And I know the DC police force doesn't have global jurisdiction to root out cyber attackers, but the 3 letter agencies that do have this jurisdiction may view ransomware in a different light after this attack.
People who live in other countries aren't just mindless drones that march in lock-step with their ministry of foreign affairs.
That's why the reply a few comments up the chain said "These type of ransom seems to be state backed or at least tolerated."
"At least tolerated" part means that the hackers are doing it for their own purposes or for money, but not under command or employment from foreign federal agencies. Foreign federal agencies simply tolerate those hackers by looking the other way, since no skin off their backs for some ransom payments taken from some US entities.
> Hackers from Russia or China are higher up on the hierarchy of needs and attack targets for geopolitical advantage.
That is a completely different claim from what you are talking about. The throwaway account claims that foreign hackers are all political agents. (Which is an incredibly broad generalization to make about an entire country, that strips its residents of their agency, and would require extraordinary amounts of evidence to support.) Your statement does not support that interpretation - it argues that they are economic agents that are tolerated/encouraged/whatever by the political apparatus.
Your claim is compatible with mine. The throwaway account's, on the other hand, isn't.
Their ability to evade or the lack of ability of Western countries to deal effectively with them?
Then you read how the ransomware groups "avoid" CIS countries, well I wonder why...
https://en.wikipedia.org/wiki/Commonwealth_of_Independent_St...
The group demanding the ransom can freely set their price. Surely if they know an insurance company is on the hook for it then they’ll add a few zeroes accordingly, making it impossible to underwrite.
Nothing is perfect, but when there is no money in the crime there is much less crime. (Don't confuse less with zero!)
In theory, this helps with lower prices, negotiated support policies with the ransomware criminals to ensure the decryption process goes well, and they keep cryptocurrency available so the policy holding company doesn't have to scramble to get millions of dollars in crypto in a day or two.
Similar to kidnapping negotiators, ransomware negotiators often have the experience to produce a better outcome
I would expect the net result of this would be that groups raise their demands to match what (they think) the policy limit is.
My company was attacked relatively recently and our local servers were all encrypted. All we had to do was contact our insurance provider and they handled the investigation and negotiations with the group. A day or two later and our files were back.
A lot of companies either can no longer afford the insurance, or else it has become expensive enough that it doesn't make any sense to purchase.