Wanted: Disgruntled Employees to Deploy Ransomware
krebsonsecurity.com
krebsonsecurity.com
Nobody needs to know who anybody else is - just "here's our ransomware, any ransom paid that mentions your unique ID, we'll split with you. Have fun"
Crowdsourced criminality.
A similar dynamic is at play between ransomware attackers and their victims. Why would ransomware attackers restore files from a successful attack after the ransom is paid? Easy. The attackers need the world to know that paying the ransom will work, otherwise no one would pay it.
Why is a ransomware company going to follow the rules of common decorum when dealing with a collaborator if the whole point is to defraud a third party?
How do I know that they made the payout? Is the collaborator going to come forward and identify themselves? The only way you know that person got paid is if they don't get arrested. There are whole branches of organized crime than live and breathe in the space between 'got paid and lived happily ever after' and 'ended up on the front page of the NYT'. Just off the top of my head you have blackmail, extortion, and hiding the body.
They need third parties to think that working with them is their best option. Their best option is to do something legal, but desperate people can be manipulated. Greedy people can be really manipulated. Maintaining the illusion of safety is just marketing.
If the game is extortion, then psychological manipulation is part of the game. I have no assurances that you've given me $1.4 million today and this is the last I will ever hear from you. If I know little about you I can't even turn State's Evidence to save my ass if I get caught but you don't. If I think I know that you or anyone with details of your operation won't come back later and threaten to turn me in unless I pay you money, then I'm a fucking idiot. You could ask for money, or to "deliver a package" for you. In that situation, what you and your associates are counting on me forgetting is that I am mortgaging my future by piling on new crimes with later statute of limitations dates, and establishing a pattern of behavior that makes me look even more complicit.
There is no honor among thieves. Stop trying to figure out how to pet a wolf without getting bit.
Victims of ransomware are public and will publicize if they don’t get their files back. An individual willingly trying to compromise their employer’s network is not going to publicize not getting paid because it will get him/her arrested.
They will anonymously post on the message boards dedicated to ransomeware gangs that this particular gang is not reputable. Like leaving a Yelp review, except even more trustworthy because it's a relatively tight-knit community.
It would only work out for the gang if the ransom was enough money they decide to "retire" and not pay out. In all other situations, they need their reputation.
And why would someone believe an anonymous post? Don’t you see the problem here?
Aside from bugs in the contract, or opsec concerns, the main risk (for the saboteur) would be the ransom folks directing the victim to pay some other address that wasn't part of the smart contract, so no money ever comes into it. Really, it's only marginally more reliable than just depending on them to pay you when they get paid.
It's a sort of prisoner's dilemma problem - since the game won't be repeated with any single employee, and there's no communication between employees, the gang gets a better outcome in all cases by not paying.
I'd bet on the employee getting scammed too.
Ugh feels so dirty even saying it, I guess that's why sociopaths win so often.
"we paid this other guy and he got caught"
"come join us!"
For me it's not hard to believe at all that someone who is already at a low point and motivated with malicious intent would read up on such an offer and think to themselves "I can screw my boss __and__ get a cool million in etc? Just for 'accidentally' uploading some ssh keys with a misplaced wildcard?"
Even before the covid pandemic, stress in IT was high and disgruntled employees doing damage on the way out was making headlines. Search 'Disgruntled employee destroys data' on google and check the date of some of the news articles. Here's one that made US national news in 2014 about how data theft was a trend.[0]
Whether or not there's a real payout is of no consequence it seems. I'm only able to immediately find articles about such incidents in the US and the UK, but I am fairly sure it's not limited to such locations, or that outsourced IT isn't just as vulnerable.
I've written it before on HN for other reasons, but people like to talk about new laws/standards/etc, but IT doesn't have problems that need legal solutions, as an industry, IT needs to improve discipline across the board and stop letting situations where one person can be so destructive happen. Too many places still run their IT like it's the 80's/90's where one or maybe two with absolutely control over everything. This leads to burnout first of all, which is horrible, but it also creates these bad situations of unregulated control in the first place.
[0] https://www.wsj.com/articles/fbi-warns-of-rise-in-disgruntle...
I mean, it's like having the neurosurgeon at the hospital retire/quit for a software company to lose it's IT.
The issue is, many software companies don't know/think they are a software company.
You don't even have to time it perfectly. In six months, when they're most upset and seeking revenge they'll remember the email
Many companies that get hacked get hacked again anyway. With the help of an insider, an attacker could more effectively around any new countermeasures, too.
https://www.zdnet.com/article/lightning-does-strikes-twice-i...
It is an extremely bad idea to bring coworkers into the scene at the time of firing and it's an even worse idea[1] to bring unnecessary people into the decision about firing - especially if they effectively have no voice in the decision.
You probably won't notice most of your coworkers leaving - but there are a few you'd likely feel deeply and people do occasionally need to move on. Go grab a coffee with them after the fact (or during their two weeks notice if that applies) and get your empathy in - but before someone is formally let go it will just hurt moral to spread that news too widely.
Especially in a small company, sometimes it’s best to cut your losses quickly and toss the rotten apple over the cliff rather than go out of your way to stomp on it and deal with rotten apple stuck on the bottom of your shoe.
Definitely not a 10x, just a scam artist.
Did you only fire him because you found out he worked other jobs or because he didn't do enough work?
(He was also not doing an amazing job - he required constant supervision without which he wouldn’t produce any meaningful output, presumably because he had 2 other managers he was trying to please at the same time)
It’s not so much about whether he was a good coder. More that I can’t trust someone with production database access if I discover 6 months in that he has 2 other full time jobs.
Clearly it’s a dumb thing to do because you are in the same country as the victim, would be on a list of interesting people to talk to and you’ll probably leave a trace of some sort. Unlike the scammer who is anywhere and anyone.
Ask a lawyer what is legal.
$ 1.8 BLN in "Business Email Compromise (BEC) or CEO Scams, in which crooks mainly based in Africa and Southeast Asia will spoof communications from executives at the target firm in a bid to initiate unauthorized international wire transfers."
$0 for terrorism.
Meanwhile wage theft in the US is estimated between 40 and 60 Billion $.
AFAIK it boils down to "amount that employees should have been paid but haven't". That might sound comparable to regular theft, but it's not, because it fails to account for the intent component. If you forgot to scan a bag of potatoes in your shopping cart and you walked out of the store with it, it's not theft because you didn't intend to do it. I'm not saying that all wage theft can be excused this way, but I'm not a fan of the combination of naming/definition.
It's a question of the magnitude of lateness - if ever your employer says they'll "make sure you get double next pay period" it's a good sign to leave - and they're still obligated to pay you for the previous pay period regardless of how undiplomatically you exit.
You also need to realize that a lot of Americans work paycheck to paycheck so an employer failing their obligation can cause financial hardship and possibly force debt (with the accompanying interest) on their employee.
That... depends? If you're salaried and your employer missed a paycheck I'd agree it's scummy, because it's hard they screwed that up. However, if you're being compensated variably (eg. hourly or on commission), and you got paid incorrectly because of some random failure (eg. timesheet got lost/buried, sales numbers got delayed due to ERP issues) I think it's excusable if it was fixed in a timely manner.
I think it's fair - while that money is tied up in limbo - to essentially cease working. That provides a very clear incentive and attaches a level of importance to the incident that should prompt your employer to correct in the future.
Everyone makes mistakes - we're all human - however recovering denied wages is a very difficult legal fight that often results in failure due to debt shenanigans and the like. As an employee you need to be incredibly defensive about any interruption to your pay stream.
This is an incredibly common practice. Employees may come to believe some version of, "this sucks, but that's just how it is". Meanwhile employers and management have complete deniability and can point to company policy saying this is explicitly not allowed.
At the same time employees are [secretly] stack ranked and everybody knows that the expectation is to work 50 hours a week to survive in the company.
That's a 25% more work than 40 hours. Not a rounding error.
"""Wage theft is the denial of wages or employee benefits rightfully owed to an employee. It can be conducted by employers in various ways, among them failing to pay overtime; violating minimum-wage laws; the misclassification of employees as independent contractors, illegal deductions in pay; forcing employees to work "off the clock", not paying annual leave or holiday entitlements, or simply not paying an employee at all. """
from https://en.wikipedia.org/wiki/Wage_theft
It's not a delay in payment or a misplaced bag of potatoes.
>This failure to pay what workers are legally entitled to can be called wage theft
https://www.epi.org/publication/epidemic-wage-theft-costing-...
Not quite what you're looking for, but here's a recent article [0] on a $1.6M fine for $1.4M in violations at a single restaurant in San Francisco.
[0]https://www.google.com/amp/s/www.ktvu.com/news/san-francisco...
...having said that, wage theft is not only difficult to quantify but even to define precisely.
An employer with-holds/steals/defrauds an employee for £500 or more, and not only will the police not care, they won't even note it as a crime. Best bet is a civil court, but that takes time and can cost money.
So most people just move on and the employer does it again and again.
We made a big stink out of it, but he didn’t budge until there was an outage on Saturday and we didn’t fix it until Monday. There was only three of us, colluding not to fix it, but he’d have gotten away with it if the team were bigger. It’s hard to “make a stand” when more people are involved.
What's this supposed to mean? That terrorists don't receive financing and/or conduct illegal activities to finance their activities?
What do you think is used for audits and oversight if not email and spreadsheets?
Or are you just saying that everything everyone does, doesn't really work?
Because cloud. If it's not cloud it needs to be cloud because cloud. Cloud.
The only difference being that the BSA's program is legal because it benefits huge multinationals.
We're trapped in the worst possible timeline where we have an abundance of resources and work that's so much abused by privileged elites that many people suffer from bad access to food & housing (despite an over-abundance, at least in the global north), others from lack of meaning to their work/life (see also bullshit jobs), while others suffer from the pollution created by IoT and entire families of throwaway products that populate all supermarkets and e-commerce sites.
He's far from the most radical thinker i can think of in this regard, but i think David Graeber's (RIP) CCC talk on Managerial feudalism and the revolt of the caring classes is spot on in many regards.
I suspect what actually happens is that the employee takes all the heat for an empty promise of big money, and the criminals walk away with the entire profit.
Imagine if these groups actually advertised right out in the open. I’m sure they could catch a few people before their free AdWords account got suspended.
Imagine getting blacklisted by ransomware gangs for being an untrustworthy company.
That isn't to say everyone who chips in is going to get a cut and its all lollipops and sugar snaps in the extortioners guild! But if you're thinking Oceans 11 or something you've missed the mark.
That’s not a thing. Even non-criminals very frequently feel that someone didn’t fulfill an agreement and refuse to pay.
Companies most certainly aren’t refusing to pay people to please shareholders. Shareholders hate companies that don’t pay their bills.
You might as well ask why the group would bother providing the decryption key once the ransom is paid. It's a little trickier here - do you want to be in a position to call them out publicly afterwards if you were complicit in sabotaging your employer? - but the criminals arguably have more to lose.
Every negotiation is about the best alternative each party has to an agreement.
If someone has a plausible alternative to a ransom, like restoring from backups, they will take it, regardless of the reputation of the adversary.
If someone doesn't have a plausible alternative to a ransom, then they might as well pay it even if the chance is infinitesimal.
Since in either case, the behavior of the victim is unrelated to the level of trust they have in the criminal gang, there is no incentive to be "professional" and trustworthy.
This might not apply if the gang actually is tied to a nation state and/or has political motives.
But if they are purely profit maximizing entities, then they should not be expected to concern themselves with a reputation for keeping their word.
Somehow people forget that the victims don't choose who they are victimized by.
Legitimate question here.
Or, you know, anybody anywhere
At the very least, companies will be incentivized to improve security and reduce the pool of disgruntled engineers.
- Do you hire someone to give you a secure phone? But then, there’s only one link to subvert…
- Do you hire a security company to build a custom phone for you? But then, there are 10 engineers to trust and all the open-source dependencies they have,
- Do you purchase a standard iPhone by going to a warehouse and choosing the box yourself, because they can’t bug the whole pallet?
Who gets to push updates to your phone? Isn't that a fundamental property of most phones (yes even "dumb" phones) to be controllable remotely? Whether through (unisolated) modem firmware, or via the system's service such as Google Play Services?
So i'd say all in all it's not just that pallet that's bug, but the entire production line ;)
Does Bill Gates just have a standard phone? Do Macron and Merkel just have standard phones? I have difficulty imagining they run Apple’s image detection software.