A number of US cities have paid ransoms of hundreds of thousands of dollars after getting caught out by hackers - and if the business model is working, cybercriminals will keep exploiting it.
Ransomware once seemed to be on the decline, but it's now gained a new lease on life - and additional notoriety - after crooks identified a lucrative new set of targets for their file-encrypting malware.
Once content to target individuals' PCs, cybercriminals have extended their reach upwards after realizing that they can make tens of thousands of dollars at a time by encrypting the entire networks of small and medium-sized businesses and other organizations, and holding them to ransom.
While some cybercriminal gangs shifted away from using ransomware in favor of other attacks such as cryptojacking or trojan malware, those specializing in file-locking campaigns kept plugging away, developing more highly targeted - and much more effective - attacks.
Cities and local governments, particularly those in the US, have fast become regular victims of ransomware campaigns. Recently, Riviera Beach and Lake City paid $600,000 and $500,000 after ransomware took down their systems.
They're paying because it's the quickest way to get your operations back up and running. If you look at some incidents that have impacted critical services, those are highly disruptive and definitely felt by the citizens of the city. That's probably factoring in to cities decisions to pay.
And, because targeting cities is bringing in lucrative paydays, cybercriminals are going to keep attacking them with ransomware. Ultimately, these guys are conducting these operations because they want to make a profit - they wouldn't be doing so if it wasn't working.
The best option for such cities - and the one which protects their budgets in the long run - is to invest in security before falling victim to an incident. That's not without cost and pain, however.
Read the complete article > ZDnet.com

No comments:
Post a Comment