Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Ransomware Becoming Bigger Threat for Businesses, Critical Infrastructure

    Written by

    Pedro Hernandez
    Published February 14, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      SAN FRANCISCO—Ransomware was the cyber-security story of 2016, and it is likely to be a big story again this year, with malicious operators upping the stakes by going after bigger and more lucrative targets like corporations, public infrastructure and industrial control systems.

      Those were some of the conclusions from vendors and researchers during a daylong seminar on ransomware here at the RSA Conference 2017.

      Throughout the day, experts discussed ways of not only preventing malware but also dealing with it once it hits, including whether to pay or not to pay. But paying or not, there is still a lot of work to be done for a victim as part of the mitigation process.

      There must be strategies in place for properly restoring data, patching the holes and training staffers to be on the alert for ransomware possibilities. In other words, ransomware is an ongoing security issue that should involve the entire company.

      Ransomware Is Big Business

      Ransomware netted cyber-criminals more than $1 billion last year, mostly from individuals and small businesses. The technique of locking or encrypting files and then demanding ransom for the key is an evolution of traditional cyber-crime business models of merely stealing data or taking down networks. Those methods take a lot of effort and don’t always deliver a lot of money, if any.

      “Bad guys are sick and tired shoveling PII [personally identifiable information] around,” said security researcher Gal Shpantzer. “The market is saturated. It’s no longer a seller’s market.”

      Rather than peddle stolen data on the black market, cyber-criminals have opted instead to go direct to the customer, so to speak, which significantly shortens the attack life cycle and overhead and delivers money more quickly, he said.

      Ransomware actors also act like business people, for the most part. They are known to negotiate on price. Hollywood Presbyterian Hospital last year paid only $17,000 in Bitcoin after an original demand of more than $3 million.

      But the business side of ransomware goes deeper than that because the business needs to operate on a level that commands enough respect that victims pay up. And once they do pay, the hackers must honor the deal and deliver the keys to unlock the data or the entire business proposition goes out the window.

      In other words, there must be rules to the game, said Jeremiah Grossman, chief of security strategy at cyber-security firm SentinelOne. Grossman compared today’s ransomware criminals with the modern-day kidnapping and ransom market—which includes Somali pirates—in which a cottage industry has evolved that includes security personnel, ransom negotiators and insurance syndicates such as Lloyd’s of London.

      Likewise, ransomware campaigns are increasingly being “professionalized” and funded, with sophisticated money laundering schemes, Grossman said. Ransomware negotiators are emerging, and cyber-insurers require clients to keep ransomware policies secret.

      “Who really is profiting from the kidnapping and ransom business? It’s not the pirates,” he said. While pirates earned about $150 million in 2010, $1.85 billion was paid out in insurance against the pirates. By 2021, Grossman contends, the ransomware protection market will reach $17 billion.

      Critical Infrastructure on the Hit List

      Over the past few years at the Black Hat conference, researchers have shown ways hackers have compromised everything from cars to door locks to guns and every internet of things (IoT) device in between. Ransomware changes the dynamics of these hacks significantly, to the point where the nation’s critical infrastructure will be held for ransom.

      In just the past few months there have been two examples of public systems being compromised by ransomware: the San Francisco MUNI system in November and the closed circuit TV cameras in Washington, D.C., days before the presidential inauguration in January.

      Pedro Hernandez
      Pedro Hernandez
      Pedro Hernandez is a writer for eWEEK and the IT Business Edge Network, the network for technology professionals. Previously, he served as a managing editor for the Internet.com network of IT-related websites and as the Green IT curator for GigaOM Pro.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.