A Lawyer's Look at "Big Game Phishing"

Stu Sjouwerman | Oct 17, 2019

ransomware-screen-skullRansomware attacks have increasingly been going after high-value data in order to extract larger ransoms from victims, according to the well-known law firm Cooley. This trend was highlighted by the FBI’s recent warning about high-impact ransomware events. These attacks can target any type of organization that would be crippled by losing access to important data.

Attackers usually gain access via a phishing attack or a network configuration vulnerability such as an exposed RDP port. Once they’re in, they can move throughout the network and identify critical data before launching the ransomware attack.

Cooley says three of the most valuable targets for an attacker are “(i) high-value data or assets, such as trade secrets or personally identifiable information; (ii) critical timing issues or red-letter dates, such as tax-filing deadlines or the start of a new school year; and (iii) data backups.”

Additionally, Cooley points out that the costs associated with a ransomware attack include “not only paying the ransom demand but also expenses associated with lost business, time, files, equipment; wages; third-party remediation services; or higher insurance premiums.”

For large companies, ransomware attacks can be extremely costly, and for smaller organizations, one of these attacks could be a business killer. Organizations need to invest in countermeasures to prevent attackers from getting in. New-school security awareness training can address the human element and prevent your employees from falling for phishing attacks. Cooley has the story: https://cdp.cooley.com/big-game-phishing/

 

Ready to Build a Security Culture That Lasts?

Stop treating training like a checkbox exercise. Using 15+ years of behavioral data, our AI-powered platform personalizes training for every user to significantly reduce human risk and stop attacks before they start.

Get a Quote

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.