEO Joseph Blount told US lawmakers that although his company had an emergency-response plan in place, it didn’t include plans for responding to a ransomware attack.  However, the company did have insurance to pay for ransomware attacks, so the decision to pay was swift. A ransomware notice first appeared on a machine in Colonial Pipeline’s control room around 5 a.m. on May 7th and by 6 a.m. the company had shut down its 5,000-mile pipeline, Blount testified. 

By 7 a.m. the company had contacted outside legal counsel and engaged digital investigations firm FireEye to begin a forensic assessment of the damage. By late afternoon the same day, Blount decided to pay the ransom and on May 8th the money was sent.

The FBI advises victims to avoid negotiating with hackers, arguing that paying ransoms incentivises criminal behavior. This puts victims in a tricky position. “Regardless of whether you or your organisation have decided to pay the ransom, the FBI urges you to report ransomware incidents to law enforcement. Doing so provides investigators with the critical information they need to track ransomware attackers, hold them accountable under US law, and prevent future attacks”, says an FBI report.

The rise in ransomware as a business for criminals has produced a parallel rise in companies engaged in helping victims negotiate ransoms and recover the money extorted. 

Negotiating ransoms is a fraught process that can take more than a week and change rapidly, depending on the demands of the extortionists and the condition of the victim’s backups, according to Bill Siegel, CEO and co-founder of Coveware, a company that negotiates ransomware payments for victims. Coveware also aggregates statistics and other data about ransomware incidents to help the government track the scourge. Siegel told The New Yorker that Coveware has negotiated a “few thousand” ransomware cases since 2018 and that each case is different..

Siegel declined to discuss his customers or the specifics of negotiations, to avoid giving ransomware actors insight into negotiating tactics. Handling one of these negotiations is not easy and often goes five or seven days, it typically means that the company isn’t sure if they actually need to pay or not.

If an organisation has to pay very fast, it’s typically because they know they have no other means to recover.

The issue for most organisations is that they have not properly configured a backup if they suffer a ransomware attack. A server that gets impacted with ransomware has to be, at a minimum, heavily remediated to ever be trusted again. The best practice is to establish a clean backup network where you can re-image all of the servers, re-install all of the applications and then, for the data,  upload uncontaminated backups that you can restore to the backup network servers. To determine if files will decrypt properly you need to do scans on all of the encrypted files to look at the integrity of the encryption. A properly encrypted file will normally properly decrypt. 

A major aspect of the he Colonial Pipeline outage is that it had cascading effects that the company had no direct control over - the reaction of consumers - who started panic-buying and hoarding fuel.  Even though there wasn’t actually a fuel shortage, people created a fuel shortage from panic.

This is a compelling example of the follow-on effects that might not anticipated in an emergency and which that can put pressure on organisations to pay the ransom.

NCSC:    FBI:     Zero Day:    New Yorker:     ENISA:     SHRM:    ZDNet:   CloudsavvyIT:     Schnier On Security:

Image: Unsplash

You Might Also Read:

Running Out Of Cyber Gas

Will Governments Ban Ransom Payments To Hackers?:

 

 

« DarkSide May Not Stay Dark For Long
Global Police Operation Closes Fake Pharma Websites »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

National Agency for the Security of Information Systems (ANSSI) - France

National Agency for the Security of Information Systems (ANSSI) - France

The role of Agence Nationale de la Sécurité des Systèmes d'Information (ANSSI) is to foster a coordinated, ambitious, pro-active response to cybersecurity issues in France.

Bayshore Networks

Bayshore Networks

Bayshore Networks was founded to safely and securely protect Industrial IoT (IIoT) networks, applications, machines and workers from cyber threats.

itWatch

itWatch

itWatch is focused on data loss prevention (DLP), endpoint security, mobile security, encryption, and cost reducing solutions for IT operations.

OneWelcome

OneWelcome

Onegini and iWelcome have merged to become OneWelcome, the largest European Identity Access Management Saas Vendor.

Ensconce Data Technology (EDT)

Ensconce Data Technology (EDT)

EDT’s focus is on providing solutions to properly sanitize Solid State Drives (SSD) and Magnetic Drives (HDD) before they are disposed or redeployed.

Asia Data Destruction (ADD)

Asia Data Destruction (ADD)

ADD is the leading IT Assets Disposal and Data Destruction Company in Thailand.

eLearnSecurity

eLearnSecurity

eLearnSecurity is an innovator in the IT Security training market providing quality online courses paired with highly practical virtual labs.

Aujus Cybersecurity

Aujus Cybersecurity

Aujas is a pure-play cyber security services company with deep expertise in Identity and Access Management, Managed Security and Security Testing services.

Cybersecure Policy Exchange (CPX)

Cybersecure Policy Exchange (CPX)

Cybersecure Policy Exchange is a new initiative dedicated to advancing effective and innovative public policy in cybersecurity and digital privacy.

CyberNews

CyberNews

Cybernews.com is a research-based online publication that helps people navigate a safe path through their increasingly complex digital lives.

Outseer

Outseer

Outseer is a leading technology company in the fight against payments fraud. Outseer reliably determines authentic customers from fraudulent behavior.

Cheops Technology

Cheops Technology

Cheops is a specialist in IT Business Technology Services. We help SMEs and large companies build, optimize and manage their IT so they can focus on their core business.

ITProTV

ITProTV

ITProTV is part of the ACI Learning family of companies providing Audit, Cyber, and IT learning solutions for enterprise and consumer markets.

Sunday Cyber

Sunday Cyber

Sunday is a personal cybersecurity platform, built to protect the world’s top executive teams beyond the enterprise perimeter.

Keytos

Keytos

Keytos has revolutionized the Identity Management and PKI industry by creating cryptographic tools that allow you to go password-less by making security transparent to the user.

Bearer

Bearer

Bearer helps modern teams ship trustworthy products with the help of our code security solution built for security, privacy and engineering teams.