Nobody needs to know who anybody else is - just "here's our ransomware, any ransom paid that mentions your unique ID, we'll split with you. Have fun"
Crowdsourced criminality.
Nobody needs to know who anybody else is - just "here's our ransomware, any ransom paid that mentions your unique ID, we'll split with you. Have fun"
Crowdsourced criminality.
It's a sort of prisoner's dilemma problem - since the game won't be repeated with any single employee, and there's no communication between employees, the gang gets a better outcome in all cases by not paying.
I'd bet on the employee getting scammed too.
You don't even have to time it perfectly. In six months, when they're most upset and seeking revenge they'll remember the email
For me it's not hard to believe at all that someone who is already at a low point and motivated with malicious intent would read up on such an offer and think to themselves "I can screw my boss __and__ get a cool million in etc? Just for 'accidentally' uploading some ssh keys with a misplaced wildcard?"
Even before the covid pandemic, stress in IT was high and disgruntled employees doing damage on the way out was making headlines. Search 'Disgruntled employee destroys data' on google and check the date of some of the news articles. Here's one that made US national news in 2014 about how data theft was a trend.[0]
Whether or not there's a real payout is of no consequence it seems. I'm only able to immediately find articles about such incidents in the US and the UK, but I am fairly sure it's not limited to such locations, or that outsourced IT isn't just as vulnerable.
I've written it before on HN for other reasons, but people like to talk about new laws/standards/etc, but IT doesn't have problems that need legal solutions, as an industry, IT needs to improve discipline across the board and stop letting situations where one person can be so destructive happen. Too many places still run their IT like it's the 80's/90's where one or maybe two with absolutely control over everything. This leads to burnout first of all, which is horrible, but it also creates these bad situations of unregulated control in the first place.
[0] https://www.wsj.com/articles/fbi-warns-of-rise-in-disgruntle...
I mean, it's like having the neurosurgeon at the hospital retire/quit for a software company to lose it's IT.
The issue is, many software companies don't know/think they are a software company.
Ugh feels so dirty even saying it, I guess that's why sociopaths win so often.
"we paid this other guy and he got caught"
"come join us!"
Many companies that get hacked get hacked again anyway. With the help of an insider, an attacker could more effectively around any new countermeasures, too.
https://www.zdnet.com/article/lightning-does-strikes-twice-i...
Aside from bugs in the contract, or opsec concerns, the main risk (for the saboteur) would be the ransom folks directing the victim to pay some other address that wasn't part of the smart contract, so no money ever comes into it. Really, it's only marginally more reliable than just depending on them to pay you when they get paid.
A similar dynamic is at play between ransomware attackers and their victims. Why would ransomware attackers restore files from a successful attack after the ransom is paid? Easy. The attackers need the world to know that paying the ransom will work, otherwise no one would pay it.
Why is a ransomware company going to follow the rules of common decorum when dealing with a collaborator if the whole point is to defraud a third party?
How do I know that they made the payout? Is the collaborator going to come forward and identify themselves? The only way you know that person got paid is if they don't get arrested. There are whole branches of organized crime than live and breathe in the space between 'got paid and lived happily ever after' and 'ended up on the front page of the NYT'. Just off the top of my head you have blackmail, extortion, and hiding the body.
They need third parties to think that working with them is their best option. Their best option is to do something legal, but desperate people can be manipulated. Greedy people can be really manipulated. Maintaining the illusion of safety is just marketing.
If the game is extortion, then psychological manipulation is part of the game. I have no assurances that you've given me $1.4 million today and this is the last I will ever hear from you. If I know little about you I can't even turn State's Evidence to save my ass if I get caught but you don't. If I think I know that you or anyone with details of your operation won't come back later and threaten to turn me in unless I pay you money, then I'm a fucking idiot. You could ask for money, or to "deliver a package" for you. In that situation, what you and your associates are counting on me forgetting is that I am mortgaging my future by piling on new crimes with later statute of limitations dates, and establishing a pattern of behavior that makes me look even more complicit.
There is no honor among thieves. Stop trying to figure out how to pet a wolf without getting bit.
Victims of ransomware are public and will publicize if they don’t get their files back. An individual willingly trying to compromise their employer’s network is not going to publicize not getting paid because it will get him/her arrested.
They will anonymously post on the message boards dedicated to ransomeware gangs that this particular gang is not reputable. Like leaving a Yelp review, except even more trustworthy because it's a relatively tight-knit community.
It would only work out for the gang if the ransom was enough money they decide to "retire" and not pay out. In all other situations, they need their reputation.
And why would someone believe an anonymous post? Don’t you see the problem here?