What happens in practice is the victim hires a 'data recovery specialist' company, provides them the encrypted files, and ask them to decrypt them with their magic algorithms. The data recovery specialist coincidentally is paid a little bit more than the ransom. The specialist then contacts the hackers, pays the ransom, decrypts the files, and provides them back to the victim. Specialist, victim and maybe also law enforcement do their utmost best not to ask/explain how exactly the files were decrypted, citing e.g. trade secrets or an accidental key leak in the malware.
The data recovery specialist generally hires a contractor, who hires a contractor, who ... , so ransom money trail passes trough plenty of jurisdictions to darken the trail.
"As ransomware attacks crippled businesses and law enforcement agencies, two U.S. data recovery firms claimed to offer an ethical way out. Instead, they typically paid the ransom and charged victims extra."
https://features.propublica.org/ransomware/ransomware-attack...
Always a risky answer, of course, especially from some random person on HN. But in this case, it makes sense, and a 'long arm', international treatment is a general solution for powerfull entities needing to break a law.
I don't think you'll find anyone going officially on record as breaking the law, however. Most companies won't even let it leak they're a victim.
depends on jurisdiction, but if the ransoming organization is a sanctioned entity, it may be considered an illegal sanctions violation.
for instance, the US OFAC has issued this statement warning companies to not pay ransoms: https://home.treasury.gov/system/files/126/ofac_ransomware_a...
royal mail is in the UK, but the UK has its own sanctions regime with similar penalties.
edit: the UK OFSI has issued a similar warning this month
https://assets.publishing.service.gov.uk/government/uploads/...
Such laws run the risk of fostering a climate in which individuals frequently transgress established legal boundaries, with the authorities given free rein to target anyone they please on a whim.
This would inevitably lead to a breakdown of the rule of law and a culture of lawlessness that would imperil the rights and liberties of all citizens.
This is patently absurd, as there exists not only situations where its reasonable but an imperative to deal with organised crime.
Hackers gaining control over the space station and not only threatening the lives of the crew but also threatening to send it back to earth targeting a high population area.
I’d guess that’s also illegal, but IANAL.
The cost of dying is basically infinite, the cost of paying the ransom can be shifted up and down with fines until it is high enough to disincentivize paying.
Making the payment of ransom illegal just means you never hear about ransoms again.
So we should make getting mugged illegal, so long as the law is clear that the illegal part only applies if you have a reasonable way to get away from the mugging without paying. I'm not sure how you can be mugged and yet have a reasonable way to get away without paying, I leave that question to the reader.
What if you're skilled in hand to hand combat? Or what if you're familiar enough with firearms to notice the mugger's weapon looks fake? Would you then be legally required to attempt to fight back? Would a judge need to estimate your probability of dying, and if it was under some threshold you would be punished for not attempting to fight?
I can't imagine their S3 bill is above 80 millions...
The intent would be to put pressure on national legislatures to repeal laws that make paying ransoms illegal. Smart ransomware groups don't care about targets that can't afford to pay. So any "inability" to pay is either the result of stubbornness or a law, both of which can change if enough pressure is applied. Of course, the solution is for businesses to harden their systems enough to resist these sorts of intrusion in the first place.
Completely legal.
I do believe that if the "market" for victims shrinks, naturally the number of ransomware attackers will shrink - sure, ransomware is "easy", but perhaps there's easier cybercrime to be committed with better odds. (I'm not sure how likely this is - I bet the ransomware scene is nowhere near saturated)
* pay enough in IT to run an up to date, secure system
* pay enough in ransom to get your files
* eat the cost of losing your files
Adding a possible fine to the middle one means the cost of the top and bottom ones can be higher. Either non-paying option makes the business of running ransomware schemes less viable.