Ransomware corrupts data, so backups can be faster and cheaper than paying up
- Reference: 1684132325
- News link: https://www.theregister.co.uk/2023/05/15/ransomware_corrupts_data/
- Source link:
That's the opinion of Richard Addiscott, a senior director analyst at Gartner.
"They encrypt at excessive speed," he told the firm's IT Infrastructure, Operations & Cloud Strategies Conference 2023 in Sydney on Monday. "They encrypt faster than you can run a directory listing."
[1]
Ransomware operators therefore encrypt badly and lose some of the data they then try to sell you back.
[2]
[3]
Restoring from corrupt data dumps delivered by crooks is not easy, Addiscott advised – and that's if ransomware operators deliver all the data they promise. Plenty don't – instead they use a ransom payment to open a new round of negotiations about the price of further releases.
That sort of wretched villainy means just four percent of ransomware victims recover all their data, he said. Only 61 percent recover data at all. And victims typically experience 25 days of disruption to their businesses.
[4]
Addiscott suggested that period can be reduced if organizations create ransomware recovery playbooks and practice their use.
"Do you have scripts ready for a cloud rebuild?" he asked. "Don’t build the plane while you are trying to fly it."
To pay or not to pay?
A blanket policy to pay, or not pay, ransoms is not helpful, Addiscott opined. Instead it should be considered a business decision that takes into account risks including payments to offshore players could violate international sanctions and lead to fines.
Paying ransoms is also no guarantee data will be restored, he added.
Ransomware gangs also tend to re-attack those who pay once, making payments a tactic of last resort in Gartner's opinion.
In any case, the decision might not be yours: cyber-risk insurers may decide a ransom is cheaper than funding a restore, and require payment. Addiscott said he's even aware of one ransomware operator that sent a victim the relevant section of their insurance policy to point out any payments would be covered.
Securing the funds to prepare for a rapid post-ransomware recovery means couching the risk in the language of the business, not IT.
Revenue protection, risk minimization, and cost control, are the topics likely to loosen the purse strings, according to Addiscott. Although he also shook his head as he recalled moments in which business leaders authorized large and rapid ransom payments that dwarfed the denied investments that could have made them unnecessary.
He counselled proper preparation, because ransomware scum have figured out one way to accelerate stalled negotiations over a payment: whacking their victims with a DDoS attack so they're fighting two fires at once, and are therefore willing to pay to make at least one problem go away.
[5]A right Royal pain in the Dallas: City IT systems crippled by ransomware
[6]Let's take a closer look at these claims of anti-ransomware SSDs
[7]Medusa ransomware crew brags about spreading Bing, Cortana source code
[8]LockBit crew cooks up half-baked Mac ransomware
Ransomware operators also like to double-dip by seeking payment from organizations whose data they stole, then mining it to find other targets. Addiscott mentioned an attack on a healthcare provider whose customers were hit with a demand for payments or else their medical records would be released.
Customers named in a stolen data heist may also be targeted with a suggestion they let suppliers know they want payments made – to lessen the risk of their data being exposed.
[9]
Addiscott suggested immutable backups, and an isolated recovery environment, are an excellent combination of defences.
But he also pointed out that the folks behind ransomware are smart, ruthless, creative, and persistent, so will find new and even nastier ways to attack.
The analyst did have one good piece of news: a 21 percent drop in ransomware incidents in 2022 compared to 2021. He theorized that drop was caused by sanctions making it harder for ransomware gangs based in Russia to go about their business. ®
Get our [10]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZGICwtIUv-bpZUPTeR9WAwAAAE0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGICwtIUv-bpZUPTeR9WAwAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGICwtIUv-bpZUPTeR9WAwAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZGICwtIUv-bpZUPTeR9WAwAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/05/05/dallas_royal_ransomeare/
[6] https://www.theregister.com/2023/04/24/ssd_ransomware/
[7] https://www.theregister.com/2023/04/19/medusa_microsoft_data_dump/
[8] https://www.theregister.com/2023/04/17/lockbit_ransomware_mac_devices/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZGICwtIUv-bpZUPTeR9WAwAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://whitepapers.theregister.com/
Re: Too many random companies
Fortunately, security, user training and tools to protect against ransomware are also just tick boxes on a compliance list, so after the rapid and low cost implementation process it's off to the pub for G&Ts to celebrate!
What could possibly go wrong?
Although he also shook his head as he recalled moments in which business leaders authorized large and rapid ransom payments that dwarfed the denied investments that could have made them unnecessary.
One would hope the shareholders would be told about the size of the mitigation that was refused, and the cost now being authorised, so said officials can be dismissed. But sadly I doubt it.
Of course following on from reading about yet another MS Outlook vulnerability...
In order to have a complete backup system you already regularly perform a disaster-recovery drill, so in the event of any problem, even ransomware, returning to normal is no more than performing the exact same tasks you already regularly perform but on someone else's schedule (DRaaS?) --- they are effectively free.
It seemed quite sensible until "He theorized that drop was caused by sanctions making it harder for ransomware gangs based in Russia to go about their business"
Now forgive me if I'm wrong but these clowns get paid in bitcoin. Exactly what sanctions are stopping a decentralised currency from being traded? What is actually stopping them from using countries without sanctions against Russia to send money into Russia? Also, the internet is decentralised and you can pretty much route through or from anywhere in the world.
I get that blaming Russia, North Korea, China and Iran is the default for these things but lets keep perspective. There are bad actors in every single country on the planet.
"Exactly what sanctions are stopping a decentralised currency from being traded?"
The sanctions are restricting them exchanging Bitcoins for USD Dollars so they can go out and spend.
Too many random companies
"What is this restore you speak of? Our backups are for checkmark on an audit and compliance list, we don't plan on ever having to use them!"