U.S. corporations that have long resisted bending to the demands of computer hackers who take their networks hostage are increasingly stockpiling bitcoin, the digital currency, so that they can quickly meet ransom demands rather than lose valuable corporate data.
The companies are responding to cybersecurity experts who recently have changed their advice on how to deal with the growing problem of extortionists taking control of the computers.
"It's a moral dilemma. If you pay, you are helping the bad guys," said Paula Long, chief executive of DataGravity, a Nashua, N.H., company that helps clients secure corporate data. But, she added, "You can't go to the moral high ground and put your company at risk."
"A lot of companies are doing that as part of their incident response planning," said Chris Pogue, chief information security officer at Nuix, a company that provides information management technologies. "They are setting up bitcoin wallets."
Pogue said he believed thousands of U.S. companies had prepared strategies for dealing with hacker extortion demands, and numerous law firms have stepped in to facilitate negotiations with hackers, many of whom operate from the other side of the globe.
Symantec, a Mountain View, Calif., company that makes security and storage software, estimates that ransom demands to companies average between $10,000 and $75,000 for hackers to provide keys to decrypt frozen networks. Individuals whose computers get hit pay as little as $100 to $300 to unlock their encrypted files.
Companies that analyze cyber threats say the use of ransomware has exploded, and payments have soared. Recorded Future, a Somerville, Mass., threat intelligence firm, says ransom payments skyrocketed 4,000 percent last year, reaching $1 billion. Another firm, Kaspersky Lab, estimates that a new business is attacked with ransomware every 40 seconds.
"If you're hit by ransomware today, you have only two options: You either pay the criminals or you lose your data," said Raj Samani, chief technical officer at Intel Security for Europe, the Middle East and Africa. "We underestimated the scale of the issue."
Hackers often send out email with tainted hyperlinks to broad targets, say, an entire company. All it takes is one computer user in a company to click on the infected link to allow hackers to get a foothold in the broader network, leading to hostile encryption.
"At least one employee will click on anything," said Robert Gibbons, chief technology officer at Datto, a Connecticut company that offers digital disaster recovery services.
Law enforcement counsels U.S. businesses not to succumb to ransom demands, urging them to keep backup copies of their data in case of hostile encryption.
"The official FBI policy is that you shouldn't pay the ransom," said Leo Taddeo, chief security officer for Crypt-zone, a Waltham, Mass., company that provides network security. Until 2015, Taddeo ran the cyber division of the FBI's New York City office.
But practical considerations increasingly are dictating a different approach. "It's an option to pay the ransom to get back up and running. Sometimes it's the only option," Taddeo said.
"But it has downsides," he added. "Paying ransom just invites the next attack."
Moreover, 1 in 4 companies that pay ransoms never get their files restored, Gibbons said.
The idea of rewarding extortionists with payment makes some technologists see red.
"That makes me super mad," said Lior Div, chief executive of Cybereason, a Boston-area cybersecurity company. "There are things that are unacceptable, and we need to fight them."
Div and his company have done something about the extortion epidemic. They built a product called RansomFree that claims to detect 99 percent of all ransomware strains.
So far, the free software has been downloaded 125,000 times, the company says.
As extortionists get more sophisticated, researchers say, they are modifying their malicious code, their infection strategies and the way they collect payments.
Once they weasel their way into your network, they now take a look around.
"They'll actually explore your system to see how much money they can squeeze from you," said Andrei Barysevich, director of advanced collection at Recorded Future.
And they won't offer any sympathy, no matter how valuable the encrypted data, even if lives are at stake, say, in a health care network. They may even say they are doing nothing evil.
"They actually think they are on the moral high ground. They think the companies should have paid more for security," said Barysevich, who spoke at a presentation this week at the annual RSA cybersecurity conference in San Francisco, which bills itself as the world's leading gathering of cybersecurity specialists.
One of the reasons midsize and large companies are storing bitcoin for emergency use is that extortionists, once they succeed at penetrating a system, commonly give a deadline for payment before destroying data. But victims can't rush out and buy bitcoin in a day or two.
"It takes at times a week for (brokers) to process you," Barysevich said.
Setting up the wallet ahead of time, Pogue said, allows businesses an option that is quick, although perhaps repugnant.
"If they need to go to it, they are not spinning their wheels standing up a bitcoin wallet," Pogue said.
2017 The Star Democrat under contract with NewsEdge/Acquire Media. All rights reserved.
Read more:
Spooked by Cyber Extortion Spike, Businesses Stockpile Bitcoin - NewsFactor Network
- Google removes malware Android apps used to secretly mine bitcoin [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin exchange MtGox liquidated [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin Wannabe Litecoin Emerges as Low-Price Challenger [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- The Worlds First Bitcoin Debit Card Is Almost Here [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- How does Bitcoin work? - Bitcoin - Open source P2P money [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin - Wikipedia, the free encyclopedia [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- The Bitcoin Group #27 - China Bans Bitcoin Again - Politics - Dark Market - Bitcoin VC - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Edan Yago - Free Market Bitcoin regulation and Honduras free trade zones.mp4 - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin vs. Political Power: The Cryptocurrency Revolution - Stefan Molyneux at TNW Conference - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Video: Roundup of This Week's Bitcoin News 25th April 2014 - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin Fredagsbar med Torben Mark Pedersen - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin and the Internet of Money - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin for Dummies - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin runner-up Litecoin emerges as low-price challenger [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Bitcoin or Gold? Squawk Walk Taipei- Squawkonomics - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Bitcoin Miner AntMiner S1 180 - 200 GH/s Nu in de Aanbieding! - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- New Bitcoin Documentary: Boom or Bust - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Bitcoin May v0.9.1 GitHub Source Code Development Visualization - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Atomic-Trade Bitcoin Exchange. AML, BSA, FinCEN compliant - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- China Bans Bitcoin Again -- Bitcoin the Movie -- Startup for Startups Raises 2,000 BTC - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- 4/24/14 - Xapo Debit Card, Russia's 1st Bitcoin Conference, Silk Road 2.0 - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- What is Bitcoin? - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- David Andolfatto, How Does Bitcoin Work? - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Australian Bitcoin traders hit by crash [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Bitcoin traders hit by Mt.Gox crash [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Market Extra: Bitcoin venture capital money hasnt kept up with buzz [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Bitcoin price slips as China steps up regulation [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Bitcoin price slips on China regulation [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Win .33 Bitcoin ($150 or so, Depending on BTC value) - Meme game for May 1st - Take My Bitcoins - Video [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Ron Paul on Bitcoin - Video [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- btc.sx Bitcoin derivatives platform George Samman clip - Video [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- 'The Rise And Rise Of Bitcoin' Filmmaker: 'There Is No Answer Yet' [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- Bitcoin the movie: It just had to happen [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- Bitcoin Vies with New Cryptocurrencies as Coin of the Cyber Realm [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- The Bitcoin Meetup - BitcoinMKE Hosts Jeffrey Tucker - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- MIT Bitcoin Expo 2014 - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- Bitcoin Expo 2014: Fireside Chat with Dr Gavin Wood - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- Rise Bitcoin Singapore - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- Preview: Bitcoin Authenticator - 2FA for wallets - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- The Bitcoin Group #27 (Live) - China Bans Bitcoin Again - Politics - Dark Market - Bitcoin VC - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- 4/25/14 - More China uncertainty, Missourian bitcoin warning, BadLepricon malware - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- Money & Tech at The Rise And Rise Of Bitcoin Afterparty - Video [Last Updated On: April 29th, 2014] [Originally Added On: April 29th, 2014]
- New Bitcoin student club at MIT will promote the virtual currency [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- 4/29/14 - MIT Bitcoin Project, Mt Gox revival plan, Mastercard lobbyists & Team Rubicon - Video [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- BitCoin Dentist GoCoin Fox News Interview - Video [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- Bitcoin Foundation Election Hiccups -- Pathetic Ohio Bans Bitcoins -- Dogecon SF 2014 - Video [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- Bitcoin Slips to $420 as BTC China Halts Transactions - Video [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- MultiSig Plus BitCoin Multi Coin Wallet looks like HUGE INVESTMENT potential! - Video [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- Bitcoin: what happens when the miners pack up their gear? [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Dark Wallet Is About to Make Bitcoin Money Laundering Easier Than Ever [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Bitcoin Talk Show #7 -- Skype BitcoinTalkShow to Call in Live! 🙂 - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Basic Bitcoin Bitches - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Gold standard vs Fiat vs Bitcoin - Truthloader - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- How to Defund the System: Bitcoin vs. the Central Banksters - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Bitcoin, Anarchy and Freedom with Roger Ver - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- MIT Goes Bitcoin-Wild [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Bitcoin Weekly 2014 April 30: Bloomberg adds Bitcoin to their market index, MIT to produce campus-wide bitcoin ... [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- 'Dark Wallet' wants to make Bitcoin even harder to trace [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Bitcoin made simple (video animation) - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Jon Matonis: Bitcoin - The future of commerce? - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- $100 in Bitcoin Going to Every MIT Undergrad - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- The Rise of Digital Currency - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Money Goes Virtual: The Bitcoin Bourse - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- Bitcoin Lights with LIFX - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- Bitcoin: How We Got Here and Where We Are Going [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- 5/1/14 - Larry Summers warns critics, Paym system & Bitcoin Center NYC roundtable - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- On est Connect S2 #07 1/2 : BitCoin et Musique sur Internet - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- MIT Undergrads To Receive $100 Worth Of Bitcoin This Fall - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Why it only took ME less than 2 minutes to believe in Bitcoin - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Bitcoin Basics and Regulation Thoughts from NH Liberty Forum - Bruce Fenton - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- PRIMER CAJERO DE BITCOIN EN BIT CENTER DE TIJUANA - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Yelp adds Bitcoin acceptance to business listings - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Bitcoin A Terrorist Threat? Counterterrorism Program Names Virtual Currencies As Area Of Interest [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- How Does Bitcoin Works - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- 10 Things You Didn't Know About BitCoin - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- BITCOIN The Future of Money - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Bitcoin Miner Review - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- The Bitcoin Group #28 (Live) - Yelp Lists Bitcoin - MIT Bitcoin $100 - Dark Wallet - Ohio Bans BTC - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Bitcoin: Gary North is Mentally Deranged And Bitcoin Will Change Everything - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Who is the Bitcoin Warlord? - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]