Ransomware ban backers insist thugs must be cut off from payday
- Reference: 1709562606
- News link: https://www.theregister.co.uk/2024/03/04/experts_echo_calls_for_ransomware/
- Source link:
Ciaran Martin, founding CEO of the UK's National Cyber Security Center (NCSC), reiterated his stance on the matter a week after LockBit started to get back on its feet again following the efforts of Operation Cronos to bring its servers offline for good.
"Ransomware is by far the most damaging cyber threat to most businesses right now. We have to find a way of making a ransom payments ban work," he said.
[1]
LockBit recovered its online presence (albeit in a limited capacity at the time of writing) within days of Operation Cronos' [2]week-long embarrassment of the gang and weeks after the FBI flopped in its [3]wrestling match for control over ALPHV's infrastructure.
[4]
[5]
Martin's comments reflect a growing belief in the cybersecurity community that a [6]ban on ransom payments is the only way to disrupt the crime in the long term, despite the challenges that would come with such a move.
One of the foremost [7]arguments is that banning ransom payments would leave many businesses unable to recover their systems.
[8]
Jake Moore, global cybersecurity advisor at ESET, said: "Banning ransomware payments can often have further implications – and this is not the first time this idea has cropped up. Although prevention is better than cure, there are still multiple cases where the only option has been to pay. Being stuck between a rock and a hard place is no position any company wants to be in but if the law is directing only one way, then companies can easily fold and the potential of livelihoods lost can make this a damming and forced decision.
"Although the long-term effects of banning ransom payments may sound idyllic, the path needed to navigate all companies to this ideal is going to be challenging, if not impossible. And then there is the inevitability that companies will still become a target and left with no other option."
It's an argument that those in favor of a ban acknowledge and appreciate, a compelling one without a tangible solution right now.
[9]
Martin argues that a ban will only work if governments collaborate on establishing a framework of support for organizations that are attacked and don't have the resources available to recover.
In a piece co-authored with Tarah Wheeler, CEO at Red Queen Dynamics, the pair pointed to the Troubles in Northern Ireland, a conflict that saw insurers refusing to cover businesses against bombings, meaning the government had to step in to offer the support that was needed.
"There may even be a case for financial support to affected businesses who don't pay," they [10]wrote .
"That's unusual, but an emergency situation requires unusual measures – and there can be no doubt that ransomware constitutes an emergency."
The financial support described would have to persist for as long as ransomware does post-ban, which could be for years before the criminals get bored and move on to something more profitable. It would be a painful battle of attrition between organizations legally unable to pay and criminals draining their governments of support funds.
[11]LockBit's contested claim of fresh ransom payment suggests it's been well hobbled
[12]US officials close to persuading allies to not pay off ransomware crooks
[13]Ransomware payment ban: Wrong idea at the wrong time
[14]LockBit identity reveal a bigger letdown than Game of Thrones Season 8
Establishing this support package would need to account for attacks on key services and critical infrastructure, where we've seen in the past that paying a ransom is often deemed the only solution for a fast recovery.
Other arguments against a ban are increasingly falling apart, Martin said.
"Terrible arguments have been made against a ban. One is that 'it will drive the problem underground.' Will company directors really knowingly break the criminal law? Other reasons are falling apart," he [15]opined in The Times.
Cybersecurity expert Kevin Beaumont agreed, [16]saying : "A lot of the arguments against this fall apart with any basic level of scrutiny and are largely being made by people and orgs who directly or indirectly benefit from the status quo.
"Nothing should be off the table, and it may well help manage ransomware group's targets if this option was very much on the table, in fact."
It's a take with which others have also concurred, such as Lisa Forte, partner at Red Goat Cyber Security, who [17]said that small disruptions of ransomware gangs aren't working, so the finances of ransomware must be the next target.
She also pointed to the 1991 law enacted by the Italian government to curb ransom payments to high-profile kidnappers – an endemic crime at the time.
The law saw the government seize control of all assets of a kidnapping victim's family so they couldn't be offered as a payment, and the prohibition of kidnapping ransom insurance policies.
It took a few years to work but it did to a decent degree, although it's believed some families just stopped reporting the kidnappings to avoid their assets being seized.
Strictly technical measures such as trying to prevent attacks through adequate security products and controls have been argued as ones that should be prioritized over a ban. Ensuring robust backups are in place is also a long-peddled solution but neither is full proof, clearly.
There are currently no plans to develop a legal ban on ransom payments from the governments of the Five Eyes nations.
Nearly 50 members of the Counter Ransomware Initiative (CRI), which includes the UK, US, Japan, India, and Israel, all [18]vowed to not pay ransoms in October 2023, although this of course isn't legally binding.
The ongoing debates linger against a background of growing cyber extortion rates, according to security shop Emsisoft, which pegged last year's average extortion payment at $1.5 million.
The New Zealand-based company is another proponent of a ransom payment ban. Brett Callow, threat analyst at Emsisoft told The Register at the start of the year that it's [19]probably the only solution to the perpetual issue. ®
Get our [20]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZeX@NhEIf6kVi0iAxoPfGgAAABg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2024/02/23/lockbit_identity_reveal/
[3] https://www.theregister.com/2023/12/19/blackcat_domain_seizure/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZeX@NhEIf6kVi0iAxoPfGgAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZeX@NhEIf6kVi0iAxoPfGgAAABg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2024/01/04/feds_stole_the_ransomware_limelight/
[7] https://www.theregister.com/2024/01/06/ransomware_payment_ban_wrong_idea/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZeX@NhEIf6kVi0iAxoPfGgAAABg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZeX@NhEIf6kVi0iAxoPfGgAAABg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://www.brookings.edu/articles/should-ransomware-payments-be-banned/
[11] https://www.theregister.com/2024/03/04/in_brief/
[12] https://www.theregister.com/2023/10/31/us_ransomware_payment_ban/
[13] https://www.theregister.com/2024/01/06/ransomware_payment_ban_wrong_idea/
[14] https://www.theregister.com/2024/02/23/lockbit_identity_reveal/
[15] https://www.thetimes.co.uk/article/cyber-ransoms-are-too-profitable-lets-make-paying-illegal-kc8cmhxs0
[16] https://cyberplace.social/@GossiTheDog/112036049965592704
[17] https://twitter.com/LisaForteUK/status/1764555241758843034
[18] https://www.theregister.com/2023/10/31/us_ransomware_payment_ban/
[19] https://www.theregister.com/2024/01/03/ban_ransomware_payments/
[20] https://whitepapers.theregister.com/
Yes, there needs to be a ban. And it needs to not just be a fine for companies that pay, it needs to come with prison time for the CEO.
No, there does NOT need to be any corporate welfare to go with it. I'm sure the usual suspects would love that, but for-profit companies do not deserve help for being stupid.
Yeah, I was about to comment on the corporate welfare part.
So the idea is that if a company doesn't want to spend the money to do security right, tax payers will just come along and bail them out? That sounds like a typical government solution. Spend someone else's money...
Sometimes doing nothing is the correct answer
An effective ban on paying ransom is about as likely as an effective ban on ransomware, it relies on every country agreeing and implementing an effective ban. It's probably easier for a desperate company to pay a ransom via some shady intermediaries than it is to actually perform the cyberattack in the first place. It's a shame when companies get hit, but they should be prepared for it, and there is no excuse for not having a tested disaster recovery process.
10 do_backup
20 test_backup
30 goto 10
Re: Sometimes doing nothing is the correct answer
"it relies on every country agreeing and implementing an effective ban."
No it doesn't. If county X bans paying ransoms then the scammers will quickly get the message and just concentrate on countries Y and Z. They aren't going to waste their time and effort in a country where they won't be paid. Other countries would be likely to follow the example if successful. As someone else mentioned, paying a ransom in country X should mean the CEO of that company goes to jail. It would be very difficult for larger companies especially to hide payments to scammers without also fiddling their accounts too, opening them up to an even bigger can of worms if their accounts are audited.
"banning ransom payments would leave many businesses unable to recover their systems." This might be true if there were no way to protect those systems, which is not the case. It might be impossible to guarantee 100% that your systems won't suffer an attack and exfiltration of your data but there's plenty of existing security and recovery tech and procedures out there to reduce the impact of an attack.
Solution to "Cannot recover without paying"
The solution for handling companies that would not survive a payment ban has been around since life started on this planet and was published decades ago by Darwin. If a company goes out of business because of a ransomware attack it can go bankrupt and be replaced by companies that are either not vulnerable or can recover using backups.
My response to the idea of a government bailout for ransomware victims is a stream of bad language that would legitimately result in strong action from the moderators.
The Italian system of confiscating the wealth of victims so they cannot pay up is interesting. For the time being I would leave it as a threat: this is what will happen if companies try to sneak payments around a ban.
The National Cyber Security Centre (NCSC)
“ [1]The National Cyber Security Centre (NCSC) is an organisation of the United Kingdom Government that provides advice and support for the public and private sector in how to avoid computer security threats.”
Like: don't click on a URL or open an email attachment /s
[1] https://en.wikipedia.org/wiki/National_Cyber_Security_Centre_(United_Kingdom)