Negotiating ransoms: when to play and when to fold
zetter.substack.com
zetter.substack.com
How do we go from here? Your job as a negotiator is to get them get them off their "fight mode" through the use of time, dialogue, and empathy.
By saying "I wont negotiate" you're building a gloom vision that there is no future. If the threat is real, you're out of time and out of luck. As Voss says, "She's dead"*
Further readings:
Stalling for Time: My Life as an FBI Hostage Negotiator ( by Gary Noesner)
Never Split the Difference (Chris Voss)
Ego, Authority, Failure (Derek Gaunt)
Movie: A Hijacking (IMDB)
* "60 seconds or she dies" challenge on Youtube (Chris Voss).
The goal of this exercise is to control your emotions and behavior. Easier said than done. I can see how the author above had a problem being logical about the situation. I still have those issues myself even knowing what needs to be done, things just happen. Tough skills and even tougher for a "natural born assertive".
Tangentially related to technical fixes: There was an incident recently where my brother had his phone simjacked, and the attackers changed his google password. He recovered access by email but they kept changing the password as quickly as he did. Both parties were still logged in. I called his phone number, someone picked up and then hung up. So I got on Skype on a couple different machines and basically DOSd the phone with calls from random skype numbers nonstop. After about 15 minutes of this they either turned off the phone or the 4G. It bought enough breathing room to change the 2FA on the account and lock down his bank accounts that used gmail as his verification address. If they'd been smart or fast enough to change both the recovery email and the SMS 2FA it would have been game over.
But I'd rather compare this to a natural disaster you were ill-prepared for. A lightning strike or tornado can also wipe all your data. You can't negotiate ransom with nature. And giving in to ransomware makes it worse for everybody else since it makes ransomware financially viable. IMHO it needs to become socially unacceptable to be ill-prepared for a ransomware attack. I don't care if it was a 0day or whether your security was sloppy. It was your job to be prepared for this.
At CCC events you commonly find a sticker at the exchange tables that reads "Kein Backup, kein Mitleid" - "no backup, no compassion".
But the post makes a good point - you don't need backups. You need restore. Which takes time and is frequently ill planned. Sadly.
> If you discover that the data was corrupted during the encryption process, is it game over?
> Most of the time, yeah. If it’s database files, typically they’re gone.
I hadn't even considered what happens when ransomware tries to encrypt a database while it is in use. That's not gonna end well...
On three occasions in my career I’ve been involved in events which led to large scale data loss. The first time the backups failed, and there was no recovering from it, ever since then I’m religious about testing backups. If you’re in a position to just restore from offsite backups not only can you just flip the bird to people trying to ransom your data, you’re also in a good position to deal with anything else, up to and including the data centre containing all your servers being burnt to the ground.
I don’t think we’ll break this cycle until paying Bitcoin to a Russian Hacking group = Jail.
http://jpkoning.blogspot.com/2021/06/why-do-ransomware-gangs...
This would set up an interesting experiment. Would you accept a $20 dollar bill in the supermarket if you knew it was used in some ransom case? And what if suddenly you knew you owned such a $20 dollar bill? Would you try to get rid of it as quickly as possible?
What would you set as a threshold?
From my experience dealing with ransomware, most encrypted applications are not recoverable, even with the key. Those app servers need to be rebuilt or restored. File servers and individual files can be decrypted using the key, but applications get scrambled.
It's like with cloud and microservices, most of the time backups, monitoring, and security aren't even considered.
Hmmm.
That would be a handful of negotiations per working day, or at least two/three per day 24/7.