News: 1596463342

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

'We stopped ransomware' boasts Blackbaud CEO. And by 'stopped' he means 'got insurance to pay off crooks'

(2020/08/03)


"We discovered and stopped a sophisticated attempted ransomware attack," Blackbaud CEO Michael Gianoni has told financial analysts – failing to mention the company simply paid off criminal extortionists to end the attack.

Speaking on the US cloud CRM provider's Q2 FY2020 earnings call late on Friday, Gianoni said: "Like a lot of companies, we get millions of intrusion attempts a month and unfortunately one got into a subset of our customers and a subset of our backup environment."

As we reported, Blackbaud [1]paid a demanded ransom back in May before quietly notifying the world two months later. Blackbaud accepted the criminals' assurances that stolen data would be deleted.

Nonetheless, companies and charities that use Blackbaud's CRM systems for fundraising and communications are duty-bound to report the data theft to regulators, at least on this side of the Atlantic. Although the firm insisted that financial data had not been accessed by the criminals, personal data stored on its servers by subscribing companies was.

On the Friday earnings call Blackbaud CFO Tony Boor added: "We currently don't anticipate any kind of material financial impact for the company [from the ransomware] . We do have insurance coverage that will come into play here as well."

These remarks may well dismay the global cybersecurity industry and governments alike. Standard advice is not to pay ransoms because doing so fuels the criminal economy behind ransomware, perpetuating this form of internet criminality. However, industry has increasingly ignored this advice; the availability of cyber insurance policies that pay out on ransom demands removes the largest disincentive from the equation.

Blackbaud at least has one partial excuse: late last year the US Federal Bureau of Investigation [2]relaxed its guidance on paying ransoms to acknowledge that some firms can and will pay up.

Ransomware, as Reg readers know, is software that forcibly encrypts files on a target computer or network. The criminal operators behind this strain of malware demand hefty payments, in some cases running to [3]millions , in order to provide a decryption utility. Without a decryptor, the targeted business usually cannot recover its files to continue normal trading.

Recent research from ransomware-focused infosec biz Emsisoft [4]concluded that the average US ransom demand was in the region of $84,000.

Victims of the Blackbaud-enabled ransomware attack included a whole host of universities, charities (including the National Trust), and, according to media reports last week, the UK's [5]Labour Party . ®

Get our [6]Tech Resources



[1] https://www.theregister.com/2020/07/17/blackbaud_paid_ransomware/

[2] https://www.theregister.com/2019/10/03/fbi_softens_stance_on_ransomware/

[3] https://www.theregister.com/2020/06/29/ucsf_1_14m_dollar_ransom_paid_netwalker/

[4] https://blog.emsisoft.com/en/35583/report-the-cost-of-ransomware-in-2020-a-country-by-country-analysis/

[5] https://www.itv.com/news/2020-07-30/labour-party-has-data-compromised-following-blackbaud-hack

[6] https://whitepapers.theregister.com/

No consent for data sharing in the first place

David M

I was hit by this via the University of York, which I attended many years ago. One of my concerns is that the University never sought my consent to share my details with Blackbaud, which is a GDPR violation. The details included at least name, address, date of birth and email - very useful for identity theft. But of course the ransom was paid, and criminals are always trustworthy, so that's OK.

Re: No consent for data sharing in the first place

Mike 137

"... never sought my consent to share my details [...], which is a GDPR violation"

Not necessarily. Data sharing may be performed on several alternative lawful bases, of which consent is only on unless the data falls into the Article 9 sensitive categories. Consent would only apply if that were the lawful basis declared by the data controller as being relied on for the specific purpose.

Of all the lawful bases, consent has received the lion's share of press, and therefore public, attention, resulting in a common but mistaken assumption that it is mandatory in all cases. Indeed if another lawful basis is legitimately relied on, consent can not be invoked, as only one lawful basis can be relied on for each specific purpose.

Re: No consent for data sharing in the first place

Anonymous Coward

So what you're saying is that GDPR is another piece of bureaucratic EU nonsense that's as useful to the ordinary citizen as a chocolate teapot and whose only noticeable effect is to dish up intrusive pop-ups on nearly every website?

Re: No consent for data sharing in the first place

Paul Kinsler

If you want the University to be able to confirm you actually attended there, and what the result was, they are going to need to store some basic data which identifies you and distinguishes you from other David M's who might also have been there. The problem here is that that data wasn't secured properly, not that they stored it.

It would -- I assume -- be more than a little annoying to find that your alma mater said "Nope, got no record of that dude whatsoever" when an employer was doing a few basic CV checks [1], just because the university had over-enthusiastically tried to minimise its store of personal info.

[1] Or, for that matter, refused to replace your gone-missing/eaten-by-dog degree certificate for the same reason :-)

Shouldn't Blackbaud have warn the supervisory authority of their european customers?

Potemkine!

I mean, in the next 72h following the discover of the breach, not two months later?

If not, I bet this is a blatant GDPR violation, and I hope supervisory authorities through the EU will ask Blackbaud to provide some complementary information!

"don't anticipate any material financial impact" and "do have insurance coverage"

Anonymous Coward

Could an increase in insurance costs lead to a financial impact?

Re: "don't anticipate any material financial impact" and "do have insurance coverage"

IGotOut

Or companies being pissed of at the very slow notification and leaving.

Bullet, Dodged!

chivo243

Our org just ended a contract with Blackbaud, I sent the link for the original story to our Data Protection Officer, he's a shark type, he was all over it, I guess he smelled Blackblaud in the water?

Thanks! I'm here all week!

National Trust

Colonel Mad

We have a statement on the volunteer website, and if I understand corporate speak, the NT are far from happy.

Blackbaud probably didn't even make the decision to pay

RM Myers

Most likely, the insurance policy had a clause (subrogation) which basically required that Blackbaud do what the Iinsurance company wanted (pay or not pay). If they didn't follow the insurance company's direction, then the insurance company would not be legalyl required to reimburse Blackbaud under the policy terms.

This type of subrogation clause is very common in the United States - I don't know about other countries. For example, every auto policy will have a subrogation clause which suborns the policyholders rights to the insurance company in case of an accident. Thus you can't agree to pay $100 thousand to the other driver and then force the insurance company to pay it. In fact, if they want to be a**holes, they technically could avoid paying anything since you broke the contract terms by negotiating directly with the other driver.

Capitalism at its best

Pascal Monett

There's a market, so there's money to make, so we shall go get that money. It doesn't matter if the end result is more crime, what matters is that there is a demand.

With insurance on ransomware, there is literally no more possibility of stopping this type of crime. Now, companies are going to flock to their insurance company, get some form of coverage and turn around and not even care anymore about what IT needs to protect their data.

Muppets like this Gianoni will proudly proclaim that they have insurance, and everybody on Wall Street will be happy. And the crminals will be overjoyed, because now they up their demands since hey, what do you care, you're covered.

Brilliant. Just brilliant.

Doctor Syntax

The standard contract clauses ot the Privacy Figleaf are quite inadequate protection for data subjects (assuming, of course,that the UK is still enjoying this fictional protection during the transition period). There needs to be provision for the data subjects to take action for compensation in their own jurisdiction. From what the report says HM Opposition should have some support for this principle.

sitta_europea

I've checked all the Register reports about Blackbaud that I can find, the ICO doesn't seem to be mentioned in any of them.

I asked the ICO today if Blackbaud has reported the issue.

They said yes. They didn't say when the report was made.

If I kiss you, that is an psychological interaction.
On the other hand, if I hit you over the head with a brick,
that is also a psychological interaction.
The difference is that one is friendly and the other is not
so friendly.
The crucial point is if you can tell which is which.
-- Dolph Sharp, "I'm O.K., You're Not So Hot"