Eavesdrop on the Back-and-Forth of Negotiating with a Criminal Ransomware Organization



Transaction of Paying a Ransomware RansomDetails around the recent successful ransomware attack on fashion retailer FatFace provide some insight into what you should expect when you become a victim.

If you’ve paid attention to news stories about organizations hit by ransomware, the topic of paying the ransom inevitably comes up. But a recent story about how FatFace was hit by the Conti ransomware gang provided some first-hand details that I found fascinating.

According to the story over at Computer Weekly, the discussion about the ransom amount started at around $8 million. From the negotiation logs (shown below), the cybercriminals didn’t just come up with that number randomly. They looked through FatFace’s databases, and website traffic statistics to come up with their initial ask.

Conti-FatFace-ransom-1-800px_desktop

 

 

 

 

 

 

 

 

Source: Computer Weekly

What is equally fascinating is that when FatFace pushed back, Conti did some additional digging through the data they exfiltrated to find the cyber insurance policy in place and its’ coverage amount.

Conti-FatFace-ransom-2-800px_desktop

Source: Computer Weekly 

Ultimately, upon further negotiation, FatFace was able to reduce the ransom amount to $2.65 million.

I was happy to see that as part of their remediation steps to shore up security, FatFace included phishing testing (which is the feedback loop for Security Awareness Training to let the organization know which users need more training), as the combination of the two are extremely effective in reducing the end-user’s portion of the threat surface.

Read the full article over at Computer Weekly.


RanSim

Free downloadable software tool

Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?

RanSim gives you a quick look at the effectiveness of your existing network protection. RanSim will test 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.

RansIm-Monitor3Here's how it works:

  • 100% harmless simulation of real ransomware and cryptomining infections
  • Does not use any of your own files
  • Tests 25 types of infection scenarios
  • Just download the installer and run it
  • Results in a few minutes!

Get RanSim!

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/ransim



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews