News: 1599899588

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Don't pay the ransom, mate. Don't even fix a price, say Australia's cyber security bods

(2020/09/12)


Most online attacks could be easily avoided by following basic cyber security advice, Australia’s national cyber security bureau has said – even as it warned that the impact and severity of things like ransomware attacks are getting worse and worse.

“Cybercriminals follow the money,” said the Australian Cyber Security Centre (ACSC) in its [1]annual report for 2019-20, published earlier this week.

“Over the past 12 months the ACSC has observed real-world impacts of ransomware incidents, which have typically originated from a user executing a file received as part of a spearphishing campaign,” said the agency, adding that after the initial breach attackers typically try to exploit remote desktop-type apps to hunt for anything worth stealing – or deleting.

Australia's Lion brewery hit by second cyber attack as nation staggers under suspected Chinese digital assault [2]READ MORE

ACSC was busiest in April 2020, when it had 318 “cyber security incidents” reported to it.

Out of 2,266 incidents that the agency responded to over the 12-month period, 803 were targeted against Australia’s federal or state level governments – though the ACSC put this down to the public sector’s willingness to report incidents to it, as distinct from the private sector.

Most attacks can easily be mitigated, said ACSC, through “measures such as not responding to unsolicited emails and text messages, implementing multi-factor authentication and never providing another party with remote access to your computer.”

Those attacks include June’s [3]cyber-assaults against the Lion brewery , which were remarkably closely timed as China stepped up diplomatic pressure on Australia over international cooperation.

“Many of these [attacks] could have been avoided or substantially mitigated by good cyber security practices,” sighed the ACSC in the report ( [4]PDF, 18 pages ), which covered the months July 2019-June 2020.

The infoseccers strongly advised against paying the criminals:

Paying a ransom does not guarantee decryption of data. Open source reporting indicates several instances where an entity paid the ransom but the keys to decrypt the data were not provided. The ACSC has also seen cases where the ransom was paid, the decryption keys were provided, but the adversary came back a few months later and deployed ransomware again. The likelihood that an Australian organisations will be retargeted increases with every successful ransom payment. ...

It is generally much easier and safer to restore data from a backup than attempting to decrypt ransomware affected data.

While it won’t surprise regular Register readers to hear that ransomware is “one of the most significant threats” to online businesses in Aus (and beyond), the ACSC is already looking ahead at towards how 5G and increased digital connectivity across their nation will expose more and more people and businesses to the risks of being online.

5G networks and Internet of Things devices “require new thinking about how best to adopt them securely,” opined ACSC. Britain has [5]published design standards for IoT devices , while on 5G the US has addressed potential vendor security problems by [6]shutting out those they deem to be problematic vendors . ®

Get our [7]Tech Resources



[1] https://www.cyber.gov.au/sites/default/files/2020-09/ACSC-Annual-Cyber-Threat-Report-2019-20.pdf

[2] https://www.theregister.com/2020/06/19/lion_brewery_second_cyber_attack_australia/

[3] https://www.theregister.com/2020/06/19/lion_brewery_second_cyber_attack_australia/

[4] https://www.cyber.gov.au/sites/default/files/2020-09/ACSC-Annual-Cyber-Threat-Report-2019-20.pdf

[5] https://www.theregister.com/2019/01/28/ukgov_secure_by_design_70m_arm_cambridge/

[6] https://www.theregister.com/2020/09/04/fcc_huawei_zte_replacement/

[7] https://whitepapers.theregister.com/

Anonymous Coward

Sacrifice your business for the "greater good" says the Australian Cyber Security Centre.

Great (after the horse has bolted) advice, until your future is on the line.

Followed by FUD: "...but the keys to decrypt the data were not provided". Really. What possible logic are the hackers following if they don't claim the ransom? And even if it does happen, the ratio between that and keys being provided would be useful (eg 1%) so businesses could make an actual informed decision, based on facts rather than the ACSC (who will be telling you next that back doors are for your safety next).

Bottom line, get real security advice from non-government affiliated organisations. Likewise for business advice. Especially in Australia.

Anonymous Coward

Saying "While there have been a couple of anecdotal exceptions, 99% of those who pay the ransom received the keys and decrypted their data" doesn't fit the narrative he's trying to push, so he works with what he's got...

Don't pay the ransom.

Peter Clarke 1

Until he gets your data from the other side. Aahhh- Ahhhh Oohhh Ahhh Ahhh.

I spotted what you did with the headline :)

Efer Brick

Couple crates of fossies and a few dozen snags

Men of peace usually are [brave].
-- Spock, "The Savage Curtain", stardate 5906.5