HomeSecurityOne in three companies will succumb to cyber-extortion

One in three companies will succumb to cyber-extortion

cyber extortion

Organizations that have already succumbed to cyber-extortion, that is, have been “stung” by a ransomware, are more likely to pay again, and probably won’t admit it anywhere, according to a study published in ThreatTrack.

Overall, 30% of the organizations that participated in the survey said they would negotiate with cybercriminals for the safe recovery of their stolen or encrypted data. But this percentage rose to 55% when organizations that had previously fallen victim to cyber extortions were asked.

The biggest example of cyber-extortion in recent history is the attack on Sony Pictures and Entertainment in late 2014. Just last week, a New Jersey school was “held hostage” by ransomware and had to pay a ransom of 500 Bitcoins (about $123,000). Instead of paying the ransom, the state conducted an investigation and restored what it could from backups.

But these incidents may be much more common than we can glean from news or official data, and that’s because companies are less likely to report cyber-extortion incidents—either to the public or to law enforcement, said Stuart Itkin, senior vice president at ThreatTrack.
It’s not that organizations don’t fully appreciate that cyber-extortionists are real criminals who deserve real law enforcement. Instead, the attack on Sony has shown the public how hackers can more personally, directly affect a company, extort money or otherwise disrupt an organization’s ability to function, Itkin says.
“Organizations are less likely to report this,” he says, “so we never know.”
The ThreatTrack research suggests that the issue is, indeed, more widespread. When asked if they believe other organizations have negotiated with cybercriminals, 86% of all survey respondents said “Yes.”
Some even went so far as to say that organizations are already preparing. 23% of all survey respondents, and 43% of those who had already been victims of cyber-extortion, said that organizations should save money to pay the ransom. 59% of all respondents and 74% of respondents who had been victims of ransomware in the past said that cyber insurance providers should hire professional negotiators to act as a liaison between organizations or victims and criminals.

The problem will take on larger dimensions, as the invaders using ransomware continue unperturbed the «game» with cyber extortions. Last week, CSIS reported a new impressively clever ransomware called PacMan.

CSIS has categorized PacMan as high risk. PacMan encrypts files on the local hard drive of any Windows computer with .NET installed. It is also equipped with “kill process” capabilities, which shut down Windows operating system functions such as taskmgr, CMD, regedit , and others, making this malware very difficult to remove. Once installed, it also starts a countdown clock, giving the victim only 24 hours to pay in Bitcoins or else their files will remain encrypted forever.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS