Copied


(Rejected) Ransomware, kidnappings and ransom payments in cryptocurrencies

Donatella Maisto   May 18, 2020 23:15 4 Min Read


It’s just a few hours ago the most striking ransom demand in cryptocurrencies.

An hacker group, known with the name of REvil o Sodinokibi, was able to steal 1 TB of data belonging to Grubman Shire Meiselas & Sacks, the most important American entertainment e media law firm. 

The group of hackers then demanded a payment of $42 million in cryptocurrencies.

In case of non-payment will be revealed the "skeletons in the closet" of a large number of celebrities and important individuals. Among these also Donald Trump.

To demonstrate the possession of such data, hackers have recently released 2 GB legal documents it would seem to Lady Gaga.

Among the clients of the law firm stand out names of the caliber of Elton John, Robert DeNiro and Madonna. Criminals managed to hack into the company’s servers and steal confidential contacts.

Now the company has refused to pay the ransom.

 

This is the last of the events concerning ransom demands in cryptocurrencies.

 

The story of ransoms in cryptocurrencies, also and unfortunately linked to the kidnapping of people, is quite recent, but already significant and especially highlights the downside of the blockchain medal.

The first episode occurred in 2015, when a group of criminals kidnapped a Canadian citizen in Costa Rica, asking for half a million dollars in bitcoins in exchange for the release of the hostage.

A similar case occurred later in Hong Kong.

 

In December 2017, a criminal group kidnapped Russian Bitcoin exchange manager Exmo, Pavel Lerner, issued only after payment of the ransom per a amount equal to  a million dollar in cryptocurrencies.

From being isolated cases, in 2018 kidnappings with ransom demands in cryptocurrency were at least one per month, according to a report published by Control Risks, specialist risk consultancy.

 

Next to kidnappings of people with ransom demands in cryptocurrencies we have cases of ramsonware with payout in cryptocurencies.

 

Ransomware, a type of malware that holds data for ransom, has been around for years.

In 1991, a biologist spread PC Cyborg, the first ransomware, by sending floppy disks via surface mail to other AIDS researchers, for instance.

In the 2010s, a new ransomware trend emerged: the use of cryptocurrencies as the ransom payment method of choice by cybercriminals.

It works by restricting access to computer files until a ransom is paid.

On how to handle a ransomware attack and ransom payment is very interesting the Forrester’s Guide .

The appeal to the extortionists is obvious, as cryptocurrencies are specifically designed to provide an untraceable, anonymous payment method.

Most ransomware gangs demanded payment in bitcoin, the most high-profile cryptocurrency, although some began shifting their demands to other currencies.

A new London lawsuit illustrates how the hackers are seeking to launder their ill-gotten gains.

Lawyers say the case is a landmark one as it is the first time the UK’s High Court has expressly stated that crypto-assets such as bitcoin constitute property.

In December the High Court issued a court order against unknown hackers and cryptocurrency exchange Bitfinex, which held nearly $1m in bitcoins that had been paid to the hackers as a ransom.

Details of the judgment were released by the High Court on 17 January2020, following a ruling delivered by Justice Simon Bryan on 13 December 2019.

The court case reveals that in October last year, hackers had paralysed work at a Canadian insurance company by using a software bug to render over 1,000 company computers unusable.

The hackers then demanded $1.2m, paid in bitcoin, as a ransom in order to restore the victim’s computers to their pre-attack state.

After consultations with specialist intermediaries, the Canadian company’s insurer, which had covered its client against losses from cybercrime, agreed to pay the hackers $950k in bitcoin for a decryption tool.

The decryption tool arrived within 24 hours of the ransom being paid.

 

In 2019, an increasing number of government agencies, public and financial institutions and electricity companies suffered IT system shutdowns as a result of ransomware attacks.

In 2020, we will start to face with the reality of cyber-crime on a global scale.

 

Like terror, whether domestic or foreign, cybercrimes will increase the sense of insecurity for people in 2020.

This feeling is added to the instability caused by Covid-19.

 

The most effective strategy for stopping ransomware attacks relies on preventing them from ever entering your organization. The number of applications and services businesses require to operate continues to increase.

 

Legacy cybersecurity approaches have primarily focused on detection and remediation, but this is no longer effective. A shift in practice from detection to prevention is essential.

Stop attacks before they can infect organizations and cause harm will be the priority.

Organizations must have the appropriate security architecture in place to enable this shift, operating over three levels: reducing the attack surface, preventing known threats, identifying and preventing unknown threats.

 

Payments to criminals using Ransomware to hold data hostage may run afoul of banking laws and policies as well as related statutes and regulations. Individuals and organizations choosing to make ransom payments to end Ransomware attacks could be subject to international sanctions programs administered in the U.S. by the Office of Foreign Assets Control (OFAC), though such enforcement has not yet been tested as of this writing.

On the website of CISA it is possible to find an important line guides.

Ransomware and the use of cryptocurrencies as ransom fee definitely represent the dark side of technology and of its future.

The decentralization and the disintermediation of blockchain used wrongly may constitute a worsening of progress and a black hole for the future?

Best practices, guide lines and the advice to not paid the ransom fee may truly be the only way to deal with these crimes?

The resolution of all this must necessarily move to a higher plane.

The rules will be the death of the blockchain or its new future?

It’s time to think about where we want to go and how to do it!


Read More