Most organizations hit by ransomware would pay up if hit again
- Reference: 1652451070
- News link: https://www.theregister.co.uk/2022/05/13/organizations_pay_ransomware/
- Source link:
The findings come from a report titled "How business executives perceive ransomware threat" by security company Kaspersky, which states that ransomware has become an ever-present threat, with 64 percent of companies surveyed already having suffered an attack, but more worryingly, that executives seem to believe that paying the ransom is a reliable way of addressing the issue.
The report, available [1]here , is based on research involving 900 respondents across North America, South America, Africa, Russia, Europe, and Asia-Pacific. The respondents were in senior non-IT management roles at companies between 50 and 1,000 employees.
[2]
Kaspersky claims that in 88 percent of organizations that have had to deal with a ransomware incident, business leaders said they would choose to pay the money if faced with another attack. In contrast, among those that have not so far suffered a ransomware attack, only 67 percent would be willing to pay, and they would be less inclined to do so immediately.
[3]
[4]
The report also found that those companies that have been the victim of an attack are also more likely to pay up as early as possible in order to regain access to data, or will pay after just a brief period of time spent attempting to recover their encrypted data.
This willingness for companies to stump up the cash could be attributed to managers having little awareness of how to respond to such threats, according to Kaspersky. Management may also be unprepared for how long it may take to restore data, with some businesses losing more revenue while their data is being recovered than by just paying the ransom.
[5]
However, security experts and government agencies strongly recommend that organizations do not pay up for ransomware attacks as this simply validates this kind of activity as a viable business model for criminals. But this does not help much if your organization is affected, as Kaspersky acknowledges.
[6]Ransomware the final nail in coffin for small university
[7]Fresh ransomware samples indicate REvil is back
[8]Malware goes regional as attackers change tactics
[9]It costs just $7 to rent DCRat to backdoor your network
"Because it's about the business continuity, executives are forced to make tough decisions about paying the ransom. Giving money to criminals is never recommended, though, as this doesn't guarantee that the encrypted data will be returned and it encourages these cybercriminals to do it again," said Kaspersky VP for Corporate Product Marketing Sergey Martsynkyan.
Paying up might also not be enough to save an organization. [10]One university in the US has recently been forced to close down following a ransomware attack, despite paying the ransom and having access to its systems restored.
Kaspersky offers some recommendations to help protect against malware. These include some obvious steps such as keeping software updated to minimize the risk from vulnerabilities, setting up offline backups that the ransomware cannot touch, and deploying security tools for advanced threat discovery and detection.
Cyber insurance model is broken, consider banning ransomware payments, says think tank [11]READ MORE
The security outfit also highlights the [12]No More Ransom website , an initiative by the National High Tech Crime Unit of the Netherlands police, Europol's European Cybercrime Centre, Kaspersky, and McAfee. This offers advice for those affected by ransomware, plus decryption tools that may be able to recover data.
Meanwhile, Kaspersky itself has been the target of suspicions over the company's ownership and possible ties to the Russian government, with the [13]German federal cybersecurity agency recently warning citizens not to install Kaspersky security tools . For its part, Kaspersky maintains that these suspicions are politically motivated and states that it is a private company with no ties to the Russian government. ®
Get our [14]Tech Resources
[1] https://www.kaspersky.com/blog/anti-ransomware-day-report/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yn6AowvXJUkAo5NsHjJsEQAAAIw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yn6AowvXJUkAo5NsHjJsEQAAAIw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yn6AowvXJUkAo5NsHjJsEQAAAIw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yn6AowvXJUkAo5NsHjJsEQAAAIw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2022/05/12/ransomware_dangerous_enough_to_close/
[7] https://www.theregister.com/2022/05/11/revil-returns-secureworks-samples/
[8] https://www.theregister.com/2022/05/10/malware_attacks_regional/
[9] https://www.theregister.com/2022/05/09/budgetfriendly_dcrat_malware/
[10] https://www.theregister.com/2022/05/12/ransomware_dangerous_enough_to_close/
[11] https://www.theregister.com/2021/07/01/rusi_cyber_insurance_ransomware_report/
[12] https://www.nomoreransom.org/
[13] https://www.theregister.com/2017/12/03/uk_government_bans_russian_anti_virus_software/
[14] https://whitepapers.theregister.com/
Fat Tony
yeah, that's nice data you have there, would be shame if anything happened to it? How long before these guys start asking for protection money?!!
Tax man always wins.
Interested in how a company would pay in the UK, you're buying a service, I doubt they are VAT registered so are you not facilitating tax evasion?
Re: Tax man always wins.
The scammers are missing a trick there. If they VAT registered they could hit organisations for an extra 20%. As to whether the tax man ever got the 20% is a different matter.
Re: Tax man always wins.
If you are a UK VAT business you don't have to buy goods and services from other VAT registered entities. If an individual or business has a turnover of less than £85K in a 12 month period they don't have to register for VAT.
And its not your responsibility as a business to ensure they are complying with UK tax laws if you are purchasing from them.
Surely there's an economic tipping point here?
Given that the organizations behind these attacks are typically in places where the phrase "rule of law" actually NEEDS those quote marks, one wonders - in an entirely theoretical way - at what point it becomes more expensive to pay the ransom than, say, to hire a squad of thugs to "persuade" the crew to cease operations. It's not as though it's totally impossible to ID these folks, just difficult and costly (see "rule of law" above, ISP employees can be bought, too).
Incredible
-> Almost nine in 10 organizations that have suffered a ransomware attack would choose to pay the ransom if hit again
I can just about understand it, paying up *once*. I don't like the idea of it, or agree with it, but I can just understand it if:
- they really can't get their data back from backups (already a failure)
- and they can't recreate that data within a reasonable time (reasonable depends on the nature of the data)
- and if that data is critical (so treat it as such)
- and they really have no other reasonable choice if you want to stay in business (recognise the importance of the data, and ensure it is 100% backed up and recoverable)
But paying up multiple times? No way. That is definitely a failure on the part of the victim. What steps did they take (or rather what didn't they take) after the first time? It's like being burgled while they used 'This is the Lockpicking Lawyer and what I have for you today is an egregious example of a bad lock' locks, then didn't replace them when then Bob the Burglar opened them using a fork, a spoon, or a spare bottle top. At some point you have to say 'these locks are no good'.
who pays?
> Almost nine in 10 organizations that have suffered a ransomware attack would choose to pay the ransom if hit again
But would the cost of the ransom be deducted from the IT (or security dept.) salary budget?
Maybe from the CIO's bonus, too?
Danegeld
[paying the ransom] ... encourages these cybercriminals to do it again.
"Encourages"? I thought it guaranteed another hit as soon as the criminals have worked through their list of previous paying customers.