News: 1585862913

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Why is ransomware still a thing? One-in-three polled netizens say they would cave to extortion demands

(2020/04/02)


Want to know why ransomware is still rampant? One in three surveyed folks in North Americans said they would be willing to pay up to unscramble their files once their personal systems were infected.

This is according to [1]a customer survey [PDF] by Kaspersky Lab. The Russian security house polled more than 2,000 business workers in the US, and 1,000 in Canada, in an online study, and found that 33 per cent would cough up at least some money to cyber-extortionists to get their data back on their own personal machines.

If you're a crook, one third of your victims paying out is a pretty nice return, especially when Kaspersky estimates that 1.2 million people are hit with ransomware every six months. Americans are easier marks than Canadians, the study found, so the US can't [2]blame Canada for this one.

Kids today...

Young adults are the best target for extortionists, it seems. The study noted that 20 per cent of people born between 1995 and 2002 (that's 18 to 25 years old) said they would shell out between $50 and $200 to get their personal info back. Only seven per cent of people born before 1964 would be willing to pay that much.

Fresh virus misery for Illinois: Public health agency taken down by... web ransomware. Great timing, scumbags [3]READ MORE

When the question was changed from personal computers to data encrypted on company machines, 39 per cent said the cash demand should be paid, we note.

Amusingly, five per cent of people think employees should shoulder the financial burden if companies reuse to cough up the ransom, paying the costs of a leak out of their own pockets.

This is where we should point out that paying ransomware fees is a really bad idea. Security and law enforcement groups alike agree that keeping regular offline backups and patching your software is a far better plan than paying demands, and [4]there is no guarantee you will even get your data back should you agree to foot the extortion fees.

While it is considered a best practice not to give in to ransomware demands, some suggest that tough talk only goes so far, and when it comes down to getting critical business data back, sometimes [5]there is a case for paying up. ®



[1] https://media.kasperskydaily.com/wp-content/uploads/sites/85/2020/03/25170451/Final_Ransomware-Report.pdf

[2] https://www.youtube.com/watch?v=bOR38552MJA

[3] https://www.theregister.co.uk/2020/03/12/ransomware_illinois_health/

[4] https://www.theregister.co.uk/2018/03/09/less_than_half_of_ransomware_marks_get_their_files_back/

[5] https://www.theregister.co.uk/2019/06/06/ransomware_coping_strategy/

One in three

Pascal Monett

I'm willing to bet that all of them

1) have no technical understanding of what they're using

2) are incapable of making a backup if their life depended on it, and

3) will still not learn the importance of backups if it does happen to them

That is the price to pay when computing has been commoditized. That thing that is grafted to your hand is a computer. Learn how it works beyond just flicking screens from right to left.

Re: One in three

The Central Scrutinizer

In my experience with friends and relatives, your average computer user is mostly technologically illiterate. Computers are just appliances these days unfortunately, or at least most people seem to treat them that way. Actually knowing how they work is just too much bother.

Happirstday of my life...

Lorribot

When my son came over and said his laptop had been encrypted what should he do?

Have got backups of all your course work?

Yes, two copies, on Uni servers and USB drive

Photos and music?

Yes, phone and OneDrive

Ok do a reset on Windows and don't visit that site again, you will need to reinstall and re-download software and games. You good to go?

Ok.

Oh happy days he was actually listening.All his stuff was OK no course work lost and lesson learned.

Basically, ioctl's will _never_ be done right, because of the way people
think about them. They are a back door. They are by design typeless and
without rules. They are, in fact, the Microsoft of UNIX.

- Linus Torvalds on linux-kernel