Analysis: Ransomware's Costly Impact episode artwork

EPISODE · May 1, 2020

Analysis: Ransomware's Costly Impact

from Info Risk Today Podcast · host InfoRiskToday.com

The latest edition of the ISMG Security Report analyzes the rising costs of ransomware attacks and the latest victims. Also featured: An assessment of Australia's new contact-tracing app designed to help battle the spread of COVID-19, and a discussion of applying the "zero trust" model to the remote workforce.

Episode metadata supplied by the publisher feed · Published May 1, 2020

Embed this episode

NOW PLAYING

Analysis: Ransomware's Costly Impact

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

The scourge of ransomware attacks on the public sector, contact tracing goes live in Australia, and the leap to zero trust in the age of the remote worker. These stories and more, and this with ISMG security report. Hello, I'm Nick Honda. You might think that in the event of a global pandemic where literally everybody everywhere is at risk, that cybergrills may show a little bit more empathy and consideration for their fellow human beings.

And you'd be wrong. Not only are ransomware attacks showing no signs of a decrease in velocity, the average payout for an attack is increasing. And according to new research, prime targets are increasing in the public sector, including states and local governments, schools, and maybe the most perverse of all hospitals. With a story, his honest executive editor takes a reach today in Europe, Matthew Schwartz.

Ransomware continues to be a reliable moneymaker for criminals. In the first quarter of this year, the average ransom paid by victims to ransomware attackers reached more than $111,000. According to ransomware, incident response firm Coveware, that amount represented an increase of 33% from the prior order. It was largely driven by attackers wielding REUC and so did no keybeat ransomware, Coveware says.

After certain keybeat REUC, the most common ransomware infections that it investigated involved at Phobos, Dharma, Mamba, and Globe and Postor. The industries being targeted by ransomware attackers have been shifting slightly. In the main, they continue to be small in mid-sized professional service firms, such as law firms, IT managed service providers, and certified public accountancies. But increasingly, attackers have also been gunning for public sector organizations, including state and local governments.

Schools, however, are being particularly targeted. Indeed, about one in 20 infections investigated by Coveware in the first quarter of this year, schools typically get targeted in the summertime when they're under pressure to get their systems back up and running before students return. With the ongoing COVID-19 pandemic, however, schools appear to be an especially attractive target for attackers, as students study remotely. The healthcare sector is also not immune.

Some ransomware operators had pledged to not target healthcare organizations or to provide them with free decryptors if they got hit. But Coveware reports that the average downtime following any successful ransomware infection is about 15 days. So even if attackers were honoring their promises to provide free decryptors, they'd still be causing dangerous disruptions, not to mention continuing to hit essential supply chains. Unfortunately, some groups appear to be actively targeting hospitals, and especially attackers really re-uke, doppelpamer, and D4A777 ransomware.

Another trend we've been seeing in recent months is ransomware operators stealing data and threatening to leak it unless victims pay. The maze group first blazed this trail late last year, and 99% of its cases evolved data exfiltration, Coveware says. More recently, however, it's found that the gang's been changing tactics to target smaller businesses and exfiltrating less data. Following in these footsteps, however, some other gangs have been using this data exfiltration tactic in recent months, including Senator Kivi, doppelpamer, Mespenoza, Netwalker, Clop, Nephilim, and Segment.

Some have dedicated sites where they'll attempt to name and chain victims, and post extracts of stolen data. Others send excerpts of the data directly to victims. In an interview, Coveware CEO Bill Segal told me that it's still not clear if this data exfiltration strategy leads to more frequent payments to attackers. But he did tell me that he doesn't think it leads to higher payments.

Looking at the bigger picture, when it comes to paying a ransom to attackers for the promise of a decryption tool, law enforcement agencies and security experts agree. Don't do it. Paying a ransom directly funds cybercrime. Also, if attackers do share a decryption tool, it's not always effective.

That's just one reason why experts recommend that all organizations have in place the right defenses, including well-tested backup and recovery systems, to ensure that they never have to pay a ransom. But as ransomware-wielding attackers continue to accumulate a massive number of new victims, it's obvious that not everyone has the right defenses in place, or the time to try and restore their systems. For Information Security Media Group, I'm Matthew Schwartz. You're listening to the ISMG security report on ISMG Radio, ISMG, your number one source for information security news.

As we discussed in last week's podcast, contact tracing for COVID-19 exposure could be an incredibly powerful tool in monitoring and mitigating the spread of the disease. However, tracking the exposure of infected individuals using smartphones, either overtly or covertly, could be considered a significant infringement of personal privacy rights. The Australian government has recently released such an app, and while its early days of use is seeing significant traction with the general public. With more on the story, is ISMG's managing editor security and technology, Jeremy Cook?

This week, the Australian government released a contact tracing app called COVID-safe. The nation joins a handful of countries seeking a hopeful path out of lockdown through technology. Privacy experts and programmers have been giving COVID-safe a workover, or at least as much as possible without its source code. COVID-safe isn't perfect, but it isn't necessarily terrible either.

Understanding why plunges us into what is shaping up to be a privacy and security debate like no other, can contact tracing apps blunt the speed of a pandemic and what slivers of privacy are we giving up. Australia's program has many positive aspects. It's not mandatory to use it. Also, the government has prevented employers from making its use mandatory as a condition for coming back to work.

COVID-safe doesn't collect precise GPS location data. Rather, it's a proximity detector. It uses Bluetooth to detect other phones in range. If two people come within 1.5 meters of each other for longer than 15 minutes, that is regarded as a contact and is logged.

If someone is diagnosed with COVID-19, that person voluntarily uploads their contacts to local public health officials who then call those contacts. Neither the infected person nor the contact learn the identity of each other. But Australia's system is a centralized model. The contact data from people's phones goes into a national data store hosted on AWS.

Although that's off-limits to anyone but local health officials, those officials, or someone who has access to it, could see if two people have interacted. They wouldn't know where the contact occurred, but even seeing who a person has been near could be as revealing as where that happened. At a code level, experts have found potential privacy issues. For example, when contact data is exchanged, that is encrypted, but a person's phone model is not.

It means that an attacker with physical access to a phone and the ability to crack open the app logs could see that information, which could be revealing. That's an advanced attack scenario, but it was also enough for Australia's peak body for domestic violence to issue an advisory about it. The alternative is a decentralized model, which Germany has pivoted to in Ireland will use. It's also supported by Apple and Google's joint project.

In a decentralized setup, contact matching is done on the phone and knows central authority has access to data. If Australia had opted for a decentralized model, it would have rendered moot the concerns that a police could use the system for other purposes. As it stands, Australia has pledged to pass new laws to prevent non-health agencies from using the data. If Australia had gone with a decentralized model in the first place, that wouldn't be necessary.

Many commentators have rightfully expressed concern that the app was rushed out before those controls were in place. Stacked against other initiatives, the drawbacks of Australia's system do feel less scary. A state in India has an app that uses GPS data to detect if someone in quarantine has strayed too far from their home. South Korea is using GPS, credit card data, and CCTV footage for tracing.

I've downloaded COVID-safe. For me, the benefit of winding back the daily restrictions is more appealing than the risks right now of anyone knowing who I've been around. But that's not to dismiss the concerns of privacy experts with COVID-safe. We need their deep examinations to know every point of risk, however fine.

Everyone's tolerance for risk varies according to their personal circumstances, and we almost respect that. In the end, epidemiologists may find that automated contact tracing just doesn't work that well. If that's the conclusion, let's hope we haven't opened a new door to surveillance that will never be closed. For Information Security Media Group, I'm Jeremy Kirk.

But all companies are different, and some are faired better than others in this transition. All right, so if you're managing editor of news desk, Scott Ferguson, spoke this week with Jim Revis, CEO with Cloud Security Alliance, about what his members are experiencing with recent work from home transition, and the explosion of software defined perimeter and zero trust. Here's an excerpt of that conversation. Zero Trust is huge now.

The members are talking about the lot, and so software defined perimeter and zero trust, which are very complimentary. Some real overlap there. Software defined perimeter allows you to sort of take some public cloud and turn it into a virtual private cloud, some call it a black cloud that only your organization can see, and zero trust provides that ability to just really be very granular and not allow anything to have access to your key assets unless you specifically identify an identity management becomes a big part of it. So it's blowing up.

There's a lot more interest to do that. The issue is some applications. I'd say if you look at the very common SaaS applications, the well-known PICSA, the top hundred applications, it's pretty out of the box to go implement that. Some of the issues we've seen in this rush is that a lot of custom built applications that enterprises have done in infrastructure service, it takes a little more work, a little more knowledge to make sure that they have protected in the right way.

There's some tweaking they need to do and some policies and things like that. So the very popular SaaS applications, enterprise SaaS applications, I'm thinking of for the most part, they've been able to put on that zero trust layer pretty well. The infrastructure's a service. It just takes some time.

The organizations that really already had this designed, they've done pretty well and they've had a lot less kick-ups so far. That's it for this week's Ice and Security Report. Theme music is by Ethan Corio. I'm Nick Collins.

Catch you next time.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on May 1, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!