60% of Businesses Would Consider Paying a Ransomware Demand

60% of Businesses Would Consider Paying a Ransomware Demand

Three in five (60%) organizations would consider paying an extortion demand in the event of a ransomware attack, according to a new study by the Neustar International Security Council (NISC).

The research also revealed that one in five businesses would be prepared to spend 20% or more of their annual revenue to restore their systems in these situations.

The findings have come amid a surge in high-profile ransomware incidents in recent months, many of which have resulted in substantial payouts to the perpetrators. For example, just last week, meat processing company JBS confirmed it paid its extorters $11bn. In contrast, last month it was reported that Colonial Pipeline paid out $4.4m after attackers knocked the US’ largest fuel pipeline offline. In the latter case, the US Department of Justice was able to seize the majority of funds paid to the Russian ransomware group.

These incidents have reignited the complex debate on whether it is ever right for organizations to pay a ransomware demand.

Encouragingly, Neustar’s study, which was based on a survey of 304 senior professionals across six EMEA and US markets, found that 80% of respondents emphasize defending against ransomware attacks in light of current events. More than two-thirds (69%) saw ransomware as a growing threat to their organization, making it the top concern across more than a dozen attack vectors.

The participants were also asked for their views on the effectiveness of currently available security technologies in protecting against ransomware. Close to three-quarters (74%) said they were either ‘very’ or ‘somewhat’ sufficient, while 26% viewed the technologies as ‘somewhat’ or ‘very’ insufficient.

Rodney Joffe, NISC Chairman, SVP, and fellow at Neustar, commented: “Companies must unite in not paying ransoms. Attackers will continue to increase their demands for ever larger ransom amounts especially if they see that companies are willing to pay. This spiral upwards must be stopped. The better alternative is to invest proactively in mitigation strategies before the attacks, including the use of qualified providers of “always-on” monitoring and filtering of traffic as part of a layered security approach.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Amazon Web Services Misconfiguration Exposes Half a Million Cosmetics Customers

Amazon Web Services Misconfiguration Exposes Half a Million Cosmetics Customers

Hundreds of thousands of retail customers had their personal data exposed thanks to a misconfigured cloud storage account, Infosecurity has learned.

A research team at reviews site WizCase traced the leaky Amazon S3 bucket to popular Turkish beauty products firm Cosmolog Kozmetik.

The 20GB trove contained around 9500 files, including thousands of Excel files which exposed the personal information of 567,000 unique users who bought items from the provider across multiple e-commerce platforms.

Although the research team discovered no payment information, they did find customers’ full names, physical addresses and purchase details among the leaked orders. In some cases, phone numbers and emails were also exposed.

The oldest orders dated back to 2019, and they went right up to the present day. This indicates that the database is continually updated.

WizCase warned that many of those whose details were exposed may be unaware of the leak, as e-commerce marketplace users often don’t check the names of sellers.

Cosmolog Kozmetik, which also sells under the name “Marketlog,” is commonly found on major Turkish e-commerce platforms Trendyol, Hepsiburada, and Unishop.

WizCase warned that if threat actors managed to find and copy the exposed data, it might put these shoppers at risk of follow-on phishing and fraud, including refund scams. They could even suffer physical theft of packages if attackers track and steal shipments as they arrive at customers’ homes, it added.

“Cyber-criminals are always generating new methods to exploit anyone vulnerable on the internet,” WizCase warned in a blog post detailing the privacy snafu.

“For future purposes, we recommend always inputting the bare minimum of information when making a purchase or setting up an account on the internet. The less information you give hackers to work with, the less vulnerable you are to attack.”

Although WizCase contacted the Turkish CERT, Amazon and Cosmolog Kozmetik about the breach, none had replied at the time of writing.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Warns Russia of Cyber-Attack No-Go List

US Warns Russia of Cyber-Attack No-Go List

President Biden and his team have warned the Putin administration of 16 critical infrastructure entities that are off-limits for threat actors operating from Russia.

The news came as the two leaders sat down in Geneva for a summit which Biden said was designed to ensure a “stable and predictable” relationship between countries following the turmoil of the Trump years.

After an audacious attack on Colonial Pipeline, which disrupted fuel supplies on the East Coast for days, Biden has been under increasing pressure to confront Putin over the cybercrime groups apparently operating with impunity from Russia.

The two spent “a great deal of time” talking about cybersecurity, said Biden in a post-meeting press conference.

“I talked about the proposition that certain critical infrastructure should be off limits to attack — period — by cyber or any other means. I gave them a list … of 16 specific entities; 16 defined as critical infrastructure under US policy, from the energy sector to our water systems,” he added.

“Of course, the principle is one thing. It has to be backed up by practice. Responsible countries need to take action against criminals who conduct ransomware activities on their territory.”

The two countries will now sit down to work on a deeper agreement on cybersecurity, designed to articulate “what’s off-limits.”

The US hammered out a similar agreement with China back in 2015 when Barack Obama warned Xi Jinping not to allow state-backed spies to target US companies in “economic cybercrime” attacks.

However, that deal soon fell apart as it became clear Beijing had no intention of dropping its plans.

Putin reportedly appeared similarly unapologetic at the Geneva meeting, claiming the Colonial Pipeline attack had nothing to do with the Kremlin. His US sources told him most cyber-attacks originate from the US.

Adam Flatley, former NSA director of operations and now director of threat intelligence at [redacted], said the summit went as expected.

“Both sides went in and stated their positions to set the playing field for the next few years. Russia denied everything, which is totally standard. Biden stated our opposing positions and didn’t cave to any of Putin’s initial demands, most of which were normal,” he explained.

“It looks like we’re back in a more normal world of international relations, which is a good thing. So the real outcome here seems to be that both sides stated their opening positions and will go back home to start pushing their different agendas, and we’ll have to see who has the will and resources to succeed.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk