Ransomware negotiator weighs in on the extortion payment debate with El Reg
(2024/05/12)
- Reference: 1715544194
- News link: https://www.theregister.co.uk/2024/05/12/ransomware_negotiator_payments/
- Source link:
Interview Ransomware hit an all-time high last year, with more than 60 criminal gangs listing at least 4,500 victims – and these infections don't show any signs of slowing.
Drew Schmitt is a [1]professional ransomware negotiator and practice lead for the GuidePoint Research and Intelligence Team or GRIT — that's the team that compiled the above-mentioned [2]2023 figures .
In this role, Schmitt has interacted with all of the major ransomware crews. The Register recently caught up with him to discuss the criminal gangs' evolving ransomware tactics, the role he plays in companies' incident response when they have suffered an infection or intrusion, and the larger question of whether ransomware payments should be completely banned. You can watch the full interview below.
[3]
[4]Youtube Video
[5]
[6]
In addition to the debate over a [7]total payment ban , there's also some controversy surrounding negotiators themselves, and whether they should be regulated. The official advice from the Feds is that victims should not pay ransom demands, nor should they negotiate with criminals.
"When we're talking about these types of situations on my team, we're talking about threat actor communications rather than negotiations, because there is so much more that goes into what we do other than just making a payment," Schmitt said. "We are there to advise on risk. We are there to have conversations with threat actors, focused on recovery, rather than moving towards a payment."
[8]
As GRIT has watched ransomware gangs use " [9]more coercive tactics " to put pressure on victims to pay — this includes releasing sensitive data and even contacting companies' customers and business partners — law enforcement is also turning up the heat via [10]coordinated takedown efforts .
These have seen varying degrees of success, and while it's still too early to declare victory, "it proved some of the biggest names in ransomware are not untouchable," Schmitt said. "In some cases more of a short-term impact," he added, citing [11]LockBit in this category. " [12]ALPHV , has gone through something that's a little more permanent it seems."
Of course, only time will tell if the gangs rebrand, or their affiliates join other crime gangs, so the jury is still out on the long-term nature of these disruptions.
[13]
While the increase in size and scope of ransomware attacks has led some to call for a [14]complete ban on ransom payments, Schmitt said the problem is too complex to be solved with a silver bullet like a ban. That might be part of the solution, several years down the road, he opined, but the reality is that eliminating ransomware will take a multi-pronged approach.
"The one piece that really sticks out to me is the incentivizing of improving security," he said. "Whether that's through things like cyber insurance, or it's going to be having the federal government provide some tooling that can help small- and medium-sized businesses, really it's gonna be providing that incentive to want to be more proactive about cybersecurity." ®
Get our [15]Tech Resources
[1] https://www.theregister.com/2022/08/06/interview_ransomware_negotiator/
[2] https://www.guidepointsecurity.com/resources/grit-ransomware-report-2024-q1/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZkE8A5QZv8RqBP@7wxpomwAAAIs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.youtube.com/watch?v=Jl_yJxWcGkY
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZkE8A5QZv8RqBP@7wxpomwAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZkE8A5QZv8RqBP@7wxpomwAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2024/01/06/ransomware_payment_ban_wrong_idea/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZkE8A5QZv8RqBP@7wxpomwAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2024/01/05/swatting_extorion_tactics/
[10] https://www.theregister.com/2023/12/19/blackcat_domain_seizure/
[11] https://www.theregister.com/2024/02/26/lockbit_back_in_action/
[12] https://www.theregister.com/2024/02/19/infosec_news_in_brief/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZkE8A5QZv8RqBP@7wxpomwAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://www.theregister.com/2024/03/04/experts_echo_calls_for_ransomware/
[15] https://whitepapers.theregister.com/
Drew Schmitt is a [1]professional ransomware negotiator and practice lead for the GuidePoint Research and Intelligence Team or GRIT — that's the team that compiled the above-mentioned [2]2023 figures .
In this role, Schmitt has interacted with all of the major ransomware crews. The Register recently caught up with him to discuss the criminal gangs' evolving ransomware tactics, the role he plays in companies' incident response when they have suffered an infection or intrusion, and the larger question of whether ransomware payments should be completely banned. You can watch the full interview below.
[3]
[4]Youtube Video
[5]
[6]
In addition to the debate over a [7]total payment ban , there's also some controversy surrounding negotiators themselves, and whether they should be regulated. The official advice from the Feds is that victims should not pay ransom demands, nor should they negotiate with criminals.
"When we're talking about these types of situations on my team, we're talking about threat actor communications rather than negotiations, because there is so much more that goes into what we do other than just making a payment," Schmitt said. "We are there to advise on risk. We are there to have conversations with threat actors, focused on recovery, rather than moving towards a payment."
[8]
As GRIT has watched ransomware gangs use " [9]more coercive tactics " to put pressure on victims to pay — this includes releasing sensitive data and even contacting companies' customers and business partners — law enforcement is also turning up the heat via [10]coordinated takedown efforts .
These have seen varying degrees of success, and while it's still too early to declare victory, "it proved some of the biggest names in ransomware are not untouchable," Schmitt said. "In some cases more of a short-term impact," he added, citing [11]LockBit in this category. " [12]ALPHV , has gone through something that's a little more permanent it seems."
Of course, only time will tell if the gangs rebrand, or their affiliates join other crime gangs, so the jury is still out on the long-term nature of these disruptions.
[13]
While the increase in size and scope of ransomware attacks has led some to call for a [14]complete ban on ransom payments, Schmitt said the problem is too complex to be solved with a silver bullet like a ban. That might be part of the solution, several years down the road, he opined, but the reality is that eliminating ransomware will take a multi-pronged approach.
"The one piece that really sticks out to me is the incentivizing of improving security," he said. "Whether that's through things like cyber insurance, or it's going to be having the federal government provide some tooling that can help small- and medium-sized businesses, really it's gonna be providing that incentive to want to be more proactive about cybersecurity." ®
Get our [15]Tech Resources
[1] https://www.theregister.com/2022/08/06/interview_ransomware_negotiator/
[2] https://www.guidepointsecurity.com/resources/grit-ransomware-report-2024-q1/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZkE8A5QZv8RqBP@7wxpomwAAAIs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.youtube.com/watch?v=Jl_yJxWcGkY
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZkE8A5QZv8RqBP@7wxpomwAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZkE8A5QZv8RqBP@7wxpomwAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2024/01/06/ransomware_payment_ban_wrong_idea/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZkE8A5QZv8RqBP@7wxpomwAAAIs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2024/01/05/swatting_extorion_tactics/
[10] https://www.theregister.com/2023/12/19/blackcat_domain_seizure/
[11] https://www.theregister.com/2024/02/26/lockbit_back_in_action/
[12] https://www.theregister.com/2024/02/19/infosec_news_in_brief/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZkE8A5QZv8RqBP@7wxpomwAAAIs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://www.theregister.com/2024/03/04/experts_echo_calls_for_ransomware/
[15] https://whitepapers.theregister.com/
Re: It is better to avoid a problem than have to fix it.
Anonymous Coward
Wow, what a brilliant solution. Don't use technology and tell people not to be stupid. You should run for president, my friend.
It is better to avoid a problem than have to fix it.
Design out your vulnerabilities. Keep your data offline, air gap with carbon-based life-forms, use distributed tech to avoid data honey pots, use less interactive tech, use less tech, hold less data (you do not need to retain a scan of your employees' passports, birth certificates, biometrics and medical records), have replacement systems available (and perhaps even configured), and train your staff not to be dicks online.
Treat ransomware gangs as terrorist entities (because they are - they attack hospitals, schools and infrastructure). If you physically locate them, send in a covert team to erase them. Naming and shaming is for wimps.