News: 1704547452

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ransomware payment ban: Wrong idea at the wrong time

(2024/01/06)


Opinion A general ban on ransomware payments, as was floated by some this week, sounds like a good idea. Eliminate extortion as a source of criminal income, and the attacks are undoubtedly going to drop.

But unfortunately, it's not going to work — at least not now, and probably not in the foreseeable future — for a number of reasons. Plus, it would inevitably lead to more attacks on critical infrastructure targets such as hospitals, power grids, water systems, and the like, which isn't exactly great.

This is because a payment ban would inevitably have to include an exception for incidents where not paying the ransom poses a serious risk of death, bodily harm, or terrorist attack. In other words, there's got to be an exception for critical infrastructure.

[1]

We've seen this with the US Securities and Exchange Commission's new cybersecurity incident disclosure rules: The SEC allows [2]delayed reporting if disclosing the attack poses "a substantial risk to national security or public safety."

[3]

[4]

And no one faulted the Colonial Pipeline CEO's decision to [5]pay off the crooks in 2021 to prevent further fuel supply shortages.

A critical infrastructure exclusion makes sense. No one is going to victim blame a hospital, or argue in favor of allowing patients to die instead of paying a ransom. A similar case can be made for gas and electric companies: They can't ignore the need for residential heating during a winter storm. But this also means that attackers will simply pivot and target these sectors where declining to give in to extortionists' demands could be a matter of life and death.

[6]

We are already seeing criminals increasingly focus on hospitals and health-care facilities. In 2023, ransomware gangs breached 46 hospital systems in the US with a total of 141 hospitals between them, and at least 32 of the 46 had patient data including [7]protected health information, stolen.

These intrusions caused weeks-long outages, diverted ambulances and [8]delayed medical treatment for patients. While all of this should be a security wake-up call for any critical infrastructure organization, preventing future ransomware chaos requires a solution that's more disaster preparedness than just prohibiting payments to criminals.

Then there's also the issue of enforcement. Such a ban would need to be universal or else ransomware crews will simply focus on victims in other geographic regions that don't prohibit payments. That kind of multi-government cooperation is highly unlikely at best, and if by some miracle it did happen, the hurdles of coordinated enforcement and funding would immediately wreck this effort.

[9]

Presumably, any type of international law would be enacted by the United Nations. But this doesn't always guarantee a global mandate with teeth. Or, perhaps even worse, it would run the risk of becoming an attempt to rewrite international law by nations that already provide safe harbor to ransomware crews and use the illicit proceeds to fund state-sponsored terrorism and weapons programs.

Case in point: The [10]UN cybercrime treaty . A global approach to stopping cybercrime is needed, and it's a good idea in theory. But instead, it's looking like a attempt by Russia, with support from China and North Korea, to justify state surveillance and eliminate data privacy rules.

Another roadblock is the lack of security maturity across sectors, which Megan Stifel, chief strategy officer for the Institute for Security and Technology and the executive director of the IST's [11]Ransomware Task Force , pointed out in an [12]earlier interview with The Register .

This is especially concerning considering that two notoriously under-funded and understaffed sectors when it comes to infosec, [13]local governments and [14]schools , are increasingly being targeted by these money-grubbing miscreants.

Some of the 2023 ransomware victims in these sectors include the [15]city of Oakland , California, and [16]New York's Suffolk County , both of which [17]declared states of emergency , and [18]Dallas, Texas , which also saw its IT systems crippled by cybercrime gangs.

Meanwhile, the MOVEit breaches affected [19]millions of individuals when a Russia-linked ransomware crew stole data belonging to the Louisiana Office of Motor Vehicles, the Colorado Department of Health Care Policy and Financing, and the Oregon Department of Transportation.

[20]Freight giant Estes refuses to deliver ransom, says personal data opened and stolen

[21]Formal ban on ransomware payments? Asking orgs nicely to not cough up ain't working

[22]Court hearings become ransomware concern after justice system breach

[23]A tale of 2 casino ransomware attacks: One paid out, one did not

According to security shop [24]Emsisoft's count , at least 108 K-12 districts and 72 post-secondary schools fell victim to ransomware crews in 2023, compared to 45 ad 44, respectively, a year earlier. And some 95 government entities experienced ransomware infections last year, compared to 106 in 2022. However, 55 of the 106 were Arkansas agencies that all shared an IT services provider.

State and local government agencies and schools collect a ton of sensitive information that can be financially lucrative to criminals, and these orgs don't have the resources to defend themselves against ransomware. Simply making it illegal for them to pay ransom demands seems especially cruel unless they receive the needed professional and financial support to shore up networks first.

Luckily, on this front, there is nearly [25]$375 million in grant money available for state, local, and territorial (SLT) governments across the US to address cybersecurity risks and threats.

Additionally, a dedicated US Federal Communications Commission program aims to provide up to [26]$200 million for K-12 schools and libraries in rural and low-income communities and would gather information on "cybersecurity and advanced firewall services" to protect these orgs against cyberattacks.

A complete ban won't work. It would be nice if it could provide a magic-bullet response to ransomware. Then again, it would also be nice if countries like Russia, Iran and North Korea decided to prosecute cybercriminals operating inside their borders. None of these are realistic.

Having said that, a ban on ransomware payments is becoming more palatable than it was even a couple years ago, and this year's international Counter Ransomware Initiative summit, held at the White House, is one such indication.

At the event, the US persuaded all 50 member countries to sign on to a [27]joint policy statement under which they agreed [28]not to pay ransom demands . They also pledged to better track cryptocurrency payments to cybercriminals and increase information-sharing capabilities.

While the no payment pledge only applies to the national governments' themselves, not private companies, it couldn't get the needed support even a year prior.

Our advice? Secure your networks now. Don't be a long-hanging fruit. Implement all those basic hygiene measures that public and private infosec specialists have been preaching for years: use strong passwords and data encryption, implement zero-trust access, network segmentation and multi-factor authentication, install software updates and backup regularly.

"The best defense is to take steps to proactively avoid becoming a victim," Sam Rubin, VP of Unit 42 Consulting at Palo Alto Networks, told The Register .

In lieu of a complete ban on ransom payments, be prepared. ®

Get our [29]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZZmHNk-sXZ8HhC9tuKDQJAAAAY8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.justice.gov/media/1328226/dl?inline

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZmHNk-sXZ8HhC9tuKDQJAAAAY8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZmHNk-sXZ8HhC9tuKDQJAAAAY8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2021/06/09/old_vpn_colonial_pipeline/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZZmHNk-sXZ8HhC9tuKDQJAAAAY8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/12/11/norton_healthcare_ransomware/

[8] https://www.theregister.com/2023/10/25/canadian_hospitals_spamoflague/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZZmHNk-sXZ8HhC9tuKDQJAAAAY8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2023/08/30/microsoft_un_cybercrime_treaty/

[11] https://www.theregister.com/2021/04/29/ransomware_task_force_offers_48/

[12] https://www.theregister.com/2024/01/03/ban_ransomware_payments/

[13] https://www.theregister.com/2023/10/16/kansas_courts_security_incident/

[14] https://www.theregister.com/2022/09/06/lausd_ransomware_fbi_cisa_los_angeles/

[15] https://www.theregister.com/2023/02/13/lockbits_royal_mail_ransom_deadline/

[16] https://www.theregister.com/2023/05/29/security_in_brief/

[17] https://www.theregister.com/2023/02/20/in_brief_security/

[18] https://www.theregister.com/2023/05/05/dallas_royal_ransomeare/

[19] https://www.emsisoft.com/en/blog/44123/unpacking-the-moveit-breach-statistics-and-analysis/

[20] https://www.theregister.com/2024/01/03/estes_ransomware/

[21] https://www.theregister.com/2024/01/03/ban_ransomware_payments/

[22] https://www.theregister.com/2024/01/02/victoria_court_system_breach/

[23] https://www.theregister.com/2023/12/28/casino_ransomware_attacks/

[24] https://www.emsisoft.com/en/blog/44987/the-state-of-ransomware-in-the-u-s-report-and-statistics-2023/

[25] https://www.cisa.gov/state-and-local-cybersecurity-grant-program

[26] https://www.federalregister.gov/documents/2023/12/29/2023-27811/schools-and-libraries-cybersecurity-pilot-program

[27] https://www.whitehouse.gov/briefing-room/statements-releases/2023/11/01/international-counter-ransomware-initiative-2023-joint-statement/

[28] https://www.theregister.com/2023/10/31/us_ransomware_payment_ban/

[29] https://whitepapers.theregister.com/



Rename

elsergiovolador

They'll just change it from "ransom" to "Ransomware removal fee".

I mean they no longer will have to ask for ransom. Just ensure the name of the ransomware is distinct and when someone Bings for the removal services, it pops up on the first page.

Re: Rename

VicMortimer

FBI agent: Oh, you paid for a "ransomware removal" to a company you'd never heard of? Paid them in bitcoin? Hang on a minute, let me get my cuffs out.

It's why payment of ransom has to be a strict liability crime, to remove any plausible deniability.

Re: Rename

elsergiovolador

Doesn't really have to be like this.

These can be legal businesses, just like anti-virus companies, just happening to have expertise in ransomware removal. They don't need to have any connection to the groups distributing and creating malware, just like anti-virus companies don't have any connection to the people making viruses.

wink wink

Wrong

VicMortimer

This is completely the wrong take.

There needs to be not just a ban, but a CRIMINAL ban on paying ransomware attackers. It needs to come with actual jail time for CEOs whose companies pay, and it needs to be strict liability, whether they know they paid or not, so that they can't claim plausible deniability.

The only way ransomware stops is when paying ransom is a crime.

Hospitals

VicMortimer

Oh, and there should be NO EXCEPTIONS, especially for hospitals.

For a hospital that's been hit, there should be a requirement that they declare an emergency, and KEEP TREATING PATIENTS. The actual medical devices should not have been on the internet-connected network in the first place, so they should be fine. If not, somebody screwed up badly, but salvage what still works, and KEEP TREATING PATIENTS. SCREW YOUR PRECIOUS BILLING RECORDS, KEEP TREATING PATIENTS. If the pharmacy bot stops working, crowbar it open and have the pharmacist do it manually. The doctors can keep notes on paper for the duration of the emergency.

And if anybody pays the ransom, they go to jail.

Re: Wrong

mmccul

Already exists for many ransomware gangs. It's under the laws banning providing any funding for or doing business with embargoed organizations, countries, etc. Not all of them, of course, but enough of them are operating from an embargoed country, or have been directly linked to supporting terrorism that existing laws make it very risky to pay out blindly.

Re: Wrong

VicMortimer

While this is true, it's also too hard to determine quickly, allows for plausible deniability in some cases, and is too often ignored.

It's stopped some ransom payments, but not nearly enough. The payment of ransom itself needs to be a separate strict liability crime.

Re: Wrong

cyberdemon

+1

JLH, Why do you think there should be an exception for critical infrastructure? What happened to "don't negotiate with terrorists" etc?

If someone is holding critical infrastructure to ransom, and you pay them, what's to stop them from demanding more money, or taking the money and borking the infrastructure anyway? If they even had the means to do so in the first place? Or they could just leak the access to someone else, or plant a logic time bomb, etc etc.

It's completely daft to pay a ransom. One could argue that the ONLY exception should be where it is paid in such a way where it can a) be used to identify the perps and bring them to justice AND b) can be got back afterwards. E.g. someone has kidnapped your daughter. The correct response is to get the police involved early, and with their permission leave the money in a place where the person coming to collect it can be followed by the police, etc etc. Otherwise they can simply say "Thanks for the dosh, now double it."

However, when the perps are in another country, how can you be sure of bringing them to justice after paying a ransom? You can't. So there is no reason to pay it.

In any case, this sort of exception if it is ever valid, needs to be made by the police, not by the board of directors.

Re: Wrong

Andy Non

I fully agree. Maybe there is also a case that critical infrastructure companies, hospitals etc should undergo mandatory security auditing on an ongoing basis too, with penalties of some form for those companies or organisations that are substandard, maybe financial penalties levied at the exec's bonuses or shareholder level to stimulate active effort. Such an approach wouldn't necessarily stop all ransomware attempts as there will always be human error somewhere in the organisation, but it should help somewhat to harden their security and make it more difficult for the miscreants.

Re: Wrong

Phil O'Sophical

And if the only way to save critical infrastructure is to pay the ransom, the board should authorise that in the full knowledge that fines and jail time are in their future. The alternative being to allow the infrastructure to fail, and be fined and jailed for that instead. Both options might focus their successors' minds on better security.

"Such a ban would need to be universal"

Andy Non

Disagree with that. There would not need to be any universal ban across the world or involving the UN. If country X bans payments and the miscreants target other countries instead, you can be sure those other countries won't be far behind in individually also enacting bans. The targets across the world will diminish over time with only those remaining who are too recalcitrant for whatever reason to enact bans - but that's their problem to resolve.

Re: "Such a ban would need to be universal"

VicMortimer

Absolutely.

Ransomware will NEVER be stopped by going after the perpetrators. The only way to stop it is to destroy the possibility of profits, and if that's worldwide, wonderful. But if it's country by country, so be it.

The place to start is national laws criminalizing payment of ransom. All the better if it goes international, but pretending that you're ever going to get the whole world to agree on anything is an exercise in stupidity.

No, the time to start making paying ransomware a crime is now, and the place is wherever you are.

The best defense is to avoid becoming a victim ö

t245t

“ Secure your networks now .. Implement all those basic hygiene measures .. use strong passwords and data encryption, implement zero-trust access, network segmentation and multi-factor authentication, install software updates and backup regularly. ”

Your average business doesn't have the time, money or expertise to implement such a thing. The computers are used as they came, fresh out of the box.

Re: The best defense is to avoid becoming a victim ö

depicus

Then if they go out of business tough luck, serves them right, and the companies that do have DR plans can and will survive. None of this is rocket science to defence and mitigate against and for a lot of companies that's my data they are playing fast and loose with so if they have no IT plans then be it on their own head.

Re: The best defense is to avoid becoming a victim ö

elsergiovolador

Your average business doesn't have the time, money or expertise to implement such a thing.

Especially when they have starving shareholders to feed. It's really a tough choice - buy another yacht or hire a competent security team.

Why use Windows, when you can have air conditioning?
Why use Windows, when you can leave through the door?
-- Konrad Blum