Berliner Boersenzeitung - Stuck in cyberattack nightmare? Call the negotiators

EUR -
AED 4.291518
AFN 81.206138
ALL 97.736885
AMD 448.444329
ANG 2.09153
AOA 1071.424762
ARS 1538.513486
AUD 1.78876
AWG 2.103124
AZN 1.953872
BAM 1.968524
BBD 2.359451
BDT 142.128682
BGN 1.955894
BHD 0.440525
BIF 3446.786616
BMD 1.168402
BND 1.503615
BOB 8.075718
BRL 6.311939
BSD 1.168553
BTN 102.445758
BWP 15.732702
BYN 3.857783
BYR 22900.683958
BZD 2.347424
CAD 1.609638
CDF 3376.682411
CHF 0.942217
CLF 0.028498
CLP 1117.98599
CNY 8.388193
CNH 8.392067
COP 4697.561217
CRC 591.159042
CUC 1.168402
CUP 30.962659
CVE 110.823138
CZK 24.469798
DJF 207.648098
DKK 7.462655
DOP 71.769097
DZD 152.001424
EGP 56.57635
ERN 17.526034
ETB 163.430286
FJD 2.631008
FKP 0.865009
GBP 0.864916
GEL 3.148828
GGP 0.865009
GHS 12.316664
GIP 0.865009
GMD 84.709161
GNF 10134.46136
GTQ 8.965953
GYD 244.495972
HKD 9.17187
HNL 30.773487
HRK 7.537947
HTG 153.210101
HUF 395.845331
IDR 18970.687023
ILS 3.984129
IMP 0.865009
INR 102.47131
IQD 1530.797603
IRR 49218.944625
ISK 143.258403
JEP 0.865009
JMD 186.928263
JOD 0.828386
JPY 172.848949
KES 151.308759
KGS 102.059755
KHR 4681.045545
KMF 492.481294
KPW 1051.489033
KRW 1616.080316
KWD 0.35698
KYD 0.973857
KZT 632.075665
LAK 25270.05346
LBP 104680.536659
LKR 351.8544
LRD 235.208338
LSL 20.682857
LTL 3.449988
LVL 0.706755
LYD 6.344856
MAD 10.572984
MDL 19.465373
MGA 5176.354661
MKD 61.585983
MMK 2452.751192
MNT 4202.030238
MOP 9.449284
MRU 46.648422
MUR 53.080516
MVR 17.994329
MWK 2027.428281
MXN 21.703913
MYR 4.931815
MZN 74.731006
NAD 20.682857
NGN 1792.909864
NIO 43.007993
NOK 11.922609
NPR 163.902449
NZD 1.961015
OMR 0.449248
PAB 1.168402
PEN 4.122345
PGK 4.852771
PHP 66.419579
PKR 331.726434
PLN 4.257197
PYG 8752.483121
QAR 4.254983
RON 5.06467
RSD 117.191251
RUB 92.829566
RWF 1689.495058
SAR 4.384877
SBD 9.616642
SCR 17.226659
SDG 701.623887
SEK 11.149548
SGD 1.498429
SHP 0.918181
SLE 27.108464
SLL 24500.810237
SOS 667.786307
SRD 43.719857
STD 24183.567431
STN 24.850587
SVC 10.225092
SYP 15191.507565
SZL 20.678146
THB 37.787268
TJS 10.92683
TMT 4.101092
TND 3.377074
TOP 2.813232
TRY 47.600159
TTD 7.929765
TWD 35.021103
TZS 3002.794345
UAH 48.486104
UGX 4159.864664
USD 1.168402
UYU 46.790316
UZS 14686.463752
VES 155.108362
VND 30694.923497
VUV 139.682586
WST 3.10576
XAF 656.222332
XAG 0.03051
XAU 0.000349
XCD 3.157666
XCG 2.106012
XDR 0.820612
XOF 656.222332
XPF 119.331742
YER 280.737791
ZAR 20.523091
ZMK 10517.007643
ZMW 26.966032
ZWL 376.225045
  • SCU

    0.0000

    12.72

    0%

  • CMSD

    -0.0107

    23.56

    -0.05%

  • JRI

    -0.0100

    13.38

    -0.07%

  • RBGPF

    0.0000

    73.08

    0%

  • CMSC

    0.0200

    23.08

    +0.09%

  • RIO

    0.9600

    63.1

    +1.52%

  • BCC

    3.5200

    84.26

    +4.18%

  • GSK

    0.5100

    38.22

    +1.33%

  • BCE

    0.1500

    24.5

    +0.61%

  • NGG

    -0.9500

    70.28

    -1.35%

  • SCS

    0.2300

    16.19

    +1.42%

  • AZN

    1.2700

    75.34

    +1.69%

  • RELX

    -0.2100

    47.83

    -0.44%

  • RYCEF

    0.6400

    14.94

    +4.28%

  • BTI

    -0.4100

    57.92

    -0.71%

  • VOD

    0.0300

    11.54

    +0.26%

  • BP

    0.1200

    34.07

    +0.35%

Stuck in cyberattack nightmare? Call the negotiators
Stuck in cyberattack nightmare? Call the negotiators / Photo: - - NATIONAL CRIME AGENCY/AFP

Stuck in cyberattack nightmare? Call the negotiators

Criminals have overtaken your computer network, they are threatening to leak your most sensitive secrets and your share price is tumbling. It's time to call in the negotiators.

Text size:

They might not wear capes, but this new breed of mediator -- who often has had prior careers in law enforcement and intelligence -- is increasingly on hand to help in such a nightmare scenario.

Britain's National Crime Agency (NCA) and law enforcement partners from several other countries announced Tuesday that they had smashed the cybercrime giant LockBit, whose ransomware attacks have caused billions of dollars of damage and stolen tens of millions from victims.

The gang had targeted governments, major companies, schools and hospitals since 2020.

Institutions of all shapes and sizes are still prey to the growing criminal threat, though.

In a ransomware attack, gangs -- sometimes state-backed -- hack into networks and demand payment either to unlock the system or prevent the release of top-secret data.

While cybercrime may conjure up images of lawless bandits operating in a world of anarchy, they are usually rational actors, according to Ram Elboim, CEO of US-based cybersecurity company Sygnia.

"It's not the Wild West, where people just shoot everywhere. Ransomware is a business. It's a huge economy," he told AFP during a London visit.

Elboim's company responds to desperate requests from clients under attack, often Fortune 500 companies, by setting up a team and jetting in to take on the criminals.

- 'Gun to your business' -

Integral to this team are the negotiators, who use their experience of dealing with "real-world" criminals to act as a go-between with online crooks, either helping foil the attack, or working out a price if all else fails.

"Usually we get a call, usually it happens on a weekend or the middle of the night. This is the time where organisations let down their awareness," said Elboim.

The first tasks are to understand the nature of the attack, how the attacker got into the network, what systems are down, how to contain the spread and recover any lost data.

"Then there is a negotiation piece," said Elboim, a former member of Israel's military intelligence unit known as "8200".

"You're talking with a criminal -- it's not a criminal who pulls a gun to your head, but there's a criminal holding a gun to your business.

"Usually, we advise you to start negotiations as soon as possible.

"If your only goal is to reduce the price from $50 million to $48 million then... just a good salesperson can do that.

"But usually attackers have some kind of a deadline, pay within 72 hours. The goal of the negotiation is to allow yourself more time to recover."

Another goal is to understand what the attackers are looking for and if you can attribute the attack to a specific group.

This is when the negotiators' expertise comes to the fore, setting up a channel of communication -- usually via a chat app or email -- and squeezing information from the criminals.

"It's not as if the attacker will give you information freely," said Elboim.

- Great reward -

In the best-case scenario, "we drag on the negotiations" for long enough and glean enough information to kick out the attackers and retrieve the data.

"After a few days of this game, the organisation can just... tell the hacker 'I'm not paying, do whatever you want'."

In the worst case, when the system appears lost and with crucial data about to be leaked, many institutions then have to decide whether to pay.

"Some organisations do not want to pay on principal. In some cases, the organisation is willing to pay but not willing to pay so much," with negotiators then haggling over a price.

Even if they pay the ransom and the network is decrypted, it is not plain sailing but rather the beginning of a long recovery process.

Attackers may promise not to attack again for a certain period of time, but there is no guarantee that the network is safe.

"We even had one case where we had a discussion with one attacker and he says 'okay, I move away' and then another came in and it's for sure they exchanged information, they knew everything the first one did," recalled Elboim.

But the rewards for a successful mission are great, he added.

"We had an attack... and the entire company was out, and this is a multinational organisation."

After repelling the attackers, "one of the guards at the entrance stopped us and said: 'Thank you for rescuing my work, now, I will not be hungry'.

"This is one of the most satisfying moments you can have."

(A.Lehmann--BBZ)