Ransomware-hit law firm gets court order asking crooks not to publish the data they stole
- Reference: 1625596386
- News link: https://www.theregister.co.uk/2021/07/06/ransomware_4_new_square_chambers/
- Source link:
4 New Square chambers, which counts IT dispute experts among its ranks, obtained a privacy injunction from the High Court at the end of June against "person or persons unknown" who were "blackmailing" the firm.
Those persons were said to be "responsible for engaging in a cyber-attack on [the barristers] on or about 12 June 2021 and/or who is threatening to release the information thereby obtained."
[1]
Trade mag The Lawyer [2]reported the ransomware attack but the obtaining of an injunction against people outside the jurisdiction of the English courts seems strange.
[3]
[4]
Handed down by Mrs Justice Steyn, [5]the injunction orders the ransomware criminals not to "use, publish or communicate or disclose to any other person" any of the (unspecified) data they stole in June. No data from 4 New Square appears to have been published on the known ransomware gangs' Tor-hosted leak blogs, though the injunction return date is this Friday (9 July).
Ransomware, as Reg readers know, is malicious software that encrypts targeted networks before its operators send a demand for money in exchange for the decryption utility. So-called double-extortion ransomware, currently the dominant model, demands a second ransom in return for not publishing or sharing data stolen during the initial attack.
[6]
Plenty of public domain information points to the criminals operating ransomware scams being based in places such as Russia, North Korea, Iran, and so on – in short, countries that don't tend to enforce English court orders.
[7]Ransomware victim Colonial Pipeline paid $5m to get oil pumping again, restored from backups anyway – report
[8]Hospitals cancel outpatient appointments as Irish health service struck by ransomware
[9]The latest REvil ransomware victim? Sol Oriens. Oh, a US nuclear weapons contractor
[10]Cuffed: Ukraine police collar six Clop ransomware gang suspects in joint raids with South Korean cops
We have asked 4 New Square's CEO about the firm's reasoning for getting the order and will update this article if we hear back from her. It seems odd to get a piece of paper asking foreign criminals not to "publish data stolen from us" when that is how they do their business.
It is very difficult to see what effect, if any, a civil non-disclosure order will have on a ransomware gang potentially based in a hostile foreign country – especially when such criminals attack multiple countries' critical national infrastructure with apparent impunity.
Recent examples include the US Colonial Pipeline hack, where the Russian-speaking Darkside ransomware gang [11]triggered a full-scale US law enforcement and diplomatic response and yet are still walking free; the [12]WizardSpider crew who deployed Conti ransomware into Ireland's Health Service Executive, causing hospitals to grind to a halt while staff fumbled to set up paper-based fallback processes; and [13]US Department of Defence nuclear contractor Sol Oriens , targeted by the REvil ransomware crew.
So far the nearest anyone has got to arresting a ransomware criminal are Ukraine's cyber-cops who with the help of South Korean officials and Interpol, busted and charged half a dozen suspects in June [14]who they alleged were linked to the Clop gang's money-laundering efforts .
[15]
While we would love to report that a civil court in London has achieved what criminal law enforcement agencies from the entire western world couldn't, we won't be holding our breath. ®
Get our [16]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YOTScAL0Wx83s-M3S-D4QgAAAFE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.thelawyer.com/4-new-square-struck-by-ransomware-attack/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YOTScAL0Wx83s-M3S-D4QgAAAFE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YOTScAL0Wx83s-M3S-D4QgAAAFE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.judiciary.uk/judgments/new-square-limited-v-person-or-persons-unknown-privacy-order/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YOTScAL0Wx83s-M3S-D4QgAAAFE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2021/05/13/colonial_pipeline_ransom/
[8] https://www.theregister.com/2021/05/14/ireland_hse_ransomware_hospital_conti_wizardspider/
[9] https://www.theregister.com/2021/06/15/us_nuclear_weapons_contractor_sol_oriens/
[10] https://www.theregister.com/2021/06/16/clop_ransomware_gang_arrests_ukraine/
[11] https://www.theregister.com/2021/05/13/colonial_pipeline_ransom/
[12] https://www.theregister.com/2021/05/14/ireland_hse_ransomware_hospital_conti_wizardspider/
[13] https://www.theregister.com/2021/06/15/us_nuclear_weapons_contractor_sol_oriens/
[14] https://www.theregister.com/2021/06/16/clop_ransomware_gang_arrests_ukraine/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YOTScAL0Wx83s-M3S-D4QgAAAFE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://whitepapers.theregister.com/
Re: D'oh
I say! They would never do such a thing, it just wouldn't be cricket!
Such pessimism
"While we would love to report that a civil court in London has achieved what criminal law enforcement agencies from the entire western world couldn't..."
"Couldn't" is very different from "chose not to". All we have to do if we want this to stop (assuming that's really where the criminals are) is turn down all the Internet connectivity from those places and any other country (looking at you, China) who don't do the same. If they wish to remain connected, they will have no choice but to clean house. If not, they can look forward to becoming the 22nd century's Sentinel Island.
Great option? No, not really. I don't think anyone is too excited about a geographically bifurcated Internet. But nothing else has borne fruit; diplomacy with rogue states is ineffective, law enforcement cooperation equally so, which means that unless someone has an appetite for war that's going to be the only option. I think I'm firmly in the majority preferring cutting off Internet access to rogue states and their sponsors over war. Let's get to it, then.
Re: Such pessimism
Hmmm... how would you define "rogue state", in a global sense?
I suppose...
... it only goes to show how out of touch with reality, the legal profession really is. " I put it to you, Mr Burglar, that you should return the goods you stole from my client, and should reimberse him with the costs of repairing the damage that you inflicted on him, in the theft which you carried out."
Re: I suppose...
(pause) "or else"
That'll do.
Insurance
Anybody know how insurance against this kind of thing works? Maybe there's an insurable risk against breach of the injunction or somesuch?
It could be that they are looking to set up a situation where court sanctions, if the perpetrators were caught, would be more extreme, as in contempt-of-court for example.
As the old adage goes, 'it is easier to gain forgiveness than it is to get permission', which is an imperfect fit I grant you.
Of course that assumes that the crooks are in the same criminal jurisdiction.
There's another possibility here, actually. Sometimes, court orders against foreign entities are enforceable against domestic entities controlled by the noncooperative foreign government. So if for example one could eventually prove that this harm was caused by people in East Twatistan, and East Twatistan's government refuses to act, the court may be able to enforce this judgment against any assets belonging to East Twatistan or corporations registered in East Twatistan provided those assets are located in the UK or some other place where the UK court has jurisdiction.
This is probably a long shot, and it would obviously first require proving where the criminals are located. But it never hurts to obtain a judgment; the courts have very long memories and will enforce long-ago judgments if an opportunity arises. By the same logic, if the criminals *are* within the court's jurisdiction, the lawyers have set themselves up for success later on.
While this may seem ridiculous, it's also pretty easy to see it as a zero-cost, zero-risk long-shot investment. Knowing lawyers, that's how they saw it too.
I agree completely. It's all very funny to go "haha, look et zee loyers unt zer seelee games", but the reality is that people employ lawyers for a reason. They know the ins and outs, the risks and benefits. They don't care if we think it's dumb, clearly this was worth their effort to do and I expect they have a good reason (even if it is not the reason stated).
I suspect if the criminals get wind of the fact that these lawyers have obtained a ridiculous court order against them it will make it MORE likely they would release the data than if they hadn't done so.
I would consider this a foregone conclusion regardless. One must assume that once this kind of information has been compromised, it is public knowledge. Even paying off the crooks doesn't guarantee they won't sell it on to someone else or just publish it anyway. So "pissing them off" isn't a consideration; they're criminals, you must assume they will do the worst.
The point of this would be twofold: to demonstrate to their clients (whose information will leak) that they've done all they reasonably could to prevent that, and to establish grounds for eventual recovery should it prove possible to identify the perpetrators and any assets they may have subject to the court's jurisdiction.
Wasted opportunity
Court could also order people to be happy and respectful of each other.
The naivete ..
I bet this injunction is used to suppress reporting on the case.
Is it really pointless?
It would certainly be effective if the perps are actually UK-based, but even if not, it seems to also ensure that anyone in the UK who diseminates the information once it is released will be guilty of contempt-of-court. Which might be good enough, depending on what the information is.
court order demanding the criminals do not share stolen data.
- Or else what?
- Or else we will be very, very angry with you... And we will write you a letter, telling you how angry we are.
It is very difficult to see what effect, if any, a civil non-disclosure order will have
Let me explain the cunning plan by means of a quote:
"The Funniest Joke in the World" (also "Joke Warfare" and "Killer Joke") is a Monty Python comedy sketch revolving around a joke that is so funny that anyone who reads or hears it promptly dies from laughter.
I doubt if this will end well.
It could easily could follow the Margaret Thatcher Spy Catcher legal mess - where the last Prime minister of Australia (Malcolm Turnbull) was the Lawyer who represented the plaintiff against the UK Official Secrets / D notices concerning an embarrassing publication - and ultimately won!
D'oh
Its good to see that they understand the adversary..
I wonder what they will do once they do publish the content that they stole ?