N.J.’S Largest Hospital System Pays Up in Ransomware Attack
threatpost.com
threatpost.com
Paying a ransom is like defecting in a prisoner's dilemma: it benefits you at the expense of hurting everyone else who will be stuck in the same situation. Making it illegal just forces everyone to cooperate and is something everyone would prefer.
Should be possible to prosecute under existing laws: you're providing support to a criminal enterprise, sounds illegal already.
Not to mention every law should first be measured on whether it is at all practical to meaningfully enforce. I guarantee there has been 100x more companies who've paid the ransom and didn't release a press release like this one did.
If a whole bunch of people are going to do it anyway quietly and the law isn't going to stop them, we're just going to occasionally double up the fines on the random businesses that get caught. While these endless ransomware hackings continue.
I'd much rather we spent public resources on prevention.
Let's say you're the in C-suite of a hospital that's held for $1M ransom, and you want to pay. How are you going to send the funds without someone in finance/accounting finding out? Maybe you try to convince them to keep quiet? Such a transaction will almost surely generate a suspicious activity report from the bank. Are you going to try structuring the transaction? How are you going to hide that $1M defect in your quarterly/annual reports? Are you just going to hope it doesn't get noticed by the IRS or the accountants auditing your report? The whole thing is going to unravel because of how many people you need to be "in" on the criminal conspiracy, and the amount of noise it generates. If you're caught, the amount of papertrail you left behind (from literally every step of paying the ransom) would make it very easy to prosecute.
You could try laundering your activities to a third party firm that does "ransomware recovery" (ie. they take your money and pay the ransom for you), but I'd imagine that if paying ransoms were illegal, the activities of those companies would be closely scrutinized.
Of course there could be an exception process that involves contacting LE first, paying the ransom, being fined and audited, and having to disclose a report online and in front of the entrances of the when, why, and how this occurred. Paying the ransom w/o going through this process could (maybe?) be treated as conspiring with the attacker (& since the identities of the attackers are almost always 100% unknown, some could legitimately have inside contacts anyway).
If no one paid the ransom, ransomware wouldn't exist. the more people who pay the ransom, the more incentive attackers have to create ransomware.
Even if we made it illegal, it doesn't mean people wouldn't pay them. It would just punish victims further.
I guess you didn't read the second half of my comment where I suggest that will likely be idealistic and unreleastic.
Enough companies will still pay quietly to keep it going. I'd be shocked if they didn't.
If you're attacking a public institution like a hospital and demanding many thousands of dollars... it's pretty hard to hide a payment like that. So if you outlawed paying such ransoms, those types of ransoms would stop.
Individuals would still be attacked and asked to pay a few hundred dollars, but such instances rarely put lives at stake.
Governor Rick Scott of Florida stole a Billion dollars from Medicaid before he got caught.
Even if we made it illegal, it doesn't mean people wouldn't pay them.
That doesn't change the game theory dynamics that I pointed out above.
Judges don't recuse themselves because someone they know wasn't involved in the case.
When Randsomware was a new idea and seemed to be primarily targeting individuals, it made sense that paying your way out should ultimately be legal. Any law against it would be difficult to enforce, so bad actors would still be incentivized to launch attacks, and only law abiding citizens would be hurt.
But now they're attacking banks, and hospitals, and cities. I have trouble imagining large hospital systems would be able to discretely pay hundreds of thousands of dollars illegally without anyone noticing—and if they did, it would be easy to prosecute.
Ergo, outlawing these payments should very significantly reduce the number of ransomware attacks against these large targets. If no one can pay, there's no incentive to attack.
Doesn't making it illegal just change the cost structure? The penalty for illegally paying a ransom in your proposed system would be simply to pay a fine. It's effectively how a rich person might look at a parking ticket for a premium parking spot - it might be cheaper for them to simply pick the illegal spot than to have to drive 2 miles away and call an uber to get to their destination.
No offense, but this proposal is essentially DOA.
As for size of fish, we don't go "why is theft illegal when there are murderers still roaming around?" We can have both be illegal.
Enforcing a fine relative to the ransom paid (and maybe relative to the "if we wouldn't have paid it" severity) is probably a good immediate start. This would at least galvanize businesses to improve existing security.
Every single thing done by a government, or really just any large player in the market place, is going to have small businesses that get flattened by it. That your entire company could be wiped out by changes in the marketplace, including laws, is one of the risks a person assumes when they decide to start a small business instead of working as an employee. They're earning their slice of the money pie in part by assuming that risk.
But the stories of hospitals and other entities paying non-trivial sums in ransom I would expect are mostly professional criminals, not hackers doing it for lulz.
https://www.bleepingcomputer.com/news/security/ryuk-ransomwa...
How about instead the government proactively pentests and fines orgs for security violations,and uses the money to finance education, training, and security development?
From a financial POV, as long as the ransom costs per year is lower than the cost to replace their Cerner systems, it makes sense to simply see it as the cost of operations I guess?
Sort of. Unless the cost and frequency of ransomware incidents are absurdly low, it makes sense to borrow to upgrade. Putting aside the moral hazard of being a compliant mark, there is the risk that the next attack won't be as cheap.
Their vendor ought to figure out the hospital's mean annual ransom payment, and come up with financing for an upgraded system that comes out to that amount. Now the cost is locked in, while the variance is sharply reduced. (No risk ever goes to zero.)
Bundle the financing with cybersecurity insurance.
Just think when stealing patient and financial information becomes more profitable than what regular ransom ware demands net.
Even more, perhaps targeted assassination based on screwing up data? Demanding silence and cooperation for whatever the cyber-criminal do?
BUT, given that important data needs to be backed up anyway, most commodity backup software and commodity storage platforms are sufficient to restore encrypted data. Even Windows shadow copying feature (which lots of storage platforms will expose snapshots/revisions as) is pretty sufficient to prevent significant data loss.
So unless the ransom cost is cheaper than an IT tech reimaging/rebuilding the machine + compliance costs, it doesn't really make sense.
My wife is a resident. Nearly every EMR she's used, has been either Citrix or Remote Desktop based.
An automated attack that manages to hit a random workstation can extract a ransom of a couple hundred dollars; but if they invest a couple day's hacker labor to move deeper, then there are many public cases of $50 000 - $500 000 ransoms paid, and multiple cases such as Baltimore city and Atlanta city which suffered losses in excess of $10m as a result of not paying the ransoms.
If it's phishing, typical staff clicking suspicious emails and opening URLs and attachments, there isn't a lot the hospital can do to stop it. A bit of blocking around external emails and shady attachments will help, but people will still fall for it quite often.
If it's remote vulnerabilities, probably some unpatched systems, it's risky because that could parallelize the whole hospital anytime, but as long as the vulnerability is patched by the ransomware it's still cheaper than doing the maintenance.
If the user is using Windows 10 Professional and doesn't have admin access, can they still be a victim of a ransomware attack?
https://docs.microsoft.com/en-us/windows/security/threat-pro...
The only thing that ever saved us in the half dozen or so times that we've been hit is a robust backup system.
You don't (well, not with 100% certainty anyways), you mitigate the harm.
They often also have cyber insurance that covers data leaks, but even without cyber insurance the K&R policy often covers costs to recover from ransomware, either by paying the ransom or by replacing/restoring systems.
These record systems used to all be developed in-house systems, fully self supporting, with little outside involvement. Then in the 2000s gov regulations started mandating adoption of EMRs.
Especially here this seems like a no-brainer but in actuality for many hospitals they were unnecessary and introduced with massive cost overruns as hospitals were forced to buy them from a limited pool of vendors that were approved by deadline rather than by intrinsic need.
How does this relate to the ransoms? Because if the EMRs were adopted organically, my guess is it would have happened more gradually, with more diversity of systems, more open source, more testing, and more emphasis on security, backup, and self-reliant reliability.
It's hard to overemphasize the change in records infrastructure in hospitals due to mandated EMRs, and a lot of it has been for the worse. EMRs would have been implemented eventually without the mandates, but at lower cost and greater security probably.
It's just another example of how overregulation in healthcare that sounds good but in practice ends up creating unnecessary costs and causing problems. It also once again doesn't get attention in healthcare price discussions, because it's structural, indirect, and removed from the immediate billing.
I blame these types of ransomware attacks in part on EMR mandates and those who encouraged them. Should bthe federal gov, which encouraged this mess, pay the costs, either of the ransoms, or the cost of not paying?