Ransom Where?
Total Page:16
File Type:pdf, Size:1020Kb
Ransom where? Holding data hostage with ransomware May 2019 Author With the evolution of digitization and increased interconnectivity, the cyberthreat landscape has transformed from merely a security and privacy concern to a danger much more insidious by nature — ransomware. Ransomware is a type of malware that is designed to encrypt, Imani Barnes Analyst 646.572.3930 destroy or shut down networks in exchange [email protected] for a paid ransom. Through the deployment of ransomware, cybercriminals are no longer just seeking to steal credit card information and other sensitive personally identifiable information (PII). Instead, they have upped their games to manipulate organizations into paying large sums of money in exchange for the safe release of their data and control of their systems. While there are some business sectors in which the presence of this cyberexposure is overt, cybercriminals are broadening their scopes of potential victims to include targets of opportunity1 across a multitude of industries. This paper will provide insight into how ransomware evolved as a cyberextortion instrument, identify notorious strains and explain how companies can protect themselves. 1 WIRED. “Meet LockerGoga, the Ransomware Crippling Industrial Firms” March 25, 2019; https://www.wired.com/story/lockergoga-ransomware-crippling-industrial-firms/. 2 Ransom where? | May 2019 A brief history of ransomware The first signs of ransomware appeared in 1989 in the healthcare industry. An attacker used infected floppy disks to encrypt computer files, claiming that the user was in “breach of a licensing agreement,”2 and demanded $189 for a decryption key. While the attempt to extort was unsuccessful, this attack became commonly known as PC Cyborg and set the archetype in motion for future attacks. Over the next few years, ransomware attacks were present but not yet a significant problem because cybercriminals were missing three key elements: A clear strategy to either unencrypt or destroy the files and data they demanded 1 money for. 2 The ability to communicate anonymously. 3 An untraceable method for the victim to pay the ransom. With those limitations, cybercriminals settled for leveraging exploitable vulnerabilities in software and human error to install malware onto devices through anti-virus scams to steal sensitive credentials and personal information to sell for profit. Then in 2006, the Archiveus Trojan changed the realm of ransomware. When downloaded, it encrypted all files found in the “My Documents” folder of the user’s computer. To regain access to these files, victims were directed to specific websites to make purchases, thus paying the ransom.3 The introduction of bitcoin in 2008 was a significant turning point in the world of cyberextortion. This new digital currency enabled cybercriminals to carry out attacks and receive virtually untraceable ransom payments. Now cybercriminals had the freedom to get creative with their attacks and up the ante. After several iterations of ransomware strains, CTB-Locker or CryptoLocker in 2013 fulfilled the other two missing elements. Cybercriminals could now execute powerful ransomware extortion plots. The CTB stands for “Curve, TOR and Bitcoin,”2 which provided “fast secure encryption of file content, a means for anonymous communication through ‘The Onion Routing’ (TOR) protocol, and bitcoin enabled secure, untraceable crypto-cash transactions.” With organizations’ and supply chains’ increased reliance on networks and connected devices, the scale and effect that a ransomware attack poses can elevate any organization to the level of a potential target. 2 Edith Cowan University. “Ransomware: Emergence of the cyber-extortion menace” 2015; https://ro.ecu.edu.au/cgi/viewcontent. cgi?article=1179&context=ism. 3 Computer Business Review. “The History of Ransomware” Feb. 23, 2018; https://www.cbronline.com/news/the-history-of-ransomware. 3 Lockton Companies The prevalence of ransomware The FBI launched the Internet Crime Complaint Center (IC3) to track cybercrime and ransomware attacks and provide information to people and organizations about how to protect themselves against these crimes. Since launching in 2000, IC3 has received reports of over 4 million cybercrime events, with cyberextortion on the rise. In 2018, ransomware attacks reported directly to the IC3 accounted for roughly $3.6 million in losses for the targeted organizations.4 While the financial loss reported may seem low, it is important to note that it is common for many organizations to pay ransoms and not report that they have fallen victim to ransomware attacks. Ransomware attacks are becoming more aggressive as well. Cybercriminals are These attacks are increasing at doubling and even tripling the demand if the such a fast pace that researchers at ransom isn’t paid within the specified time frame. This method of cyberextortion has Cybersecurity Ventures predict that evolved into a multimillion-dollar enterprise “a new organization will fall victim to for cybercriminals, with global ransomware ransomware every 14 seconds in 2019, costs expected to reach roughly $12 billion by 5 the end of 2019 and $20 billion by 2021.5 and every 11 seconds by 2021.” GLOBAL RANSOMWARE DAMAGE COSTS $25,000,000,000 $20,000,000,000 $15,000,000,000 $10,000,000,000 $5,000,000,000 $0 2015 2017 2018 2019 2021 Source: Cybersecurity Ventures for global ransomware damage costs data. 4 Federal Bureau of Investigation. “2018 Internet Crime Report” 2019; https://www.ic3.gov/media/annualreport/2018_IC3Report.pdf 5 Cybersecurity Ventures. “Global Ransomware Damage Costs Predicted To Reach $20 Billion (USD) By 2021” Oct. 19, 2018; https:// cybersecurityventures.com/global-ransomware-damage-costs-predicted-to-reach-20-billion-usd-by-2021/ 4 Ransom where? | May 2019 What role does cyber insurance play? Organizations need to have appropriate protection in place to guard against ransomware attacks. This extends further than implementing anti-virus, anti-malware software and backups to securing the longevity of the entity. Phishing scenarios are highly leveraged to initiate ransomware attacks and are commonly “designed to trick a user into providing Office 365 account credentials”6 to breach a system. These attacks go beyond demanding ransoms and often come with several damages and associated expenses, including: “damage and destruction (or loss) of data, downtime, lost productivity, post-attack disruption to the normal course of business, forensic investigation, restoration and deletion of hostage data and systems, reputational harm, and employee training in direct response to the ransomware attacks.”5 Cyber insurance can reduce the likelihood of a company exhausting all of its resources to investigate and recover from an attack. In the event of a ransomware attack, cyber insurance would cover the ransom demand and extra expenses, including forensics and investigation, up to the specified cyber policy limit. The value that cyber insurance provides is demonstrated through the extensive core insuring agreements and enhancements available in the marketplace, such as: Network security liability. Data recovery. Privacy regulatory proceeding. Business interruption and extra expense. Breach response costs. Dependent business interruption. Cyberextortion reimbursement. Reputational harm. Hardware replacement (bricking). Coverage enhancements like dependent business interruption offer coverage to companies for damages caused by third-party vendors because of a cyber event like ransomware. Lockton sees firsthand the value that cyber insurance affords our clients against damages and costs incurred due to ransomware attacks, like Ryuk and WannaCry, providing coverage for expenses reaching upward of $4.5 million cumulatively. Lockton has secured exclusive amendatory endorsements with many of the large cyber insurance carriers to ensure that our clients receive optimal coverage options. Ransomware attacks come with hefty price tags and considerable business interruption. For the past 30 years, ransomware has adapted to defensive strategies time and time again, with cybercriminals exploiting numerous avenues to carry out attacks. From social engineering and phishing attempts to infected websites, the threat becomes more sophisticated by the minute. Its advancement is impacting a growing number of industries, shifting the likelihood of an attack from an “if” to a matter of “when.” Organizations should shift their focus from a recovery stance to a proactive one to develop the appropriate prevention and contingency plans. 6 Baker Hostetler. “2019 Data Security Incident Response Report” April 2019; https://www.bakerlaw.com/press/bakerhostetlers-5th- annual-data-security-incident-response-report-highlights-collision-of-privacy-cybersecurity-and-compliance-details-efforts-to-minimize-risk 5 Lockton Companies TIMELINE BIGGEST RANSOMWARE AND MALWARE ATTACKS TO DATE DATE STRAIN EVENT INDUSTRY 2012 Reveton Trojan that fraudulently claimed to be law PUBLIC SECTOR — Metropolitan Police enforcement and shut users out of their Service (London) devices until the demand or “fine” was paid. September 2013 CryptoLocker Trojan used to target devices running Microsoft AEROSPACE AND DEFENSE — NASA Windows, using the Gameover Zeus virus GOVERNMENT — Health and Human delivered through spam messages. The virus Services managed to infect roughly 500,000 computers around the world. Cybercriminals were able to extort roughly $1 million within a six-month period. February 2015 TeslaCrypt A CryptoLocker