3 ms·
I thought it was illegal to pay ransom to hackers. I guess it is legal or maybe it isn't very clear? I thought that there were certain conditions that the compa
by layman51 5mo ago
I thought it was illegal to pay ransom to hackers. I guess it is legal or maybe it isn't very clear? I thought that there were certain conditions that the company had to check together with law enforcement so that at least the ransom money doesn't go to a hacker group that is on a government payments sanctions list.
Also, does anyone know the root cause of the attack? I read a rumor online (but it's not really confirmed anywhere) that it may have had to do with the common pattern of ShinyHunters where they use a vulnerability in a Salesforce Experience Cloud site. What is confirmed for sure is that the vulnterability involved the feature of Canvas called "Free-For-Teacher accounts".
- deleted 5mo ago[deleted]
- JohnMakin 5mo agoNot only is it not illegal, there are insurance policies set up to take care of this very scenario. It's almost always handled by a third party, not the company themselves, that would deal with any such concerns.
- dylan604 5mo agoIt is illegal to pay terrorists. As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If they did, would they be able to send in SEAL Team 6 to handle the hackers?
- junofan 5mo agoSearch “cyber jihad” and “cyber islamic state” if you’re curious for answers.
- wil421 5mo agoIf they were in Iran a drone would’ve paid a visit, based on current events. Most of them are in Russia or former Eastern Bloc like Belarus. USA and the west doesn’t want a direct conflict so the drones never pay them a visit. Instead, they trick the hackers into going on a vacation in a country that will let them grab them.
- fragmede 5mo agoThe cyber terrorist groups North Korean Lazarus Group and Russian groups like APT28 (Fancy Bear) are on the US SDN list, among others.
- Scoundreller 5mo ago> As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If you’re sending a large sum of money to $anonymoushacker, how do you ensure they’re not on some OFAC list? Or do your AML checks? Or make sure you’re not on the wrong side of Foreign Corrupt Practices act? The third party probably turns a blind eye to that cuz there’s no way of really checking.
- zbentley 5mo agoCryptocurrency mitigates most of those concerns. That's why the flourishing of crypto payment systems has been an unalloyed blessing for cybercriminals.
- Scoundreller 5mo agoIt can at a technical level but not at a legal level. Your BigCo accounting department is not going to be very understanding about acquiring cryptocurrency to send to ??? for a ransom.
- dylan604 5mo agoIsn't this why in other comments people have said that companies use third parties to pay the ransom rather than paying directly?
- Scoundreller 5mo agoThat’s my theory too. Setting up payments to a new vendor is hard enough even for the most legitimate. An org’s Net30 terms aren’t going to work here…
- bluGill 5mo agoNo it does not. It makes some things harder and some things easier. The public ledger means you can track where then money flowed - you might not know who had it but you know how it flows which is interesting. I don't know if it has happened, but I've heard of proposals to make any bitcoin the traces to some transaction illegal to have, and that means nobody who might get caught will have anything to do with those.
- MagicMoonlight 5mo agoIran, Russia and North Korea are the biggest sources of ransomware.
- amarant 5mo agoA large percentage of hacking groups are state sponsored Russians. That seal response would be starting WW3 over some pii. Protecting pii is important, but it's not that important
- dylan604 5mo agowe started the pretext to WW3 over someone wanting to move the focus of attention, so it's really not that much of a stretch.
- altcognito 5mo agoMan, I don’t remember Putin wanting to move the focus of attention that bad.
- amarant 5mo agoAye, I meant more in the sense of "it would be a bad idea", than "that's definitely not going to happen". Predictions are hard, especially about the future!
- calpaterson 5mo agoIt often is illegal to pay them. They are often on sanctions lists, or indeed in embargoed countries. And it's just generally not allowed to pay unidentifiable parties for basic anti-money laundering reasons. And a lot of countries are bringing in new legislation to make paying illegal, starting with public sector organisations. I'm sure that will only expand. Frankly, you pay a ransom at your peril. If it turns out it was North Korea you may well go to jail for it.
- JohnMakin 5mo agoI don't know where you are getting your information from. For one, it's very often unknown, by virtue of how these groups operate, where they are from or who they are affiliated with in the first place. For two, as I stated, it is such common practice to pay ransoms that there are insurance policies specifically for doing so, it's very common to purchase these as part of a SOP of a company's security policy. A business is required, often by the board/shareholders, to maintain business continuity, which is why these exist. For three, by the FBI's own source, they don't mention anything about it being illegal, they merely advise against doing so[0] - > The FBI does not support paying a ransom in response to a ransomware attack. Paying a ransom doesn’t guarantee you or your organization will get any data back. It also encourages perpetrators to target more victims and offers an incentive for others to get involved in this type of illegal activity. If you are a victim of ransomware, contact your local FBI field office or file a report at ic3.gov. I am not saying I support paying ransoms, or take any position here, I am just saying quite factually it is an extremely common practice to pay these, often via third parties that take care of any potential legality issues (which I am not aware of being super common at all, and if you are being targeted by a nation state on a sanctions list, you probably are well aware and have your own legal team/police liasons to deal with any such issues). Most ransomware attacks come from small, unknown groups. [0] https://www.fbi.gov/how-we-can-help-you/scams-and-safety/common-frauds-and-scams/ransomware https://www.fbi.gov/how-we-can-help-you/scams-and-safety/com...