Eavesdrop on the Back-and-Forth of Negotiating with a Criminal Ransomware Organization

Stu Sjouwerman | Apr 27, 2021

Transaction of Paying a Ransomware RansomDetails around the recent successful ransomware attack on fashion retailer FatFace provide some insight into what you should expect when you become a victim.

If you’ve paid attention to news stories about organizations hit by ransomware, the topic of paying the ransom inevitably comes up. But a recent story about how FatFace was hit by the Conti ransomware gang provided some first-hand details that I found fascinating.

According to the story over at Computer Weekly, the discussion about the ransom amount started at around $8 million. From the negotiation logs (shown below), the cybercriminals didn’t just come up with that number randomly. They looked through FatFace’s databases, and website traffic statistics to come up with their initial ask.

Conti-FatFace-ransom-1-800px_desktop

 

 

 

 

 

 

 

 

Source: Computer Weekly

What is equally fascinating is that when FatFace pushed back, Conti did some additional digging through the data they exfiltrated to find the cyber insurance policy in place and its’ coverage amount.

Conti-FatFace-ransom-2-800px_desktop

Source: Computer Weekly 

Ultimately, upon further negotiation, FatFace was able to reduce the ransom amount to $2.65 million.

I was happy to see that as part of their remediation steps to shore up security, FatFace included phishing testing (which is the feedback loop for Security Awareness Training to let the organization know which users need more training), as the combination of the two are extremely effective in reducing the end-user’s portion of the threat surface.

Read the full article over at Computer Weekly.

Ransomware Simulator

Free downloadable software tool

Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?

RanSim gives you a quick look at the effectiveness of your existing network protection. RanSim will test 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.

RansIm-Monitor3Here's how it works:

  • 100% harmless simulation of real ransomware and cryptomining infections
  • Does not use any of your own files
  • Tests 25 types of infection scenarios
  • Just download the installer and run it
  • Results in a few minutes!

Get RanSim!

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.