By Ray Birch
NELSON, New Zealand—Addressing a ransomware attack may become more costly for organizations due to a recent shift in criminal tactics, one security expert is warning.
Crooks are changing their approach to ransomware assaults—not only encrypting a company’s data but stealing it at the same time. That allows criminals to demand money to unlock the frozen data and also threaten to publish the information on criminal websites if the ransom is not paid.
As CUToday.info has reported, hackers from a criminal organization called Maze have allegedly stolen data from a company that does collections for credit unions and have posted some of it online. The company, CU Collections, is based in Manassas, Va. The stolen data includes sensitive information relating to members CU Collections is reaching out to, including home addresses, Social Security numbers, work and cell phone numbers, member numbers, and other information related to the file in collection, according to the security firm Emsisoft.
What is occurring, explained Brett Callow, threat analyst with Emsisoft, is criminals are looking to get more money out of their ransomware efforts as companies improve their ability to defend against traditional ransomware attacks in which data is just encrypted.
Starting to See a Shift
“We saw this shift starting at the tail end of last year,” said Callow, who added crooks today may steal the data and ignore encrypting it. He said crooks will often publish a small amount of the data to prove they have it. “They are seeking additional leverage to extort payment. If the company does not pay, the data is then released on a public website that anyone can access via the Internet, and the information can then be used by any criminal in any nefarious way they choose.”
Callow suspects the change is taking place due to companies getting better at backing up their data.
“As companies improve their backup processes, fewer are having to pay the ransom since they can restore their data,” explained Callow. “So, the traditional ransomware approach alone may not be enough anymore for criminals to get their money.”
Callow said much of the ransomware data is being posted on the Maze website, and also on Russian hacking forums. Callow said it is not clear if criminals from any particular country are behind this new assault.
What should be most concerning to businesses, and individuals too, is posting this data can lead to a great deal of reputational damage, said Callow—more so than a traditional data breach—due to the fact the data is posted for all to see on the web.
Risk of Lawsuits
Not only can reputations be badly damaged, observed Callow, but lawsuits are more likely to arise from this type of breach.
“There is a significant risk of a lawsuit in these cases,” said Callow. “A Canadian company is now facing a $100-million lawsuit over this type of breach. There is also a case of a plastic surgeon who was breached in this way, and the data taken seemingly included before-and-after photos of patients. Now the patients are seeing these extortion threats as well, with crooks threatening to expose the photos.”
Callow pointed out in most data breaches, such as when credit card numbers are stolen, a limited number of people generally touch the data to consider using it.
“But with these new ransomware attacks this information is being put out on the Internet for anyone to see,” he said. “It can be accessed by anyone in the world. And if you want to try your hand at identity theft using the data, well, go right ahead.”
No Answer
Callow said he has no answer regarding whether victims should pay the ransom.
“Companies paying the ransom are simply paying for a pinky promise from criminals. And why would a criminal organization ever destroy data they could monetize at a later date?” he asked. “Companies paying the ransom are really just hoping criminals will hold up their end of the bargain.”
The new ransomware tactic requires more skill from hackers than the traditional ransomware approach, noted Callow. The reason, he said, is it takes more skill to steal data than to encrypt it. As CUToday.info has reported, the rise of low-cost ransomware kits in the past year have made it much easier for criminals without a great deal of skill to pull off data encryption attacks, which led to a marked rise in those crimes. Callow said he is not certain how quickly this new wave of attacks will escalate.
“One thing about these new attacks is companies often don't disclose them,” he said. “The only way you really find out is when their names are posted on the Maze website.”
CUToday.info has reached out to CU Collections, but the company has not commented.
A Final Recommendation
Callow recommended companies improve their network monitoring to detect when unauthorized data is flowing out, in addition to making sure their data backup process is strong.
“I think we will see this new type of ransomware attack prove to be more expensive than criminals just encrypting the data,” said Callow. “In my opinion there is greater reputational risk, greater chance for lawsuits, and you still can face paying the ransom for unencrypting your data.”
