The risks of paying a ransom to cyber criminals | 7.30

By ABC News In-depth

Share:

Key Concepts

  • Ransomware: A type of malicious software that encrypts a victim's files, making them inaccessible until a ransom is paid.
  • Cybercrime: Criminal activities conducted using computers and the internet.
  • Threat Actors: Individuals or groups who pose a threat to cybersecurity.
  • Vulnerabilities: Weaknesses in systems or processes that can be exploited by threat actors.
  • Malicious Emails: Emails designed to trick recipients into revealing sensitive information or downloading malware.
  • Identity Fraud: The act of impersonating someone else to gain financial or other benefits.
  • Insolvency Event: A situation where a business is unable to pay its debts.
  • Data Leakage: The unauthorized disclosure of sensitive information.
  • Whack-a-mole: A metaphor for a situation where addressing one problem leads to another popping up elsewhere.

Data Collection and Cyber Threats

Data is continuously collected as individuals go about their daily lives, encompassing interests, purchases, and personal details. This data is entrusted to companies for safekeeping, but their systems are increasingly becoming targets for cyberattacks. Lieutenant General Michelle McInness, the country's national cybersecurity watchdog, highlights ransomware as a significant economic threat. She emphasizes that malicious actors can now inflict harm online more cheaply, rapidly, and with greater consequences than ever before. The focus of cybersecurity efforts is on prevention, preparation, response, and recovery. Threat actors actively seek vulnerabilities, exploiting weaknesses in human behavior, technology, and interconnected systems.

Evolving Criminal Methods and Financial Impact

The methods employed by cybercriminals are rapidly evolving. McInness notes a particular focus on educating Australians to identify scams, which are becoming harder to detect due to the use of Artificial Intelligence (AI) by criminals to enhance authenticity. The increasing availability of data allows criminals to impersonate individuals more effectively, making scams more convincing.

A report from the Australian Signals Directorate reveals a rise in the average costs of cybercrime for businesses:

  • Small businesses: Reported an average cost of $56,000 per incident, a 14% increase from the previous year, primarily due to techniques like malicious emails and identity fraud.
  • Medium-sized businesses: Experienced a cost increase of over 50%, reaching almost $100,000 per attack.
  • Large-scale businesses: Saw a 200% increase in costs, with incidents averaging $200,000.

The Dilemma of Paying Ransom

In boardrooms, the decision to pay ransom demands is often considered due to the perceived immediate benefits. Some in the cybersecurity sector argue that businesses may feel compelled to pay to mitigate further harm. Darren Hopkins, who leads cybersecurity analysis at business advisory firm McGra Nickel, shares an example of a client facing an impending insolvency event. The client's inability to operate without their systems for an extended period meant that manual recovery would take months, a timeframe they could not afford given their cash flow.

Hopkins outlines two primary reasons why businesses consider paying:

  1. Minimizing harm to others: Paying can prevent the public leakage of data, thus avoiding the widespread availability of sensitive information to other criminals.
  2. System recovery: Businesses may pay to restore their systems or reduce downtime. The cost-benefit analysis often favors payment when compared to the financial impact of prolonged system outages.

Research Findings on Ransom Payments

McGra Nickel, in collaboration with Yuggov, surveyed companies, many of whom admitted to paying cybercriminals. The research indicated:

  • 44% of surveyed companies fell victim to ransomware in the past 12 months.
  • 71% of those victims decided to pay the ransom.

Trust and Retaliation: The Risks of Paying

A significant concern when deciding whether to pay is the trustworthiness of the criminal. David Tuffley, a senior lecturer in cybersecurity at Griffith University, states, "There is no honor among thieves. Um most ransom uh demands if paid are not honored." He supports the government's "just say no" stance, noting that only about 10% of victims who pay actually receive their data back. He warns that paying once can lead to repeated extortion.

McInness further cautions that businesses that pay ransoms may attract future attacks. She explains that even if data is returned, it has already been exposed and is likely to be exploited by other criminals. Anecdotal evidence suggests that businesses that pay ransoms are frequently retargeted.

The Ever-Evolving Threat Landscape

While the government contemplates future actions regarding ransom payments, Tuffley warns that the rapid adaptation of cybercriminals means lawmakers are constantly playing catch-up. He emphasizes that the risk to individuals and organizations in Australia has never been greater. The cybersecurity landscape is characterized by a constant stream of new and more ingenious attack methods, making it a perpetual "whack-a-mole" scenario where addressing one threat immediately leads to another emerging elsewhere.

Chat with this Video

AI-Powered

Load the transcript when you're ready to chat so the initial page stays lighter.

Ready to summarize another video?

Summarize YouTube Video