17 ms·
University of Utah pays $457k to ransomware gang
- caddie 6y agoWhy would a university have so much cash laying around? Oh yeah, it's in the business of making money with a side effect of MAYBE educating people. SO DAMN WRONG. Time to hit the RESET button in the higher education system in USA.
- colejohnson66 6y agoWhile I agree with you, is half a million dollars really that much money for a university to have? Not to mention that U of U is not private; they’re publicly funded by the state.
- trillic 6y agoU of Utah has an operating budget of nearly $5 Billion so having a couple hundred grand in cash isn't exactly a lot.
- apta 6y agoAren't public universities much cheaper than private ones?
- werber 6y agoFor the most part, that’s true for in state tuition but the costs up if you’re out of state or international to the point they can rival many private institutions.
- ocdtrekkie 6y agoThe article states the ransom was paid by an insurance provider. Cyber insurance is actually not uncommon these days, and is presumably a normal part of their annual budget.
- jaclaz 6y agoYes, I often wonder about two things: 1) How much is the actual insurance rate for such a guarantee? 2) Which kinds of checks the insurance provider makes on the security of the setup, I mean in a much more common car theft case the insurance provider requires that the user has not left the keys in the car and that the car was locked (evidently balancing the risk against the "normal" provisions the car manufacturer has implemented and on "correct standard procedures" by the final user).
- eli 6y agoBoth questions are related and the answer is "it really depends." Small business cyber insurance can be a few thousand dollars a year. I'm sure you can get a better rate (and at some scale it probably becomes almost required) to have pen tests and third-party audits and formal certifications.
- jaclaz 6y agoThanks, I know that "it depends", but a few thousands a year is just a (vague) number, as well as how much small is the small business is to be agreed upon and - very likely - small businesses are "easy wins" for insurance companies, not because they have better security, but rather because they are very unlikely probable targets. I wondered about what would be rates (order of magnitude) and on what they would be calculated. To give you an example, AFAIK if you were to get insurance, so called "Contractors All Risk" for a building project, you could expect anything between 0.7 and 1.5 % of the value of the project, on average around 1.1-1.2 % over the usual 5-6 years of duration, with the lower end about (relatively) low risk projects (roads without particularly complex contructions and normal houses) and the higher end on (relatively) high risk ones (roads with bridges, tunnels, skyscrapers). These can be negotiated a bit, based on experience on past projects, internal safety and quality assurance procedures, but the order of magnitude remains in that range, but in case of an accident/claim, not entirely unlike the car theft example, but much more complex, you need to prove that you followed all safety and employment regulations, respected building codes, that machinery was efficient, etc.. In the case of IT, rates for a given firm/institution would depend on the invoicing or on the amount of personal data? I mean, you can make 1,000,000 US$/year with 10,000 customers (personal data) at 100 US$ each/year or with 50 customers at 20,000 US$ each/year. And what kind of "good practice" would you need to prove (if any)?
- marcinzm 6y agoLike any entity that wishes to not fail miserably at the next recession universities have cash reserves and investments. It'd be rather stupid of them not to since their income can be impacted by outside events (cough covid cough) and they wish to survive long term (more so than corporations). To that same effect donations go into an endowment which allows for stable long term income to be generated.
- mensetmanusman 6y agoJust think, they could have paid two engineers to fortify their systems against such an attack and still saved lots of money.
- lern_too_spel 6y agoHow do you know they weren't already paying at least two engineers to fortify their systems?
- mensetmanusman 6y agoHmm. I’m guessing not having backups means they may have been paying one person but also giving that person way too many responsibilities such that they couldn’t focus on doing a backup well.
- jaclaz 6y agoThey did have the backups, the ransomware was paid for (maybe) not having the stolen data published/sold. >The university said its staff restored from backups; however, the ransomware gang threatened to release student-related data online, which, in turn, made university management re-think their approach towards not paying the attackers.
- Klinky 6y agoEven worse, because we can totally trust data can't be copied or released once an extortionist ransom is paid to malevolent hackers. I am sure this ransomware gang is on the up and up and operating in a good faith to honor the agreement. In a few months we may see "University of Utah pays another $457k to the same ransomware gang".
- AnIdiotOnTheNet 6y agoIt is not in the best interest of the ransomware gang to ignore their part of the bargain. If that second headline happens, it will be a signal to every one of their future victims that they will not honor agreements and you're better off not paying them. This is why the vast majority of encryption-based ransomware puts a lot of effort into ensuring they really can decrypt your files after you pay them.
- api 6y agoThey paid 457k for not having backups.
- lern_too_spel 6y agoThey had backups. They paid $457k for a pinky promise not to release private data.
- panpanna 6y agoOh wonderful. Now we will see more of these types of attacks.
- dmd 6y agoTo be fair, it's a pinky promise where the attackers know that if they ever break one of these promises, nobody will ever pay them a dime again.
- lern_too_spel 6y agoThey can make it a monthly subscription to get recurring revenue.
- lotsofpulp 6y agoRaaS.
- notahacker 6y agotbh that's not necessarily the case since the attackers are anonymous. It's just they don't actually have much incentive to release the records once they've collected their blackmail money.
- c22 6y agoThey can just change their name next time.
- frank2 6y ago
- iandev 6y ago> "The university's cyber insurance policy paid part of the ransom, and the university covered the remainder. No tuition, grant, donation, state or taxpayer funds were used to pay the ransom" I was looking to dunk on them but it seems that what they did wasn’t entirely unreasonable. The article further states that they paid to protect student data.
- Lionga 6y agoWhere did the money come from if not from "tuition, grant, donation, state or taxpayer funds"? And if they have another source of funding, this still means the money is missing to fund things in the future that now they have to use "tuition, grant, donation, state or taxpayer funds" for. They also send a clear message that ransom ware blackmail is a great business model. I think that is more than enough reason to dunk on them.
- pc86 6y agoNo you don't understand, they didn't use that money, they used different money! Nevermind that money is fungible. Unless they set money in the budget every year for "Ransomware Insurance Shortfall" this is 100% "tuition, grant, donation, state or taxpayer funds" at some point in the chain.
- akeck 6y agoCan one detect a ransomware infection early by watching copy-on-write snapshots on a file server?
- gpm 6y agoYou can, the company I work for makes a product that does exactly that. It's very much a last line of defense way of detecting attacks because it means the attackers are already in and already have access to whatever workload is being protected. https://www.rubrik.com/en/products/polaris-overview/polaris-radar https://www.rubrik.com/en/products/polaris-overview/polaris-... Disclaimer: I'm just an engineer (not a sales person/pr/...) and all my comments on HN including this one are entirely my own views/not the companies views.
- AnIdiotOnTheNet 6y agoThere are various strategies. One way that is fairly common is to have canary files that, when modified, trigger alerts and other automated action (locking out the account that did the modification, for instance).
- bpoyner 6y agoVeeam One can alert you to possible ransomware if there is simultaneous high write rate and high CPU usage on a VM.
- freeopinion 6y agoNot all ransoms are about denying the owner use of their data. Some ransoms are about publishing copies of the data.
- amelius 6y agoIt's good to be aware that this entire thing wouldn't have been possible without Bitcoin.
- Forbo 6y agoIt's good to be aware that this entire thing wouldn't have been possible without encryption. I'm sorry, I'm not sure I'm seeing what point you're trying to make. Are you trying to say that Bitcoin is bad?
- panpanna 6y agoBitcoin was sold to me as freedom, from governments, from banks, etc. But now I have come to realize that a completely unregulated payment system is very dangerous. To be clear, Bitcoin is not "bad". Humans are bad and this is why we can't have nice things.
- 1123581321 6y agoIn what way did you buy into Bitcoin? I don’t understand what choice was presented to you. If you’re referring to why people like it, those things can all be true despite criminals also using it.
- zelly 6y agoBitcoin is more regulated and more spied on than most forms of payment. To turn a large amount of Bitcoin into dollars in a bank account, you have to go through extreme AML/KYC checks. I can go to a gas station in California and send $1000 in cash to someone in Turkey who could receive cash and walk out a few minutes later. A briefcase full of cash is not regulated at all and can be used to settle debt or pay taxes, unlike Bitcoin. The only advantage of Bitcoin is not requiring the risk of physical presence, which has to be <1% of all crime. Also, unlike cash, Bitcoin by design retains a full immutable public ledger. The criminals can mix their coins, but it'd still be possible (although computationally expensive) to recreate a chain of transactions going back to the original ransom. In the future if Bitcoin is to become used in commerce more, it should be expected that these dirty transaction outputs would be worth less than clean ones or not accepted, like dollar bills cut in half taped together.
- sho 6y agoDevil's advocate: ransomware is good. The financial incentives around it directly encourage this variety of hacking. It's an involuntary "bug bounty". And IT security becomes something more than a "nice to have" for these institutions, which it never would have before. $450k? Universities know all about paying to learn. That's cheap, and they won't make the same mistakes again.
- edflsafoiewq 6y agoCrime reduction is good. Therefore crime is also good because it incentivizes crime reduction.
- paulpauper 6y agomurder is good because it discourages people from engaging in behavior that may cause them to be murdered
- dempseye 6y agoIs this not the rationale behind the death penalty?
- AnIdiotOnTheNet 6y agoActually, depending on the cost of mitigating this sort of disaster in the future, they may learn the lesson that it is simply less expensive to pay the ransom. The criminals doing these sorts of things are businesses too, the are unlikely to price themselves out.
- rubber_duck 6y agoNonsense, it's not like it's one criminal group behind this or like these people are building a sustainable business model. Pay and ignore approach doesn't work at all long term.
- sho 6y agoWell, that is a decision every institution needs to make by themselves, of course. At least now there is a visible price tag attached, rather than trying to hide behind misuse laws ("it's ILLEGAL to access our systems in that way!")
- 0xbkt 6y agoOut of curiosity, are these hackers still demanding ransom money in Bitcoin, or say any traceable cryptocurrency? I remember encountering similar scenarios before and they all seem to want the money in a Bitcoin address. Why not Monero, or an alternative if there is any, which I guess makes moving the funds around much more stealthily? Please correct me if I'm wrong.
- voxic11 6y agoFor smaller scale ransomware bitcoin was and still is very popular because its the easiest crypto to buy and use. So if your average target is a non-technical home or small business user bitcoin will net you far better returns. Ransomeware still often includes live phone support and other features targeted at helping victims purchase and send bitcoins because its still a difficult and unfamiliar task for the average person.
- markkanof 6y agoThat's so disturbing. I can't imagine going through a phone call with "tech support" trying to figure out how to send bitcoins knowing the whole time that the support person is the one who is extorting ransom from you. It also seems like an opportunity to escalate the scam to the next level. Go to this site (controlled by the scammer) and enter your credit card to send bitcoin. Now they have your credit card too.
- colinmhayes 6y agoThis is how I feel on the phone with comcast. It's just business
- jpkoning 6y agoThey're still usually asking for bitcoin. A few months back REvil/Sodinokibi switched to Monero, but I think they're the only strain to do so.
- paulpauper 6y agono one is getting arrested or caught in spite of the traceability, unless the hacker is dumb enough to just deposit the BTC on an exchange immediately. The btc is split up and sent through mixers and laundered into thousands of tiny pieces and after a few years or so forgotten by anyone trying to track it.
- frakt0x90 6y agoI have to say I think ransomware is one of the most interesting "business" practices. The trustworthiness of the criminals is huge because if they have a track record of providing the decryption key, you may as well pay. In a logical extreme you could start adding features like "Give us the info of people you know and for every one we successfully extract a ransom from we'll give you 10% off your ransom." It's interesting to think about at least.
- HanayamaTriplet 6y agoThere was a story published by ProPublica[1] reporting on this sort of progression from the side of people negotiating to pay the ransoms. Here's a small excerpt, but I think the whole thing is worth a read: Storfer learned quickly never to use the term “hacking.” Instead, he would assume his correspondent “thinks they’re a businessman,” Storfer said. “I’d say: ‘Look, we can’t afford this [ransom] at this time. Do you mind providing your product [recovery key] at a lower rate?’ And it worked,” he said. “They’re doing a job where everyone hates them, so feeling like they were respected made them work with us. I like to think empathy goes a long way.” The rapport sometimes reaped discounts. “We were able to get a $5,000 ransom lessened to $3,000 because they knew we could deliver it exactly when we said we were going to get it to them,” Storfer said. [1]: https://features.propublica.org/ransomware/ransomware-attack-data-recovery-firms-paying-hackers/ https://features.propublica.org/ransomware/ransomware-attack...
- gowld 6y agoReads like someone bragging about being incompetent. I'm sure the foreign language native attackers who call themselves "Evil Corp" would respond to "non-business" negotiations as well. They don't want your data deleted, they want money.
- chillacy 6y agoReminds me of some of the stories in Never Split The Difference, where the author was a hostage negotiator for the FBI who would reduce ransoms (on human hostages) from millions to in one case, a few thousand. He relayed a similar reasoning, at the end of the day they want to get paid and a dead person is worth $0 (and potentially the swat team coming in).
- Hitton 6y agoYou really can't blame them much, they had backups. University doesn't work like corporate, you have thousands of student who change every year, do their projects for which they require lot of access; you can't lock everything dangerous, can't have any sensible BYOD policy, ... It's really hard to lock up everything while not limiting students too much. With organization like this, that sort of incidents is unfortunate but inevitable.
- _wldu 6y agoWe sometimes refer to a public university as having a museum-like security posture. They have to be open to the general public, have to allow in visitors, yet guard things at the same time. It's not at all like strict corporate IT security. It's a fine line to walk. If you've never done this sort of security work before, it can seem odd and foreign for awhile.
- tomashertus 6y agoPublic universities and their security budget are highly underfunded. They can’t afford to invest heavily into security.
- Scramblejams 6y agoIs it that they can't afford it? Or is it instead that they would need to reprioritize some of their spending to invest into security?
- leephillips 6y agoThey had backups: good for them. But they also had unencrypted, sensitive information sitting on their networks.
- leephillips 6y agoWhat if it were a federal criminal offense to pay ransom? With long prison sentences for any individual convicted of participating in or having knowledge of a payoff? And the government was serious about tracking down and prosecuting anyone who did so? Nobody would pay ransom, and, at least in countries with such a law, these extortion gangs would stop bothering.
- teachrdan 6y agoIf the ransomers are terrorists, then it is a crime to pay them. This has been a challenge when Americans are kidnapped overseas and their families wants to pay the ransom but are warned that doing so is illegal.
- kmonsen 6y agoThere are fairly easy ways to get around this. Everyone says they never pay ransoms, but they mostly do. It is not a ransom, but you hire some cousin to do a not existing project etc. These things happens in parts of the world where transparency is not a top priority.
- ryandrake 6y agoHow does this fool even a semi-competent lawman? “Oh, officer, I never bought drugs. That’s totally illegal. I just left money in a box that my cousin picked up, and a few days later the drugs just appeared there. Totally not, myself buying drugs, though!”
- renewiltord 6y agoBecause for drugs, the semi-competent lawman goes after you. If it's for my child's life, there's no point going after me. I'd go to prison for life for that. You can't apply prison as a deterrent, you can't use it to prevent me from harming others, and honestly, you can relate to me.
- hamandcheese 6y ago
- bluecalm 6y agoAt this point the government agency should perform some of those attacks, extort the money, make it public and then delete the data so the victim is out of data and the money. Paying ransoms is terrible for the world. We will have more attacks on more targets. There needs to be heavy incentive to not pay.
- renewiltord 6y ago^ things that will get you instantly unelected
- bluecalm 6y agoIt's not like advocating for strategies that work and make the world a better place get you elected anyway. It's all about making feel good promises anyway. Maybe you can convince someone already elected in their last term to actually implement it.
- folmar 6y agoNo one was up to admitting it happened in the first place.
- fizixer 6y agoWhen you pay ransom for physical possession you get your possession back. When you pay ransom for lost data you get a copy of your data back. The culprits still have the data, but they likely don't have a use for that data. But this is the worst kind of ransom. You already have the data, you're paying ransom to make sure the culprits don't use the data, but the culprits still are in possession of the data and they can use the data next year, or two years later, or demand more payment next year. What in the world?
- deleted 6y ago[deleted]
- parliament32 6y ago>The culprits still have the data It'd be too hard/expensive to exfiltrate the data once it gets large enough, without much added benefit. They just encrypt it in-place.
- beervirus 6y agoWell it's exactly what happened here. > The university said its staff restored from backups; however, the ransomware gang threatened to release student-related data online, which, in turn, made university management re-think their approach towards not paying the attackers. The university is paying them not to release the data, but it has no way of forcing them to delete it.
- paulpauper 6y agoThis shows how bug bounties are pitifully small and inadequate. Stop thinking that a $10k reward will prevent hackers. Either pay-up for sec experts or be prepared to pay-up through extortion or having your site exploited, and it will cost way more than 10k.
- beamatronic 6y agoOr have a bulletproof recovery plan
- edoceo 6y agoDisk clones to the rescue!
- iNate2000 6y agoThey said[1] that they paid to avoid the information release. A backup won't help with that threat. [1] https://attheu.utah.edu/facultystaff/university-of-utah-update-on-data-security-incident/ https://attheu.utah.edu/facultystaff/university-of-utah-upda...
- deleted 6y ago[deleted]
- tlogan 6y agoI do not believe that is true. So they pay hackers 400k so that they will not sell data to somebody offering 200k. Really? You believe that?
- gkoberger 6y agoIs this the right way to look at it? That's like saying CVS security guards are pitifully small and inadequate. Yeah, you're right, they aren't going to stop a proper robbery... but stealing is illegal and shouldn't be happening either way. Same for hacking.
- kiba 6y ago
- gowld 6y agoThe data was leaked. They didn't "pay ransom to stop leaks".
- rrss 6y agodo you have a source? https://attheu.utah.edu/facultystaff/university-of-utah-update-on-data-security-incident/ https://attheu.utah.edu/facultystaff/university-of-utah-upda... says they paid the ransom to prevent leaks.
- Giorgi 6y agoThere is no way those 450k are not being traced right now like a hell, most likely it was allowed just because investigation said so, its matter of time now
- nick_kline 6y agoInteresting discussions here about the actual costs and value of finding the bugs that enable these problems. There's basically very little cost to the companies in most cases that have vulnerabilities. It's absolutely crucial, in my opinion, that we pass laws making paying off criminals illegal. There are arguments here that paying off via insurance or other 'secondary means' are somehow shielding the institutions. It's morally wrong, and I suspect in reality it's technically wrong to make these payments. It's just wrong. There is the problem that at least some of these ransomware groups are in countries like Russia that don't care to really prosecute them. We need to stop this, make it clear it's not acceptable, fight with our usual means against money laundering. Pretty much every company company in the western world is vulnerable to these problems, every public school, and behind the scenes lots of people are vulnerable.
- croh 6y ago> "The university's cyber insurance policy paid part of the ransom, and the university covered the remainder. No tuition, grant, donation, state or taxpayer funds were used to pay the ransom," University of Utah officials added. Can anybody elaborate more on this ? What are the other resources than tution/grant/donation/state/fund to earn money ?