HomeSecurityRansomware: Could a ban on paying ransoms reduce attacks?

Ransomware: Could a ban on paying ransoms reduce attacks?

Ransomware attacks: Could banning ransom payments, by law, reduce attacks, since hackers would not make a profit?

Ransomware

Ransomware attacks are among the most profitable cyberattacks. The reason is that many victims choose to pay the ransom (usually in Bitcoin or another cryptocurrency), and thus the hackers make a profit .

See also: Ransomware: Average ransom payment increased by 171% in 2020!

The ransoms demanded by hackers are sometimes enormous. In recent weeks, one company paid $5 million to restore its network after an attack by Darkside ransomware, while another hit by REVIL ransomware paid $11 million to obtain the decryption key.

The REVIL ransomware gang also carried out a massive ransomware attack, exploiting a vulnerability in software from the company Kaseya. The attack affected approximately 1,500 companies worldwide.

The attackers demanded $70 million to provide a universal decryption tool.

These are just a few examples. In many cases, cybercriminals demand millions of dollars and many victims choose to pay as they feel they have no other choice.

Experts, however, argue that paying ransoms is destructive because it empowers ransomware gangs. While governments discourage organizations from paying ransoms to criminals, the payment is not illegal. However, there have been discussions about implementing legislation that would prohibit paying ransoms.

The potential positive and negative consequences of banning ransom payments were recently discussed by a group of experts.

See also: Colonial Pipeline CEO: Paying the ransom was the right decision for the country

“Most people agree with banning ransom payments. Basically, we’re funding crime, and that’s bad,” says Jen Ellis, an executive at Rapid7 and head of the Institute for Security and Technology’s (IST) Ransomware Task Force (RTF).

prohibition of ransom payments
prohibition of ransom payments

Paying the ransom shows criminals that ransomware attacks are effective, encouraging further attacks, while at the same time the payments may be used to fund other crimes.

Of course, when the network is down and business operations cannot continue, businesses don't think about the long-term consequences of paying the ransom. They just want the problem resolved as quickly as possible.

In some cases, businesses can claim these costs from cyber-insurance companies. However, this does not mean that these companies agree to pay.

“Believe me, insurers do not want to pay ransoms. It is ultimately our client’s decision and I fear there are times when there is no other alternative,” says Graeme Newman, from insurance provider CFC Underwriting.

Newman explains that all companies that decide to succumb to hackers' blackmail do so because they are in desperation.

“If we ban payments, there will be a significant disadvantage for all businesses that are attacked,” he says. “What is needed is a structured system consisting of a small number of specialized actors who can determine when it is okay to make a payment.”

There is currently no guidance on the situations in which it would be acceptable for a victim to pay the ransom. There is also no guidance on what action should be taken against victims who decide to pay. However, it is said that if a law is enacted to prohibit paying ransoms to ransomware gangs, insurance companies should not be penalized.

“You’re banning the payments, not the people who may or may not facilitate the payments. Banning insurance companies from covering the payments, without banning the payments themselves, makes no sense – whether the payments are banned in general or not,” says Ciaran Martin, a professor at the Blavatnik School of Government and former director of the National Cyber ​​Security Centre (NCSC). Martin says he “wants a ban in general.”

See also: Ransomware businesses: Negotiators are in high demand

For now, the decision to pay the ransom lies solely with the victims.

However, while the idea of ​​a ban may sound appealing, it doesn't mean it will put an end to ransomware attacks. It's likely that cybercriminals will continue to carry out their campaigns, as there will always be victims who decide to pay the ransom, even if it's illegal.

ransomware ransom

“They will continue to target organizations that are less able to resist payments – critical infrastructure that cannot handle the burden of disruption or small and medium-sized businesses that do not have the capacity to cope. So if ransom payments are banned, attackers will likely focus on these groups,” says Ellis.

“Banning ransom payments seems like a good thing in the long run – we don’t know how to do it realistically, in a way that doesn’t cause a lot of short-term problems. That’s the dilemma,” he adds.

What is clear is that ransomware is going to remain a big problem for some time to come. Ideally, organizations should take protective measures to avoid falling victim to such attacks and being left with the dilemma of whether to pay or not.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS