News: 1704270608

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Formal ban on ransomware payments? Asking orgs nicely to not cough up ain't working

(2024/01/03)


Emsisoft has called for a complete ban on ransom payments following another record-breaking year of digital extortion.

Ransomware gangs breached the IT networks of at least 2,207 US hospitals, schools, and government organizations in addition to "thousands" of private-sector businesses last year, the security shop said on Tuesday. On average, these attacks cost targets about $1.5 million to rectify.

"In 2023, the US was once again battered by a barrage of financially motivated ransomware attacks that denied Americans access to critical services, compromised their personal information, and probably killed some of them," the New Zealand-based infosec firm [1]noted .

[2]

This included 46 American hospital systems, 108 K-12 school districts, 72 colleges and universities, and 95 government bodies. For comparison: 2022 saw 25 attacks against hospitals, 45 against K-12 schools, 44 targeting post-secondary education, and 106 against government organizations.

[3]

[4]

The only reason that US government saw a year-over-year decline is because 2022 numbers included 55 local governments in Arkansas affected by a single intrusion into the agencies' [5]shared IT services provider .

If it weren't for this one digital break-in, the number of 2023 incidents would have seen more than a 50 percent increase compared to 2022 ransomware infections.

[6]

There's also the high-profile private-sector entities that fell victim to extortionists last year – including [7]Boeing , [8]MGM Resorts, Caesars Entertainment , and [9]Dish Network . Now that it's mandatory for listed companies to [10]disclose ransomware attacks , per the US Securities and Exchange Commission's rules that took effect at the end of last year, we'd expect the number of reported infections to increase in 2024.

We should also note that Emsisoft does not include the MOVEit attacks, during which ransomware gang Clop exploited a zero-day to steal a ton of data from more than 2,600 public- and private-sector victims via the popular file-transfer software, in its 2023 numbers.

This is because no data was encrypted and not every organization received a ransomware demand. Still, this breach cost upwards of [11]$15 billion in clean-up fees.

[12]

The only solution to this problem, according to Emsisoft, is to ban ransom payments completely.

"Ransomware is estimated to have killed about one American per month between 2016 and 2021, and it likely continues to do so," the report observes, citing the University of Minnesota School of Public Health's [13]statistics .

"The longer the ransomware problem remains unfixed, the more people will be killed by it," the authors add. "And, of course, the economic harm and myriad of societal harms that ransomware causes will also continue for as long as the problem remains unfixed."

According to Emsisoft threat analyst Brett Callow, opposition to a total ban on ransom payments is lessening. "I think more people are coming to accept that a ban, while problematic, may ultimately be the only solution to the ransomware problem," he told The Register .

'Not a silver bullet'

In the fall, all 50 member countries of the International Counter Ransomware Initiative signed on to a [14]policy statement under which they agreed [15]not to pay ransom demands to cyber criminals.

However, this agreement only governs "institutions under … national government authority." So most of the victim organizations in the report, as well as all private-sector companies, are still free to pay.

"The intention is well grounded, I think we can eventually get to a ban, but at this point in time it is not a silver bullet and will result in more harm than good," argued Megan Stifel, chief strategy officer for the Institute for Security and Technology and the executive director of the IST's Ransomware Task Force.

So, for example, the Biden administration deciding to make ransom payments illegal as of February 1 would be "problematic, given the lack of overall resilience and maturity across the economy, particularly when you think about all those soft targets the report identifies," Stifel told The Register , echoing the [16]conclusion [PDF] reached by the Ransomware Task Force.

Eventually, a ban will be "an important part of the solution to reduce and hopefully eliminate ransomware, but it has to be coupled with number of other tools that the government has at its disposal," she added.

[17]US officials close to persuading allies to not pay off ransomware crooks

[18]A tale of 2 casino ransomware attacks: One paid out, one did not

[19]Cyber sleuths reveal how they infiltrate the biggest ransomware gangs

[20]Court hearings become ransomware concern after justice system breach

While the US government advises organizations not to pay ransom demands – "paying ransom will not ensure your data is decrypted, that your systems or data will no longer be compromised, or that your data will not be leaked," according to the [21]official guidance – it can and should do more to support resilience, Stifel argued.

This includes enacting policy changes that discourage vendors from releasing buggy software and [22]providing grants for local governments and [23]schools to boost their security.

Most insurance providers are already requiring policy holders to meet some basic IT security standards to qualify for coverage, and the US government could enact similar measures, according to Stifel and the [24]task force .

"We can require organizations to demonstrate some degree of due diligence before they make a payment," she noted.

"Did they actually see whether their backups are viable? Did they see if there was a decryption key available? Plus, there needs to be a full-throated, robust awareness campaign around ransomware prevention, ransomware response, societal harms that come from ransomware. And we haven't really tried that."

Mandiant's Jeremy Kennelly, a senior analyst in the Google-owned threat intel firm's Financial Crime Analysis division, believes banning payments isn't as simple as it sounds.

While a "global and universally enforced" ransomware payment ban could lead to a decline in these types of extortion attacks, this type of solution would be nearly impossible to enforce," he argued.

"Beyond issues related to the viability of enacting and enforcing uniform international standards around ransom payments, another challenge is the simple fact that ransomware is only one tool being used to collect extortion payments. We continue to see diversification across this ecosystem, with criminals sometimes only stealing data before demanding payment," Kennelly told The Register .

"Extortion cases without ransomware deployment may not cause the same type of immediate disruption," he added. "However, in this new world, data encryption may simply become the consequence for non-payment rather than the issue an organization is paying to help remediate." ®

Get our [25]Tech Resources



[1] https://www.emsisoft.com/en/blog/44987/the-state-of-ransomware-in-the-u-s-report-and-statistics-2023/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZZU@V@kNA7D89yBABjsSfAAAAMM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZU@V@kNA7D89yBABjsSfAAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZU@V@kNA7D89yBABjsSfAAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.ktbs.com/news/texarkana/miller-county-offices-impacted-by-cyber-attack/article_5e175af4-6794-11ed-96b8-53186a21f676.html

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZU@V@kNA7D89yBABjsSfAAAAMM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/11/10/lockbit_leaks_boeing_files/

[8] https://www.theregister.com/2023/12/28/casino_ransomware_attacks/

[9] https://www.theregister.com/2023/05/23/dish_networks/

[10] https://www.theregister.com/2023/07/26/sec_reporting_security/

[11] https://www.emsisoft.com/en/blog/44123/unpacking-the-moveit-breach-statistics-and-analysis/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZU@V@kNA7D89yBABjsSfAAAAMM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.statnews.com/2023/11/17/hospital-ransomware-attack-patient-deaths-study/

[14] https://www.whitehouse.gov/briefing-room/statements-releases/2023/11/01/international-counter-ransomware-initiative-2023-joint-statement/

[15] https://www.theregister.com/2023/10/31/us_ransomware_payment_ban/

[16] https://securityandtechnology.org/wp-content/uploads/2021/09/IST-Ransomware-Task-Force-Report.pdf

[17] https://www.theregister.com/2023/10/31/us_ransomware_payment_ban/

[18] https://www.theregister.com/2023/12/28/casino_ransomware_attacks/

[19] https://www.theregister.com/2023/12/22/how_to_infiltrate_ransomware_gangs/

[20] https://www.theregister.com/2024/01/02/victoria_court_system_breach/

[21] https://www.cisa.gov/resources-tools/resources/stopransomware-guide

[22] https://www.fema.gov/grants/preparedness/state-local-cybersecurity-grant-program#totals

[23] https://www.federalregister.gov/documents/2023/12/29/2023-27811/schools-and-libraries-cybersecurity-pilot-program

[24] https://www.theregister.com/2021/04/29/ransomware_task_force_offers_48/

[25] https://whitepapers.theregister.com/



Not "nearly impossible to enforce"

Lurko

Only impossible to enforce 100% of the time. It'd be remarkably difficult for any sizeable attack to be disguised (so everybody knows it's happened), and then to illegally pay a ransom requires execs and finance bods to put their career and/or liberty on the line. After a few imprisonments the message would very quickly get through, added to which the costs and intrusion of the authorities investigation to see if a ransom was paid will be significant.

Obviously there's countries that won't sign up to these rules so leave them to become the ransomware capitals of the world, but for developed nations it's pretty straightforward, and can be done unilaterally at national or supra-national level (eg as anti-bribery laws often are).

I suppose the problem is that we currently have the worst collection of inept, out-of-their-depth charlatans leading almost all developed nations.

Re: Not "nearly impossible to enforce"

Gene Cash

If they're a public company in the US, they'd be required by the SEC to disclose both that they got cracked and that they paid ransom.

And the SEC is one of the few agencies with teeth, other than the IRS.

Absolutely should be banned

cyberdemon

Paying a ransom ought to be a criminal offence already.

Otherwise boards will think "Pay the odd ransom, or actually pull our fingers out of our arses and implement proper security?" Ah, the latter sounds like hard work. Who cares if some of our customer data gets leaked, we'll just pay the crooks to do their next job

Spazturtle

Why do we need to ban something that is already illegal? Just enforce the existing laws against funding terrorism and criminal enterprises.

Yorick Hunt

So you're saying ban political contributions?

Ban

elsergiovolador

Why don't they ban poverty or cancer?

"$1.5 million to rectify"

Pascal Monett

Sure. All private businesses have that kind of cash on hand and in reserve just for that. Oh, you're counting lost business as well ? And adding stock devaluation ?

Of course. Anything and everything to sweeten the pot so you can go before the camera with thundering figures and impress everyone.

Sure, there are intrusions that cost a million or two in equipemt and man-hours to rectify, but I hardly think that that is an average figure.

Then again, if that's what it takes for businesses to sit up, pay attention and start actually protecting their data and procedures, well, carry on then.

In Ohio, if you ignore an orator on Decoration day to such an extent as
to publicly play croquet or pitch horseshoes within one mile of the
speaker's stand, you can be fined $25.00.