The U.S. has spent recent years strengthening its efforts to combat ransomware, yet that specific type of cyber attack remains a problem, with new strains that are harder to attribute and incident reporting gaps that leave questions. Even so, at the same time, there may be new reasons for optimism.
Ransomware has spiked in public awareness of late, with high-profile incidents such as the 2021 Colonial Pipeline panic, and it continues to cause new problems for local government, in places ranging from Dallas to Spartanburg County, S.C. As a result, federal efforts to fight these attacks are ongoing, and they have frequently aligned with the recommendations of the Ransomware Task Force (RTF), a public-private collaboration whose members have previously included the now-acting National Cyber Director Kemba Walden.
RTF released a 2021 report detailing the global ransomware landscape with proposals for how nations could work to disrupt it in long-lasting ways, and the U.S. has made at least some progress on most of the recommendations in that report, speakers said during a recent event hosted by the Institute for Security and Technology (IST), which coordinates the RTF. Among the wins: international partnerships have disrupted some perpetrators, and the U.S. has started pre-emptively warning organizations when they have vulnerabilities that are susceptible to ransomware actors.
Federal security and cybersecurity officials said they want to compel cryptocurrency entities and cloud services providers to keep cyber criminals off their services. Anne Neuberger, U.S. deputy national security adviser, said the U.S. is also mulling a ban on ransomware payments, with exemptions granted to some essential organizations.
But its unclear if any of this marks a lasting shift away from ransomware. The drop in such attacks against the U.S. may have been driven by world events, with Russias war against Ukraine diverting the attention of cyber crime groups in the region, the RTF said.
Officials are cautious about describing the landscape, but some tentatively suggest hope.
The rate of ransomware attacks seems to be somewhat stabilizing, and, I think a level, plateau, steady state is where we've been, said David Ring, head of the FBI Cyber Divisions private-sector engagement and cyber criminal intelligence missions.
However, Allan Liska, intelligence analyst at the threat intelligence platform provider Recorded Future, said the situation remains murky.
We think ransomware attacks have seen a resurgence in 2023, after dipping a little bit in 2022," Liska said, "... but the answer is that we dont know, because theres not enough incident reporting to get a clear picture.
Regardless of the number of attacks, those that do successfully hit can be punishing. Ransomware continues to strike U.S. hospitals, schools and local governments.
Fully understanding the ransomware landscape is challenging, because reporting requirements are often nonexistent or fragmented, making it hard to get a complete view, Liska said. Even the FBI believes it only received victim reports on about 20 percent of Hive ransomware attacks, Ring said.
Michael Phillips RTF co-chair and chief claims officer at cyber insurance provider Resilience said organizations fear being stigmatized if they admit to suffering a ransomware attack, and they also want a standardized way to report. That latter step would make it easier for victims to inform authorities promptly, while theyre still in crisis mode dealing with the effects of an attack.
Mandatory reporting requirements are forthcoming for some sectors under the Cyber Incident Reporting For Critical Infrastructure Act (CIRCIA), which passed in 2022. But the Cybersecurity and Infrastructure Security Agency (CISA) is still paving the way for its implementation, and CISA Chief Strategy Officer Valerie Cofield said we won't see the fruits of that legislation for a couple of years.
Screenshot
Prior years have seen ransomware-as-a-service (RaaS) models proliferate, in which developers create the malware while other cyber criminals called affiliates deploy it and share some of the extortion profits.
We're now seeing a lot of threat actors move away from there, Liska said.
Ransomware code is increasingly leaked and stolen, leading to some new variants that include other ransomware groups code. Liska calls these variants Franken-ransomware and said the code recycling makes it difficult to determine whos actually behind attacks.
That kind of fracturing of the ransomware market has made it harder for us to track and identify what the growing strains are [or] even [identify] who hit us? Liska said. I get this question all the time now Hey, we got hit by this, do you know what it is? Because theres no name in the ransom note, just some random email address. Thats a real challenge for incident response and even for reporting.
The U.S. has made strides in the past year toward building intergovernment and public-private collaborations around disrupting ransomware as well as in working to address risks from cryptocurrency entities that facilitate perpetrators payments, per the RTFs report. The U.S. also deepened its focus on reporting and information sharing.
The U.S. has now made significant progress on 50 percent of the task forces 48 recommendations and some progress on 92 percent of them. Thats up from May 2022, when IST CEO Phil Reiner reported significant progress on 25 percent and some progress on 88 percent.
More remains to be done, even on areas that are showing progress. U.S. Rep. Elissa Slotkin called for ensuring crypto exchanges, kiosks and trading desks follow Know Your Customer (KYC) and anti-money laundering practices.
There are gaps in our crypto regulations, and these gaps allow bad actors to evade the law, Slotkin said in pre-recorded remarks.
Acting National Cyber Director Kemba Walden said multipronged efforts can help make ransomware less profitable and less easy for perpetrators to conduct. Addressing illicit cryptocurrency use can disrupt the flow of profits, while requiring cloud services providers to follow KYC practices could help hamper ransomware operations by preventing nefarious use of this digital infrastructure.
Pushing for software and hardware to be secure-by-design and secure-by-default could also make the U.S. more cyber secure overall and do so in a way that lifts the responsibility off of small players and end users, Walden said.
Screenshot
When we talk about, potentially, countering Chinese malicious cyber activity, there are some countries who will say, We don't want to do that publicly, Neuberger said.
The U.S. and its partners have been trying a variety of disruptive efforts and are working to assess just how impactful any of these strategies are, Neuberger said. For example, the U.S. and international partners took actions against the Hive ransomware gang and dark web marketplace Genesis Market. Those included seizing Hive servers and decryption keys as well as 11 of Genesis Marketplaces domain names. But questions of effectiveness remain:
We know it has a disruptive impact for how long? Neuberger said. How do we extend how long that lasts? How do we ensure these disruptions have foundational impact on the infrastructure, on the people, on the money laundering networks, that makes this possible and that drive it?
Whether organizations should be allowed to pay ransom is a tricky question. The U.S. is actively discussing whether to issue a broad ban against this practice, while allowing case-by-case exemptions for essential entities, Neuberger said.
A question that weve grappled with both within the U.S. government and bilaterally, as well as multilaterally is, do we ban ransomware, with a waiver? Neuberger said.
Paying extortion makes the attacks profitable, enabling and encouraging more ransomware. But when victims are critical entities, not paying risks leaving their essential services going down for longer.
For an individual entity, it may be they make a decision to pay. But for the larger problem of ransomware, that is the wrong decision, Neuberger said. Now, there may be an individual entity a major hospital, an emergency services that we just are committed to bringing the services back up as quickly as possible. So [when] we think about banning ransom payments, we asked, Would we do so with a waiver e.g., notifying [and] asking the permission of the relative U.S. government?
The RTFs 2021 report warned that imposing a full ban on ransom payments might prompt perpetrators to initially test this resolve and ramp up their attacks against essential organizations like health-care providers, local governments and other custodians of critical infrastructure.
As such, any intent to prohibit payments must first consider how to build organizational cybersecurity maturity, and how to provide an appropriate backstop to enable organizations to weather the initial period of extreme testing, that report read.
The 2021 RTF report recommended nations require victims to avoid paying unless theyd first conducted a cross-benefit analysis to confirm that doing so would really be worthwhile. Victims should also have to consider alternative options before choosing to pay. Sometimes data is recoverable elsewhere or decryption keys are already available, for example.
Screenshot
For example, the program in February warned 93 critical infrastructure owners and operators about a Microsoft Exchange ProxyNotShell vulnerability and has since seen a 30 percent uptick in patching that vulnerability, Cofield said.
The past two years have also seen ransomware victims become more trusting of federal government support, with the FBIs Ring saying victims are more likely to report attacks.
Two years into this, I think the conversation has shifted to, rather than, Should we report this to law enforcement? to When should we report this to law enforcement?, which is a small change, but a very, very significant change in terms of how people think, Ring said.
Read the rest here:
Report: U.S. Making Progress in Fight Against Ransomware - Government Technology
- The Daily Progress: The Daily Progress, Charlottesville News [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- Progress Lighting - Home [Last Updated On: March 25th, 2016] [Originally Added On: March 25th, 2016]
- WTC PROGRESS - One World Trade Center [Last Updated On: July 10th, 2016] [Originally Added On: July 10th, 2016]
- Postpartum Progress - postpartum depression and postpartum ... [Last Updated On: July 10th, 2016] [Originally Added On: July 10th, 2016]
- Center for American Progress [Last Updated On: July 18th, 2016] [Originally Added On: July 18th, 2016]
- Contact Us - Progress Energy [Last Updated On: July 27th, 2016] [Originally Added On: July 27th, 2016]
- National Assessment of Educational Progress (NAEP) [Last Updated On: October 11th, 2016] [Originally Added On: October 11th, 2016]
- Progress Announces ProgressNEXT 2017 Partner Conference - Business Wire (press release) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Think Progress Editor Mocks Audi for Equal Pay Super Bowl Ad - Breitbart News [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Penguins injuries: Hagelin has concussion; Malkin still out, but making progress - NBCSports.com [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Patel: Syria progress at risk without new push in 2017 - ReliefWeb [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Market Recon: There's Progress on the Deregulation Front - TheStreet.com [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Assignment Helps Students Assess Their Progress - Faculty Focus (blog) [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Kiener Plaza reopening in May; Gateway Arch renovations continue progress - STLtoday.com [Last Updated On: February 6th, 2017] [Originally Added On: February 6th, 2017]
- Progress being made on possible grocery store co-op in Winston-Salem - myfox8.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Nioh Review-in-Progress: FromSoftware's Formula Evolved - Shacknews [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Deutsche Bundesbank Cites Progress With Blockchain-Based Settlement - CryptoCoinsNews [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Progress apparent on defense - Pittsburgh Steelers - Steelers.com [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- IMF: Greece's Debts are Still Unsustainable, Despite Progress - Voice of America [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Haupt's Take: It took eight years to destroy 50 years of progress - Watchdog.org [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Cavaliers' pitching rotation a work in progress - The Daily Progress [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Can US disrupter-in-chief trigger some progress? - Jerusalem Post Israel News [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- The Cost of Progress - Slate Magazine [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- DACC women making progress - Danville Commercial News [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- City police cite progress vs. drugs - Rutland Herald [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Women's Progress in the Boardroom Took a Hit in 2016 | Inc.com - Inc.com [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Britney Spears Says Niece Maddie Is 'Making Progress' After ATV Accident: 'Let's All Keep Praying' - PEOPLE.com [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Progress on vet's Mustang to be unveiled - Indianapolis Star [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Through the looking glass: Tower view showcases progress on Amazon's unique biospheres - GeekWire [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Blight Elimination Progress, Uplifting - MyWabashValley [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Forecasters See Slow Progress in Labor-Market Measures Favored by Trump Administration - Wall Street Journal [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- United coach Adrian Heath looks at steady progress after third straight draw - TwinCities.com-Pioneer Press [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Evgeni Malkin making 'progress,' could return Saturday in Arizona ... - Pittsburgh Post-Gazette [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Franks recognized as 2016 Partner in Progress - Chanute Tribune [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- 49ers players optimistic about progress under Shanahan, Lynch - The Mercury News [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Colts position review: OL showed legit progress, but work remains - Indianapolis Star [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Jimmy Cheek: UT chancellor appreciative of hard work, progress on journey - Knoxville News Sentinel [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Egyptian Economy Making Slow, Tentative Progress - VOA News - Voice of America [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Marginal progress for Turkish-backed forces in north Syria - PBS NewsHour [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Syria Regional Crisis 2016 Emergency Appeal - Progress Report - Reliefweb [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- CWLP officials: Bailout repayment would set back progress - The State Journal-Register [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Clairton works: Real progress is coming to the former steel town - Pittsburgh Post-Gazette [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Pistons' Johnson making halting but definite progress - The Detroit News [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Bluefield officials urge those that want to see city progress to take online survey - Bluefield Daily Telegraph [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Virginia lawmakers making big progress despite shorter session - The Charlottesville Newsplex [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Tech industry shows little progress on racial diversity - VentureBeat [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- North Korea Claims Progress on Long-Range Goal With Missile Test - New York Times [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- How Travel Bans Can Impede America's Progress - Forbes [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Adele, Beyonc, and the Grammys' Fear of Progress - The Atlantic [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Ionis Earns $75M Milestone from Bayer for Progress of Antisense Drug Program - Genetic Engineering & Biotechnology News (press release) [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Guilford Schools annual report shows mixed results on progress - Greensboro News & Record (blog) [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Sniper Elite 4 review in progress - PC Gamer [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- At California's Oroville Dam, Progress Made, but Threat Lingers - Wall Street Journal [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- For Honor Review In Progress - GameSpot [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Downtown Seattle's 'incredible year of progress' - The Seattle Times [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- CDC reports more progress against HIV, but gay Latinos contracted more infections - Washington Post [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- China's military progress challenges Western dominance, says IISS - Deutsche Welle [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- PFW in Progress Recap 2/14: Patriots Offseason Outlook - Patriots.com [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Huntsville-based Progress Bank to acquire Birmingham's First Partners Bank - Birmingham Business Journal [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- California officials lift evacuation order for 200000 threatened by damaged dam - CBS News [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Indiana Regional Cities Initiative Gets Progress Report - Tristatehomepage.com [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Clean Samish Initiative partners discuss progress - goskagit.com [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Man United's Jose Mourinho: Progress in cups will create 'many problems' - ESPN FC [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Google Touts Progress in Android Security in 2016 - Threatpost [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- UW coach Lorenzo Romar: Markelle Fultz making progress but still not cleared to play - The Seattle Times [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Some Progress On Occupational Licensing But Much More Needed - Forbes [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Officials making 'great progress' on California dam repairs, remind residents to stay vigilant - Fox News [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Republicans' health care overhaul still a work in progress - Press Herald [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Why Do We Pay So Much More for No Progress? - Cato Institute (blog) [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Halo Wars 2 Review in Progress - IGN [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Lenovo's data center ambitions remain work in progress following Q3 results - ZDNet [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- S&P 500: 'Blow-off' Phase in Progress - DailyFX - DailyFX [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- F-35 Program Makes Significant, Solid Progress, Official Says - Department of Defense [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- PFW in Progress Recap 2/16: Free Agency and Potential Patriots - Patriots.com [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Combine invites are another sign of progress at Michigan - Big Ten ... - ESPN (blog) [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Donald Trump touts promise progress at press conference - PolitiFact [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Mild winter helping crews make significant progress on East End Connector - WRAL.com [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Latest edition of Pig Progress goes to Asia - Pig Progress (registration) (blog) [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Committee updates Legislature on precinct consolidation progress - Chicago Tribune [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- SEC basketball shows progress but has room for growth - STLtoday.com [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]