Ransomware payment rates drop to new low – only 29% of victims are forking over cash
- Reference: 1706728511
- News link: https://www.theregister.co.uk/2024/01/31/ransomware_payment_rates_drop/
- Source link:
The [1]data from ransomware response and negotiation company Coveware continues a downward trend since it began monitoring in 2019, when it said the rate of companies choosing to pay ransomware actors was a whopping 85 percent. The reason for the change, Coveware founder and CEO Bill Siegel states in the company's latest quarterly report, comes down to awareness.
Not only are more ransomware victims prepared for the inevitability of attacks by keeping better backups, Siegel points out, but several years of ransomware making top headlines – and associated [2]stories of payments amounting to nothing – have led to a reluctance to trust [3]data kidnappers .
[4]
There's just no honor among thieves, it seems – even digital ones.
[5]
[6]
"Q4 was rife with examples of how data assurances can fail, even when interacting with well-known 'brand established' ransomware groups," Siegel says. "Threat actors cannot be trusted to prevent ongoing misuse/publication of stolen data, and … payments to them for these imaginary assurances have zero if not sub-zero value."
Along with a decrease in overall ransomware payments, Coveware found that payments for data exfiltration-only incidents also hit an all-time low since it began tracking them in 2022. While 53 percent of companies were paying such demands two years ago, only 26 percent did so in the fourth quarter of 2023.
Further proof a ransomware payment ban is a bad move
Coveware's takeaway is that the world is making progress in dealing with ransomware that a payment ban would completely undo.
"A ban would signal that as a country, we are admitting that we are incapable of defending ourselves," Siegel states. He adds that early experiments with payment bans have been largely ineffective. The report cites a Florida [7]ban on ransomware payments that took effect on July 1, 2022, noting that "we have not yet seen a decline in attacks inside [Florida and other] states" that have enacted a payment ban, like North Carolina.
[8]US officials close to persuading allies to not pay off ransomware crooks
[9]Ransomware payment ban: Wrong idea at the wrong time
[10]Formal ban on ransomware payments? Asking orgs nicely to not cough up ain't working
[11]Be honest. Would you pay off a ransomware crew?
Instead, Siegel offered reporting requirements, like those [12]enacted by the US Securities and Exchange Commission [13]and the Federal Trade Commission, as a major reason for the progress. If a nationwide payment ban were enacted, that progress would be unpicked, the report argues.
"There would still be demand for ransom payment services because people and organizations will do what they must to survive," says Siegel. Enact a payment ban, and compliance with reporting rules may decrease as companies make payments through offshore accounts and "re-order the flow of money through a new illegal market of service providers."
[14]
Like ransomware criminals themselves, illegal service providers could easily take the money and run.
Safe harbors, encouraging companies to work with law enforcement, and more awareness of how to stay safe is the key, Coveware insists.
"Greater costs must be imposed on the threat actors by changing the incentives of the victims," Siegel says in the report. "Carrots and sticks are necessary." ®
Get our [15]Tech Resources
[1] https://www.coveware.com/blog/2024/1/25/new-ransomware-reporting-requirements-kick-in-as-victims-increasingly-avoid-paying
[2] https://www.forbes.com/sites/daveywinder/2021/05/02/ransomware-reality-shock-92-who-pay-dont-get-their-data-back/?sh=29cd42fbe0c7
[3] https://www.theregister.com/2022/10/09/extortion_ransomware_threats_category/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZbrRFisy6rWQvqHIi9qzGQAAAYw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbrRFisy6rWQvqHIi9qzGQAAAYw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbrRFisy6rWQvqHIi9qzGQAAAYw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.huntonprivacyblog.com/2022/07/26/florida-enacts-law-prohibiting-state-agencies-from-paying-cyber-ransoms/
[8] https://www.theregister.com/2023/10/31/us_ransomware_payment_ban/
[9] https://www.theregister.com/2024/01/06/ransomware_payment_ban_wrong_idea/
[10] https://www.theregister.com/2024/01/03/ban_ransomware_payments/
[11] https://www.theregister.com/2024/01/10/ransomware_kettle/
[12] https://www.theregister.com/2023/07/26/sec_reporting_security/
[13] https://www.theregister.com/2023/10/31/ftc_30_day_breach_disclosure/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbrRFisy6rWQvqHIi9qzGQAAAYw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
Re: Time to ban paying!
Seems to me the Reg carries quite a few articles that claim a ban on ransomware would be a bad thing. Maybe they know the Reg employers pension fund manager checked the box for "100% of investments to the Blackdog Unethical Emerging Markets and Global Cybercrime Syndicates Index Growth Fund".
Re: Time to ban paying!
You noticed that too?
I'm not going to go as far as suggesting that the vulture is necessarily in bed with the ransomware providers, but it certainly is suspicious.
Re: Time to ban paying!
Any problem has a solution that is simple, elegant, obvious, and wrong. Right now, disclosure requirements seems to be working by hewing to a middle path between no accountability and total criminal liability. Businesses have some heat on them but not so much that they appear to be concealing the scope of the issue. Ban ransomware payments entirely, and a black market in ransomware payment facilitation seems likely to emerge, and ransomware payment will become an additional way for ransomware scum to blackmail victims. Since the current approach actually seems to be working, why not let it continue?
Re: Time to ban paying!
Because the current approach IS NOT WORKING.
If ransomware is still seeing nearly 30% of victims paying, they're still making huge profits.
Banning payments will not create a black market, because payment to a shady facilitator will look just as obvious in an audit as a payment of the ransom.
No, a ban on payments with jail time for CEOs and others who pay is a solution that is simple, elegant, obvious, and correct.
Re: Time to ban paying!
We apparently have different concepts of "working." When the rate of anything drops from 85% to 29%, most normal people would consider that significant.
Hang on...
That linked Forbes article gives:
"According to the Sophos State of Ransomware 2021 report, the number of organizations deciding to pay a ransom has risen to 32% in 2021 compared to 26% last year. Here's the thing though, that same global survey discovered that only 8% of them got all their data back despite doing so. Nearly a third, 29%, couldn't recover more than half the encrypted data."
That's a far cry from the supposed 85% in 2019 given in the Reg article.
So in 2019 it was 85% (El Reg), in the 2020 it dropped massively down to 26% (Forbes), rising to 32% in 2021 (Forbes), then fluctuating to, now, 29%?
Forbes used Sophos and El Reg quotes Coveware, but still: if it was a horrid 85% back in 2019, which then dropped massively, then the changes since are minor fluctuations.
What am I missing?
Re: Hang on...
You're missing that probably both the 29% and 85% numbers came from surveys from very few victims, and there wasn't any way to insure they are being truthful. So I am highly skeptical of both numbers, or any "evidence" that the payment rate has fallen.
That's what businesses that profit from ransomware existing and don't want payment bans (i.e. those selling ransomware insurance, consulting on ransomware attacks, consulting to improve security against one, etc.) would like people to think, so people don't get smart and pass laws banning ransomware payment entirely.
Time to ban paying!
There REALLY needs to be a payment ban, with criminal charges carrying jail time for CEOs of companies that pay.
That 29% would drop to 0% in a hurry, and ransomware would become completely unprofitable.
It's time to end excuses and stop this crap from happening.