Son Dakika
DEIrankrieg: USA starten erneut Angriffe gegen Iran, Huthis schießen auf ÖltankerDEPolizei-Großeinsatz in Zwickauer Innenstadt nach Hinweis auf StraftatDETrump droht Iran mit Zerstörung von Infrastruktur bei Angriffen in Hormus-StraßeDEMutmaßlicher Epstein-Vertrauter Daniel S. tot in Frankreich aufgefundenDEAlphabet übertrifft Erwartungen und erhöht KI-InvestitionenDEUSA greifen Iran weiter an - Huthi beschießen Öltanker im Roten MeerDETesla steigert Autoverkäufe, Gewinn sinkt – Fokus auf Robotaxis und FusionsspekulationenDEUSA und Saudi-Arabien schließen Atomabkommen zur zivilen NutzungDEKriegsminister Hegseth relativiert Erfolgsmeldungen im Iran-Krieg vor dem SenatDEArbeitgeberpräsident Dulger kritisiert AfD und fordert ReformenDEIrankrieg: USA starten erneut Angriffe gegen Iran, Huthis schießen auf ÖltankerDEPolizei-Großeinsatz in Zwickauer Innenstadt nach Hinweis auf StraftatDETrump droht Iran mit Zerstörung von Infrastruktur bei Angriffen in Hormus-StraßeDEMutmaßlicher Epstein-Vertrauter Daniel S. tot in Frankreich aufgefundenDEAlphabet übertrifft Erwartungen und erhöht KI-InvestitionenDEUSA greifen Iran weiter an - Huthi beschießen Öltanker im Roten MeerDETesla steigert Autoverkäufe, Gewinn sinkt – Fokus auf Robotaxis und FusionsspekulationenDEUSA und Saudi-Arabien schließen Atomabkommen zur zivilen NutzungDEKriegsminister Hegseth relativiert Erfolgsmeldungen im Iran-Krieg vor dem SenatDEArbeitgeberpräsident Dulger kritisiert AfD und fordert Reformen
Newsgather
GeriCompanies Paying Ransomware Demands Often Face Second Extortion, Report Finds
Companies Paying Ransomware Demands Often Face Second Extortion, Report Finds
Teknoloji
TechCrunch1 saat önceTeknoloji1 dk okumaUnited States

Companies Paying Ransomware Demands Often Face Second Extortion, Report Finds

A Proofpoint survey reveals over one-third of companies that paid hackers were hit with a second demand, highlighting the risks of negotiation.

Hızlı Bakış

  • A Proofpoint report indicates that over one-third of companies paying hacker ransoms are subsequently hit with a second extortion demand.
  • The findings underscore the evolving nature of ransomware attacks, which now often involve multiple leverage forms like threatening to release stolen data, as seen in incidents involving Klue and Change Healthcare.

Yapay zekâ özeti

Neden Önemli?

Governments have long warned against paying hacker ransom demands, arguing it funds criminal activity and does not guarantee an end to extortion.

Yazı boyutu

Governments have long warned not to pay a hacker’s ransom demands, arguing that doing so only lets criminals profit from their cyberattacks and funds the next one. There’s also another reason: The hackers are unlikely to leave you alone if you pay up once, and many will come back demanding more.

In a report published Wednesday, cybersecurity giant Proofpoint said it surveyed 953 companies and found that over one-third of companies that paid a hacker’s ransom were hit with a second extortion demand. The findings underscore the long-held understanding among security researchers and network defenders that it’s impossible to negotiate in good faith with an extortion racket because there’s no incentive for the other side to actually walk away.

Proofpoint’s data shows that ransomware attacks and extortion attacks have evolved from a single transaction where hackers would get paid once and move on, into an effort using multiple forms of leverage, such as retaining stolen data under the threat of publicly releasing it.

While hackers have claimed in the past that they will delete or destroy the victim’s stolen data, past incidents have shown that not to be the case.

Last month, a hack at market research firm Klue exposed data belonging to its customers, including several cybersecurity firms. The company said it struck a deal with the hackers, who claimed to have deleted the data, but the company later conceded that a separate hacking group swiped a sample of the company’s stolen data, leaving its customers exposed to potential future extortion demands.

A similar situation befell Change Healthcare in 2024, after a Russian-speaking ransomware gang stole the health and medical data of the majority of people in America, some 192 million people. Amid a dispute between the hackers and their affiliates (criminal groups often subcontract out attacks), Change Healthcare paid separate ransoms to both groups of criminals to keep the sensitive medical data off of the internet.

Açık Sorular

  • How many companies choose not to pay a second ransom?
  • What specific measures are most effective in preventing re-extortion?

İlgili Konular

Bu haber ilk olarak şurada yayınlandı: TechCrunch.

İlgili Haberler

Bu konuda daha fazlaransomware