A Strategy for Addressing Big Risk to CUs

By Ray Birch

WASHINGTON—With the growing wave of ransomware attacks, one cybersecurity firm is contending there is only way to end the threat—government bans on organizations paying the ransom.

In a new report, Emsisoft notes that in 2023 a total of 2,207 U.S. hospitals, schools and governments were directly impacted by ransomware over the course of the year, with many more being indirectly impacted via attacks on their supply chains. Additionally, thousands of private sector companies were either directly or indirectly affected, including banks and credit unions.

thumbnail_Feature Ransomware Study

As CUToday.info reported, 60 credit unions’ operations were recently hit by a ransomware attack on a third-party provider. Cybersecurity expert Jim Stickley told CUToday.info that credit unions, like other financial institutions, are not being specifically targeted, there are just being caught as crooks caste wide nets.

According to Chainalysis’ mid-year update, $449 million in ransoms was paid in the first six months of last year, with 2023 on track to be the second most profitable year to date for ransomware actors. The bulk of that $449 million was likely paid by U.S. organizations, Emsisoft said.

Other ransomware-related costs include business disruption, incident response, loss of intellectual property, and a plethora of other post-breach expenses including regulatory filings and notifications, the company said.

 ‘The Only Solution’

“We believe that the only solution to the ransomware crisis—which is as bad as it has ever been—is to completely ban the payment of ransoms,” Emsisoft states in the report.

The table below shows the number of organizations that were impacted in each of the last three years.

  2021 2022 2023
Hospital systems* 27 25 46
K-12 school districts* 62 45 108
Post-secondary schools 26 44 72
Governments 77 106 95
Totals 192 220 321

Emsisoft acknowledges the data is difficult to compile and certainly incomplete, as only a minority of ransomware incidents are reported or disclosed.

“Even when incidents are disclosed, it is not uncommon for organizations to use obfuscatory language—for example, referring to incidents as ‘encryption events’ rather than ‘ransomware attacks’—which makes search-based tracking challenging,” the report states. “While this report aggregates data from multiple sources, it is inevitable that some incidents will not have been counted and, consequently, the extent of the problem is almost certainly understated.”

Not Just About the Money

callow

Brett Callow

Emsisoft pointed to what it said is the enormous need to stop ransomware attacks, as they involve more than a loss of money.

“Ransomware is estimated to have killed about one American per month between 2016 and 2021, and it likely continues to do so. The longer the ransomware problem remains unfixed, the more people will be killed by it. And, of course, the economic harm and myriad of societal harms that ransomware causes will also continue for as long as the problem remains unfixed,” the company said.

Emsisoft pointed out that governments have formed task forces, international coalitions, and pledged at the federal level not to pay ransoms, while law enforcement has disrupted operations across the ransomware ecosystem, dismantled botnets, seized crypto assets, and made arrests.

“But despite all of this, ransomware stubbornly remains as much of a problem as ever,” the company said. “The only viable mechanism by which governments can quickly reduce ransomware volumes is to ban ransom payments. Ransomware is a profit-driven enterprise. If it is made unprofitable, most attacks will quickly stop.”

Pushing Through the Pain

Security researcher Kevin Beaumont believes there is only one place to start.

“I mean it—ransomware payments to these groups need to be outlawed, internationally,” Beaumont said in the report. “We have to push through the short-term pain because it is the safer option. Start planning for this, signal it loudly, and do it. This one needs firm leadership from the very top, as the lobbying against it will be real.”

Allan Liska, a threat intelligence analyst at Recorded Future, agreed.

“I’ve resisted the idea of blanket bans on ransom payments for years, but I think that has to change,” Liska said in the report. “Ransomware is getting worse, not just in the number of attacks but in the aggressive nature of the attacks and the groups behind them. What we are doing simply isn’t working.”

Can’t ‘Defend Way Out of Situation’

Brett Callow, a threat analyst with Emsisoft, is also a proponent of a ban.

“Current counter-ransomware strategies amount to little more than building speed bumps and whacking moles,” Callow said. “The reality is that we’re not going to defend our way out of this situation, and we’re not going to police our way out of it either. For as long as ransomware payments remain lawful, cybercriminals will do whatever it takes to collect them. The only solution is to financially disincentivize attacks by completely prohibiting the payment of demands. At this point, a ban is the only approach that is likely to work.” 

What 1 Report Found

In a 2021 report, the Ransomware Task Force—which consists of over 60 members from software companies, government agencies, cybersecurity vendors, financial services companies and more—noted that governments have avoided introducing bans, probably due to the potential impact on victims, according to the report.

“The challenge comes in determining how to make such a measure practical, as there remains a lack of organizational cybersecurity maturity across sectors, sizes of organization, and geographies,” the Task Force stated. “Ransomware attackers require little risk or effort to launch attacks, so a prohibition on ransom payments would not necessarily lead them to move into other areas. Rather, they would likely continue to mount attacks and test the resolve of both victim organizations and their regulatory authorities. To apply additional pressure, they would target organizations considered more essential to society, such as healthcare providers, local governments, and other custodians of critical infrastructure.

Emsisoft said in its report that if a ban was enacted the bad actors would quickly pivot and move from high-impact encryption-based attacks to other less disruptive forms of cybercrime.

“It would really make no sense for them to expend time and effort attacking organizations which could not pay,” the company said.

Potential for Short-Term Problems

Callow acknowledged banning payments may cause problems in the short-term for some victims.

“If ransom payments were to be banned, it wouldn’t happen overnight meaning organizations would have plenty of time to go shields up,” Callow emphasized. “Most attacks succeed because of security shortcomings so, in theory, most could be prevented. But, yes, not all would and there would be some short-term pain. Unfortunately, if we want to tackle the ransomware problem quickly, that pain is unavoidable. Those who advocate against a ban rarely have any alternative solutions that would quickly bring about an end to the ransomware crisis. That’s because there are none.”

Section: Standard
Word Count: 1740
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/A-Strategy-for-Addressing-Big-Risk-to-CUs