Royal Mail dismisses ‘absurd’ $80M ransom demand
theguardian.com
theguardian.com
The ransomers sound like kids, "speculating that the directors personally held 100m of crypto"? What a disgusting amateur job.
(Of course these criminals are disgusting.)
I don’t think the ethics of the operation are high on the list of considerations.
These attacks happen all over the West, you only know about this one because the negotiation was leaked. Lots of public service providers are targeted, such as universities for example. The actual scandal is that this gets hushed up, if the people knew the scale of these attacks they might think we're in a sort of digital war.
The intent would be to put pressure on national legislatures to repeal laws that make paying ransoms illegal. Smart ransomware groups don't care about targets that can't afford to pay. So any "inability" to pay is either the result of stubbornness or a law, both of which can change if enough pressure is applied. Of course, the solution is for businesses to harden their systems enough to resist these sorts of intrusion in the first place.
Completely legal.
I do believe that if the "market" for victims shrinks, naturally the number of ransomware attackers will shrink - sure, ransomware is "easy", but perhaps there's easier cybercrime to be committed with better odds. (I'm not sure how likely this is - I bet the ransomware scene is nowhere near saturated)
* pay enough in IT to run an up to date, secure system
* pay enough in ransom to get your files
* eat the cost of losing your files
Adding a possible fine to the middle one means the cost of the top and bottom ones can be higher. Either non-paying option makes the business of running ransomware schemes less viable.
depends on jurisdiction, but if the ransoming organization is a sanctioned entity, it may be considered an illegal sanctions violation.
for instance, the US OFAC has issued this statement warning companies to not pay ransoms: https://home.treasury.gov/system/files/126/ofac_ransomware_a...
royal mail is in the UK, but the UK has its own sanctions regime with similar penalties.
edit: the UK OFSI has issued a similar warning this month
https://assets.publishing.service.gov.uk/government/uploads/...
Making the payment of ransom illegal just means you never hear about ransoms again.
So we should make getting mugged illegal, so long as the law is clear that the illegal part only applies if you have a reasonable way to get away from the mugging without paying. I'm not sure how you can be mugged and yet have a reasonable way to get away without paying, I leave that question to the reader.
What if you're skilled in hand to hand combat? Or what if you're familiar enough with firearms to notice the mugger's weapon looks fake? Would you then be legally required to attempt to fight back? Would a judge need to estimate your probability of dying, and if it was under some threshold you would be punished for not attempting to fight?
What happens in practice is the victim hires a 'data recovery specialist' company, provides them the encrypted files, and ask them to decrypt them with their magic algorithms. The data recovery specialist coincidentally is paid a little bit more than the ransom. The specialist then contacts the hackers, pays the ransom, decrypts the files, and provides them back to the victim. Specialist, victim and maybe also law enforcement do their utmost best not to ask/explain how exactly the files were decrypted, citing e.g. trade secrets or an accidental key leak in the malware.
The data recovery specialist generally hires a contractor, who hires a contractor, who ... , so ransom money trail passes trough plenty of jurisdictions to darken the trail.
"As ransomware attacks crippled businesses and law enforcement agencies, two U.S. data recovery firms claimed to offer an ethical way out. Instead, they typically paid the ransom and charged victims extra."
https://features.propublica.org/ransomware/ransomware-attack...
Always a risky answer, of course, especially from some random person on HN. But in this case, it makes sense, and a 'long arm', international treatment is a general solution for powerfull entities needing to break a law.
I don't think you'll find anyone going officially on record as breaking the law, however. Most companies won't even let it leak they're a victim.
I’d guess that’s also illegal, but IANAL.
The cost of dying is basically infinite, the cost of paying the ransom can be shifted up and down with fines until it is high enough to disincentivize paying.
I can't imagine their S3 bill is above 80 millions...
Such laws run the risk of fostering a climate in which individuals frequently transgress established legal boundaries, with the authorities given free rein to target anyone they please on a whim.
This would inevitably lead to a breakdown of the rule of law and a culture of lawlessness that would imperil the rights and liberties of all citizens.
This is patently absurd, as there exists not only situations where its reasonable but an imperative to deal with organised crime.
Hackers gaining control over the space station and not only threatening the lives of the crew but also threatening to send it back to earth targeting a high population area.
It sounds like a case of normalized deviance, for which the management should be held accountable.
As much as I don’t like victim blaming, I think it’s beyond incompetent to still not backup your data in 2023 as a government org.
Though I think it’s even worse if a publicly traded company fails to protect its data and falls prey to the extortion. Don’t they have a fiduciary responsibility to their shareholders? It seems wrong to waste their money due to incompetence at such basic infosec.
Government orgs are more difficult to hold accountable for losses than PLCs.
I'd imagine that often your backups get encrypted as well, early enough that the data loss to the last good backup becomes unacceptable.
With huge GDPR fines for data leaks in Europe, the criminals are using the legal system as their 'threat'.
GDPR fines come from not following basic data protection practices, not for the breach itself. Also, a lot of reputational damage of the leak comes from bad infosec (case study: LastPass). If the customer data is reasonably protected, there isn’t much motivation to pay ransoms.
Companies have data breaches all the time. Even a start-up I worked in in GDPR times had a data breach, and an extortion attempt. But all customer PI data was encrypted and only ever in plaintext on our end in an ephemeral way. The data was worthless, we never paid ransoms. We bought some darknet monitoring service for some fake canary user data, but nothing ever came up in 4 years after the breach. No ransom was ever paid and honestly, the data breach was on our minds for 10 days max.
This is not hard to do, it was done by two business guys who listened to infosec podcasts and read infosec articles online. Specialists in the area that I’m sure all of these ransomed big businesses can afford can definitely do much better data protection.
I don’t think companies are sued/prosecuted for GDPR non-compliance or any damage done to their customers if hashed blobs get leaked. Assuming the hackers even bother to leak them, because what are they going to say in the forums they sell the data on? “I have unknown encrypted data about some hashed usernames from company X”? Maybe one day in the far future that data will hold some value, but not today. I would more easily see investors suing the management for paying ransoms instead of doing even rudimentary data protection.
Because unless you actually restore your system from backups regularly, you don't actually have backups.
Setting up a system wherein you restore from backups regularly requires, time, effort and money. None of which you are likely to receive for a "mere backup system".
It is crazy the number of companies that do not have appropriate visibility of what they're backing up. If the backups are immutable and if they have ever tested their ability to recover the environment.
And when I say the environment I mean all necessary components of the environment, not just applications, but their databases, Active Directory/Domain, DNS, DHCP, File servers, virtual infrastructure (VMware/HyperV).
In a virtualized environment the backup of these components is made easier, but you still need to understand what makes up your environment in order ensure you're backing it up appropriately.
Sometimes they have backups, but once they're forced to test them, realise they weren't backing up the right components or simply couldn't recover from those backups.
It's a big, risky exercise to perform, but important.
If the Russian STATE did this yes. But we don't generally consider the act of citizens/organizations/criminal enterprises within a state as a state action unless it's clearly state sponsored. You definitely could make that argument, but it's not a given.
For example, we don't consider the 3000 British people fighting alongside Ukraine against the Russians [1] to be part of the UK state, so their fighting isn't an act of war either.
[1] https://news.sky.com/story/ukraine-war-3-000-british-volunte...
[1] https://www.healthcareitnews.com/news/fbi-disrupts-hive-rans... [2] https://therecord.media/canadas-largest-childrens-hospital-s...
So IMHO the issue was miscalculating leverage.
the hackers already threatened going nuclear by releasing files and letting Europe fines their 0.5% which is more then 80M.
This is not over and Royal Mail is in a lose/lose situation here
Its an international agreement which has come back to bite the UK because China is still classed as a 3rd world country.
Lets just say the globalist's who set the rule's are finding their rules are now not so good.
"The new 1969 agreement included terminal dues, the receiving postal agencies would charge the country of origin for delivering the post on by-weight basis.
To be blunt, shipping from China to USA (and most of the rest of the world) is much cheaper than shipping domestically in USA because the terminal-dues are much too low and account only for the total weight of the post, not for the number of items.
For example, in 2013 China paid $1/kg (or $0.50/lbs)[1] to have post delivered in USA. This is MUCH lower than domestic pricing, especially if it’s light-weight objects.
As an example, I just ordered a new wristband for a watch I own from China. I just weighed it, and it weighs 78 grams. That means China would pay less than 8 cents to have this wristband delivered anywhere in USA.
By comparison, sending the same weight in a domestic letter in USA[2] would cost 92 cents, or a factor of 11.5 more.
Reality is that this agreement now acts as a massive subsidy to especially China who produces a lot of low-cost low-weight products and can now deliver them to customers worldwide for a price much lower than local companies can.
This situation will persist until the relevant agreements are renegotiated. I’m frankly surprised that hasn’t happened already.
[1] https://archive.is/20121212225536/http://www.upu.int/en/acti...
[2] https://www.stamps.com/usps/postage-rate-increase/
https://www.quora.com/How-is-China-able-to-offer-free-worldw...
Those Spooky Hackers from Russia..... Is this what Trump called Fake News?
I've seen how security services can burn a stock market listed company for an agenda knowing the public have short term memories for some things, and share prices recover.
lol why even bother? After recent inflation, 8 cents is so close to zero we may as well give them free delivery.
Every country has their own currency, and some currency is more expensive than other currency's, so 1 British pound can buy 1.2 US Dollars, 1.12 Euros, 161 Japanese Yens and so on. The British pound is also the oldest central bank currency in the world.
So when someone buys something made abroad, they are buying into Child Abuse and Slavery.
Unfortunately, our Govt's also force people into this situation by putting things like govt services online when considering how much of todays tech is made in country's with questionable legal frameworks.
And all the while is also draws attention away from the financial system that cant make its mind up, how its going to evolve to fulfil its social contract and obligations with the public because some people cant relinquish power masquerading as knowledge.
Its all chicken and egg situation stuff.
[0] https://www.cep-research.com/news/usa-claims-total-victory-i...
[1] https://www.parcelandpostaltechnologyinternational.com/featu...
Council was hit with ransomware, they went back to pen and paper for everything. They lost track of who lives there and when moved out. They kept resending overdue bills to addresses threatening debt collects to people who moved out. The council said they will still collect council tax once they are operational and it's your responsibility to have money ready for such situation. Even now there are comments on /r/UKPersonalFinance people complaining on getting incorrect bills.
Good luck!
https://www.click2houston.com/news/local/2023/01/05/tomball-...
And cryptocurrency is the main enabler of the ransomware attacks as well.
In most jurisdictions, at least in Europe (and I think the US, but feel free to correct me if I'm wrong), you take it up with the merchant as they're the ones who hire the delivery service. Your contract is with the merchant, and if they fail to provide the product for whatever reason—such as the delivery service not following through—then they're the ones who are responsible for making you whole.
If Amazon refuse to refund, then your recourse if to take them to court. It sounds like it's a small enough purchase that small claims would handle it.
Amazon support eventually refunds basically anything if you are persistent enough.
I’ve gotten refunds for parcels lost in 2020-22 even if I was denied them initially. It’s Amazon’s strategy to deny initially.
They can sue in small claims.