University of Utah pays $457k to ransomware gang
zdnet.com
zdnet.com
[1] https://attheu.utah.edu/facultystaff/university-of-utah-upda...
That's like saying CVS security guards are pitifully small and inadequate. Yeah, you're right, they aren't going to stop a proper robbery... but stealing is illegal and shouldn't be happening either way. Same for hacking.
If, that is, the burglars could automatically try and burgle every commercial establishment and home in existence, succeeding, with zero effort expended, if the security guards in question were insufficiently vigilant.
Of course the programs aren't going to be a replacement for real product security teams, but they were never meant to be.
When setting bug bounty payouts, the company should be looking at what security researchers are likely to get when selling an exploit to criminals, not the actual extortion dollar amount (assuming that most security researchers are not willing to personally engage in illegal activity themselves, which appears to be the case).
However, when evaluating the value that a bug bounty program brings to the company, they should absolutely consider these typical extortion amounts.
This doesn't strike me as a very accurate assessment of the situation. There are already markets where people can buy and sell exploits: researchers don't have to get their hands dirty to get paid for their exploits.
I'm saying that the market value of actually performing an illegal act of extortion is higher than the market value of a zero-day, either on one of these markets or via bug bounty.
I'm arguing that the price is different because of the risk of getting caught and going to jail, not that there isn't a market for security researchers to sell exploits to criminals without otherwise getting their hands dirty.
That being said, I still think bug bounties are too low, even when risk adjusting.
Taking the certain $10k is the better deal over hunting for a shady buyer on shady sites who might send you some bitcoin if the deal even pans out or if they even pay. That's a lot more work and uncertainty while they act like it's just the choice between which lever to pull. A bird in the hand…
I recently found a compromised server on a university's network. I wasn't going to cold call them to report it because I had no idea how Betty answering the phones would react. Instead, I sent it to an IT contact that I knew personally. I knew that he didn't have anything at all to do with this, but that he would know who to get it to.
If the .edu is one of their 668 member institutions [1], they have designated security contacts at the .edu that they can directly get in touch with -- and, in many cases, can even wake somebody up at 3 a.m., if/when it's warranted!
Even if the .edu isn't a member, though, they'll almost certainly have an easier time getting in touch with someone with a clue that they can pass your report along to.
---
To explain, generally speaking a bug bounty is going to the smaller of:
1. Cost of Discovery since that is the amount someone would be willing to find bugs at otherwise they are losing money on each bounty they get.
2. Cost of Damage (risk-adjusted) since that is the most a company would be willing to pay.
The reason for this is that as long as the Cost of Discovery is lower than the Cost of Damage (up to ROI), it is reasonable to keep paying the Cost of Discovery since you are paying less than the risk-adjusted harm. But, there is also no point paying significantly more than the Cost of Discovery as long as people keep reporting problems as fast as you can fix them since there is no real reason to pay to get more problems than you can fix. So, to first order the bug bounty for a certain type of problem reflects the cost of discovery of that type of problem.
Circling back to the original point, we see problems that can cause millions in damages getting bug bounties on the order of $10K. This means that, to first order, million dollar attacks only cost $10K to execute which results in a crazy high ROI in the 100s. With an ROI in the 100s, it should be no wonder that such attacks have been increasing in frequency given their sheer profitability. The fact that bounties are so low for such critical problems is a major indictment on the prevailing level of security in the industry.
This is probably the biggest issue in terms of incentives to a researcher. You're either finding the bug by accident or out of curiosity, or you stop short of basically losing money you would otherwise earn going a paid audit.
500K once every 20 years or less beats 50K annually handsomely. Never mind the fact that once you lose control of your data you can never be sure you got that control back, that's somebody else's problem.
People are not very good at threat modeling, estimating chances of things happening to them and estimating the damage resulting from an incident. We collectively are not good at ensuring that the companies where these things happen get dealt with properly.
Bitcoin isn't the issue here.
When you have the pressure on the target, you can make the pay in whatever currency you'd like and there will always be one.
The black hat hacker "ecosystem" has also professionalized from doing it for kicks to doing it for the dough.
The attackers also only encrypted about 0,02% of the systems, but the university paid because the attackers threatened to make the stolen data public.
Better to throw it to a free market and let people find bugs for peanuts.
It's next to impossible to measure 'sec expertise'. This would only go far if the security expert gave a warranty on their service which we know is never going to happen.
Besides which, the thing that would save this companies is mostly obvious and any half-decent security officer will do them. The difference being buy-in from senior management.
https://www.cyber.gov.au/acsc/view-all-content/publications/...
In a logical extreme you could start adding features like "Give us the info of people you know and for every one we successfully extract a ransom from we'll give you 10% off your ransom."
It's interesting to think about at least.
Storfer learned quickly never to use the term “hacking.” Instead, he would assume his correspondent “thinks they’re a businessman,” Storfer said. “I’d say: ‘Look, we can’t afford this [ransom] at this time. Do you mind providing your product [recovery key] at a lower rate?’ And it worked,” he said. “They’re doing a job where everyone hates them, so feeling like they were respected made them work with us. I like to think empathy goes a long way.”
The rapport sometimes reaped discounts. “We were able to get a $5,000 ransom lessened to $3,000 because they knew we could deliver it exactly when we said we were going to get it to them,” Storfer said.
[1]: https://features.propublica.org/ransomware/ransomware-attack...There was a story a while back, perhaps on HN, discussing the results of an academic survey of prisoners (in the UK, I think). They consistently evaluated themselves as more honorable than the average person on almost every dimension.
I would think the biggest impediment to insiders doing this would be how to successfully hide and use the money, if it was a lot.
I think you could do it by issueing the shares as a zkAsset using AZTEC, and any ransom paid in btc could be transposed to renBTC on Ethereum, deposited into zkSYNC and distributed to all shareholders proportionately in the zkSYNC, that distribution transaction wouldn't be recorded onchain (although maybe zkSYNC has some ability to monitor transactions) and shareholders can withdraw their dividend at their own will.
But otherwise they can just convert the BTC to XMR first, and reintegrate that however they want.
But the issue is there are many different ransomware gangs and malware families. We'd probably start seeing a twisted form of corporate PR from most of them. "We're not like the rest. We abide by a strict code of ethics and believe fair and honest dealing is paramount to our reputation and customers' trust in us. We will never add hidden charges or 'alter the deal'. Rest assured that your keys are stored securely and will always be delivered to you within 4 hours of payment. That's the CryptoLockDeluxe guarantee."
It reminds me a lot of piracy in EVE Online, where pirates' reputation for allowing ships to carry on after paying the random was considered a big deal.
1. They infect a major institution with ransomware.
2. They demand, and successfully receive, a major ransom.
3. They DON'T immediately release the key, despite the ransom being paid. Instead, they issue an open demand for ransoms to be paid to a random Bitcoin address from other major ransomware groups.
4. The meta-ransomers only release the key to the original victim if they receive sufficient ransoms from other ransomers.
The meta-criminals would essentially be ransoming the credibility of ransomers. If the ransomers don't pay up, then the meta-ransomers will chip away at their credibility.
First thought is that the 'meta-ransomers' would probably only get one or two shots at such an action working before the major groups make some sort of statement (and even perhaps provide some sort of way to 'authenticate' that it an attack is from one of of the more 'trustworthy' ransomware groups.)
Second thought is that it would have to be a gutsy group of rogue actors or group of rogue actors. A lot of these underground folks still know each other one way or another and this would probably be considered a big 'f--- you' to the rest of the community. Bridges would be burned, unspoken agreements in the sphere may be violated. You could even see the ransomers quickly turn their efforts to exposing the meta-ransomers.
On the other hand, it could become an 'arms race' as the meta and non-meta ransomers start trying to shut each other's ransomware down
Of course this means if your child is kidnapped, you have a choice between going to jail, or receiving one finger or toe per week in the mail for the next half-year or so. (That is, if you're a generally law-abiding citizen who doesn't know the ins and outs of money laundering and you're pretty sure you'll get caught. If you think you can make the payment and get away with it, this changes your calculus.)
When your kid is horribly murdered as a result of your unwillingness to break the law, it's a cold comfort that the law's wise policy will theoretically eventually save hundreds or thousands of others' kids from the same fate.
I find it fascinating that it's illegal to pay to help a child who's in physical danger of being tortured / murdered, but apparently not illegal to pay to prevent simple doxxing. It seems like it ought to be the reverse, the law should show mercy to an individual person trying to save the life of their relative, but be more strict when it comes to a large business or institution trying to prevent merely economic or informational harms.
I was looking to dunk on them but it seems that what they did wasn’t entirely unreasonable. The article further states that they paid to protect student data.
They also send a clear message that ransom ware blackmail is a great business model. I think that is more than enough reason to dunk on them.
Unless they set money in the budget every year for "Ransomware Insurance Shortfall" this is 100% "tuition, grant, donation, state or taxpayer funds" at some point in the chain.
You may have paid all your tuition and still owe the university tuition. Got a tuition scholarship from the university? Better check the fine print. Full-tuition or half-tuition doesn't necessarily mean what you think it means. It might only cover one of the definitions of tuition. Each class can have multiple tuitions of arbitrary amounts and you have to pay them all; your scholarship does not have to cover them all.
Oh, and it is impossible to know how much to budget for a 15-credit hour semester unless you provide a specific list of classes taken.
So, "didn't come from tuition" is an ambiguous statement from a Utah school.
I remember encountering similar scenarios before and they all seem to want the money in a Bitcoin address.
Why not Monero, or an alternative if there is any, which I guess makes moving the funds around much more stealthily? Please correct me if I'm wrong.
Ransomeware still often includes live phone support and other features targeted at helping victims purchase and send bitcoins because its still a difficult and unfamiliar task for the average person.
It also seems like an opportunity to escalate the scam to the next level. Go to this site (controlled by the scammer) and enter your credit card to send bitcoin. Now they have your credit card too.
A few months back REvil/Sodinokibi switched to Monero, but I think they're the only strain to do so.
Help me with this, as I simply do not understand this 'forgetting' bit. Are you saying that a police agency, say FBI, is incapable of writing a (trivial?) program that tracks the coins, for as long as it takes to close the case?
Statute. Of. Limitations.
Also, detective/prosecutor raise+promotion incentive structure. Cold cases don't get headlines unless it's some mass-murderer-rapist-satanist.
It's absolutely crucial, in my opinion, that we pass laws making paying off criminals illegal.
There are arguments here that paying off via insurance or other 'secondary means' are somehow shielding the institutions. It's morally wrong, and I suspect in reality it's technically wrong to make these payments. It's just wrong. There is the problem that at least some of these ransomware groups are in countries like Russia that don't care to really prosecute them. We need to stop this, make it clear it's not acceptable, fight with our usual means against money laundering. Pretty much every company company in the western world is vulnerable to these problems, every public school, and behind the scenes lots of people are vulnerable.
When you pay ransom for lost data you get a copy of your data back. The culprits still have the data, but they likely don't have a use for that data.
But this is the worst kind of ransom.
You already have the data, you're paying ransom to make sure the culprits don't use the data, but the culprits still are in possession of the data and they can use the data next year, or two years later, or demand more payment next year.
What in the world?
It'd be too hard/expensive to exfiltrate the data once it gets large enough, without much added benefit. They just encrypt it in-place.
> The university said its staff restored from backups; however, the ransomware gang threatened to release student-related data online, which, in turn, made university management re-think their approach towards not paying the attackers.
The university is paying them not to release the data, but it has no way of forcing them to delete it.
$450k? Universities know all about paying to learn. That's cheap, and they won't make the same mistakes again.
The criminals doing these sorts of things are businesses too, the are unlikely to price themselves out.
If you think there's a 10% chance of incurring $1m in ransomware costs over the next 12 months, and reducing that probability to 5% will introduce an ongoing annual expense of $100,000 what's the sensible decision from a financial perspective?
>The university said its staff restored from backups; however, the ransomware gang threatened to release student-related data online, which, in turn, made university management re-think their approach towards not paying the attackers.
This is why the vast majority of encryption-based ransomware puts a lot of effort into ensuring they really can decrypt your files after you pay them.
I assumed ransomware was always a class of attack wherein non backed up data was at risk.
This seems like a failed ransomware attack where the university just got unencrypted information stolen that they didn’t want released.
Ransomware is just the act of preventing access to data, with the access being reinstated after paying a fee to the attacker. Generally accomplished by encryption. Whether or not the victim has mitigations, backups, etc. holds no relevance to the class of attack.
>This seems like a failed ransomware attack
It's not really a failed ransomware attack. The attack was successful (they were able to encrypt some data), followed by successful reinstatement of access to the data by using backups, followed by successful extortion by the attacker.
I watched a couple of presentations on security recently and just felt like we are all in a losing battle. There are always more bad actors, they get better and better, and they are a lot more motivated than any security team you can put together.
It's very much a last line of defense way of detecting attacks because it means the attackers are already in and already have access to whatever workload is being protected.
https://www.rubrik.com/en/products/polaris-overview/polaris-...
Disclaimer: I'm just an engineer (not a sales person/pr/...) and all my comments on HN including this one are entirely my own views/not the companies views.
Can anybody elaborate more on this ? What are the other resources than tution/grant/donation/state/fund to earn money ?
Paying ransoms is terrible for the world. We will have more attacks on more targets. There needs to be heavy incentive to not pay.
But they also had unencrypted, sensitive information sitting on their networks.
https://attheu.utah.edu/facultystaff/university-of-utah-upda... says they paid the ransom to prevent leaks.
I'm sorry, I'm not sure I'm seeing what point you're trying to make. Are you trying to say that Bitcoin is bad?
But now I have come to realize that a completely unregulated payment system is very dangerous.
To be clear, Bitcoin is not "bad". Humans are bad and this is why we can't have nice things.
If you’re referring to why people like it, those things can all be true despite criminals also using it.
Bitcoin (and everything like it) is very much at the "Pollute the environment with whatever the hell I want" phase of its existence. That should change.
Bitcoin should be taxed to recover the externalized costs it imposes -- basically, compensate the victims of bitcoin-enabled crime.
Is only a small fraction of bitcoin usage related to crime? No problem -- the tax will be very low.