Ransomware Evolution

Hosted By Chris Parker

341
Click Below to Subscribe
“Ransomware is still one of the most profitable types and has a relatively low barrier of entry to get in.” - Allan Liska Share on X

Ransomware has changed dramatically over the years. What started as criminals locking up individual computers and demanding relatively small payments has grown into a much larger operation involving stolen data, entire networks, third-party vendors, and increasingly sophisticated ways of pressuring victims to pay. Now AI is adding another wrinkle, giving criminals new tools while also creating some unexpected problems for them.

Joining me to talk about how ransomware has evolved is Allan Liska, a ransomware researcher and Field CISO at Recorded Future. Allan has more than 30 years of experience in information security and has spent the last 12 years researching ransomware. He has advised major corporations and government agencies, served on national ransomware task forces, and written extensively about ransomware and threat intelligence.

We talk about how ransomware became the business it is today, why small businesses can be just as vulnerable as larger organizations, and how attackers are increasingly going after trusted vendors instead of their intended targets directly. We also discuss what happens inside an organization after an attack, why disrupting ransomware groups really can make a difference, how AI is being used by criminals, and some of the mistakes ransomware operators make that ultimately work against them.

“It’s not just how is your data secured, but how is your partner’s data secured and your partner’s partner’s data secured.” - Allan Liska Share on X

Show Notes:

  • [01:06] Allan Liska introduces himself and shares how his work at FireEye led him to begin researching ransomware more than a decade ago.
  • [03:10] Growing ransomware problems pushed Allan and other researchers to begin developing better detections for attacks that many security teams were overlooking.
  • [05:22] Ransomware evolved from attacks on individual computers to taking down entire networks and later stealing data to pressure victims into paying.
  • [06:30] Publicly naming victims gave ransomware groups their own form of publicity and made it much harder for organizations to quietly deny an attack.
  • [08:05] Encryption creates technical challenges for criminals, and stealing valuable data can sometimes be just as effective as encrypting an organization’s systems.
  • [09:28] Attackers increasingly target vendors and partners, while some groups are now using AI to create fake stolen data and falsely claim organizations as victims.
  • [13:05] Chris and Allan discuss how transparency and regular communication can help organizations manage public trust after a security incident.
  • [14:35] Ransomware response can quickly lead to employee burnout, making outside coordination and basic needs like sleep, food, and scheduling an important part of incident management.
  • [16:14] A major breach may temporarily open security budgets, so organizations should already know which improvements they would prioritize after an incident.
  • [23:29] International law enforcement agencies have become increasingly creative about tracking ransomware operators and waiting for them to make mistakes.
  • [25:48] Being skilled at hacking does not necessarily mean criminals are equally skilled at protecting their identities or activities from intelligence agencies.
  • [28:21] Ransomware groups frequently make technical and strategic mistakes, including faulty AI-generated tools, reused encryption keys, and stealing data nobody considers valuable.
  • [29:36] Fewer ransomware victims are paying, but average payments are increasing, and ransomware remains profitable enough to attract new threat actors.
  • [33:09] Allan explains why simply banning ransom payments may not work and discusses approaches that could give governments better intelligence about where payments go.
  • [39:33] Collaboration remains an important part of ransomware research, and Allan encourages people entering the field to learn from other researchers and security communities.
“Even though ransomware research can be a lonely job, we rely on other researchers. We help each other out, and that is what works best in this industry.” - Allan Liska Share on X

Thanks for joining us on Easy Prey. Be sure to subscribe to our podcast on iTunes and leave a nice review. 

Links and Resources:

Transcript:

Allan, thank you so much for coming on the podcast today.

Hey, thank you for having me. I'm really excited to be here.

As am I. Can you give myself and the audience a little bit of background about who you are and what you do?

Yeah, my name is Allan Liska. I am a ransomware researcher and field CISO at Recorded Future, which is a threat intelligence company. And I've been researching ransomware for about 12 years now. You can take that one of two ways. Either I really know what I'm talking about, or since ransomware has only gotten worse, I really suck at my job. Or maybe both are true.

Or neither. OK, so I'm curious. What got you into the ransomware threat research?

At the time, I was working for FireEye, and FireEye had released its APT1 report on Chinese nation state activity. It was a huge blockbuster report. We were going around and talking to our clients, and we would bring up all of this nation state activity. But I noticed this challenge with not the big enterprise customers, not, like, the financial sector and so on, but more the regular-sized enterprise customers. I go and I talk to them about nation state.

And they would tell me, “That's great, but my problem right now is I have seven ransomware attacks happening every week.” This was in the days of Locky and Server where it's a single machine. You'd encrypt somebody's machine, ask for $300, maybe $1,000, and the IT department would go, “Well, no, I'm not going to do that. I'm just going to wipe and replace.” Or unfortunately, some people would be embarrassed about getting hit. They pay it quietly with their personal credit card or whatever.

It was one of these things where more and more companies were telling me that this was the biggest problem that they had. I would talk to the detection team in FireEye. I'm like, “Hey, this is a real problem.” Often, I would get ignored. But FireEye had acquired Mandiant. Some of the Mandiant researchers were seeing the same thing that I was.

We got this kind of tiger team together of how do we build detections? Offering a solution to the problem, we would build the detections and then give it to the platform team to put into the platform. I got really, really immersed in the world of ransomware. It's just obviously gotten a lot worse since then.

Let's talk about kind of the evolution of ransomware. Because when you talked about ransomware in your first example there, I was like, “Oh, I remember those.” But I haven't heard a person talk about ransomware in that way in 15 years. What has kind of been the the arch of ransomware?

Well, it's funny, though, you haven't heard anybody talk about it. But the most prolific ransomware is still STOP/DJVU, which is a single machine ransom of ransomware that asks for a $500 to maybe $700 ransom payment. It just doesn't usually hit even moderately well-protected machines. It’s, like, insanely popular. Popular is not the right word. Prolific in India and Bangladesh and places like that. It's just been going on for 15 years now.

But broadly speaking, the way that it's changed over time is we've gone from single-machine ransomware. And then in 2016, Hollywood Presbyterian was hit by the Samsung ransomware group. They took out the entire hospital, right? They infected several hundred machines and asked for it. I think, “God, although I don't know that there was any formal acknowledgement of that, an unheard of $17,000 ransom.”

Very quickly, all the bad guys were like, “Oh, I can get $17,000 from just one ransomware attack.” We saw that model shift to, “OK, great, now we're going to take out whole networks.” Then in 2019, we saw maze ransomware add another component to it when they released—they started releasing data. They would steal data. We knew that bad guys were stealing data during attacks, we just weren't sure what they were doing with it.

Honestly, I don't think the bad guys knew what to do with it. They hadn't figured out how to monetize that. So maze ransomware comes along and they set up a website and like, “Hey, if you don't pay us, we're going to publish the data.” They weren't the first to do it, but they were the first to do it effectively. The only mistake they made is the first domain they used was called mazenews.top.

They hit a company in Ireland. The Irish company went to the Irish courts and said, “Hey, we want that domain taken down.” Irish courts are like, “Oh, yeah. You can't publish stolen data.” Irish courts sent a letter to the registrar who then took the domain down. And so maze had to move to an onion domain. That is where kind of it's resided ever since. But that served two purposes that really helped the explosion of ransomware, because now, before what you had was, “OK, we think there was an attack,” and the company and its lawyers would deny, deny, deny.

Now, on the other hand, you had the threat actors who were very much like, “Oh, no, no. We hit them. Here’s our evidence.” Suddenly, and it’s, I think, the first time we've ever seen this, basically, the bad guys had their own PR operation. Like, the only equivalent I can see is, you know, occasionally, you'll get a guy who knocks up a gas station, and then post on Facebook that he robbed the gas station and the police nab them.

But you know, we hadn't seen organized crime do this. That just led to this explosion of ransomware. We continued on that trend for a few years. And then the bad guys started to realize that encryption is really hard. Managing keys and all that other stuff. There's this great book that Max Smeets wrote, called Ransom War, where he talks about all of the challenges with ransomware, and he has this, he uses the term the ransomware trust paradox, where ransomware are a bunch of thieving bastards. Hopefully I can say that word on your podcast.

But you have to trust them enough that if you give them money, they will give you the key. They won't, you know, and they will actually delete your files, even though we know they don't actually delete them, but they'll at least not keep them published anymore. Managing encryption in that way is a challenge, like, just because you give somebody a key, doesn't mean it's actually going to decrypt files.

Anybody who's ever done ransomware incident response will tell you, most of the time, the tools that they give you don't work, and you have to write new tools. The bad guys have figured out that, “Oh, if I steal data, I'm just as… Share on X

Anybody who's ever done ransomware incident response will tell you, most of the time, the tools that they give you don't work, and you have to write new tools. The bad guys have figured out that, “Oh, if I steal data, I'm just as likely to get paid if I steal the right data.” Then they figured out, “But I don't even have to break into your network now. I can go to any of your partners or your partners’ partners, or your partners’ partners' partners. And if your name is on the data, I can post you as the victim, and everybody will say, ‘Oh, they were the victim, not the third-party vendor’”. And so we're seeing a lot of that with, like, the Oracle plugins and the Salesforce plugins and all these tools that so many companies rely on that are relatively small companies, software companies without a big security staff, they're now being targeted.

The marketing department at my company hates this analogy, but I liken it to the STD PSAs from the 90s, where it's not just who you slept with, but who they slept with and who they slept with. Now it's not just how is your data secured, but how's your partner's data secured and your partner's partner's data secured. And then this year, the most recent thing that we're seeing—and I apologize for this long soliloquy—is we've seen a couple of campaigns now where the bad guys just use AI to create fake data and list victims on their website that are completely fake.

Now it's not just how is your data secured, but how's your partner's data secured and your partner's partner's data secured. -Allan Liska Share on X

That creates a whole new challenge, because now it's not having to know where your data is. It's how do you prove a negative? How do you prove to your CEO and your board that that's not actually your data? And what kind of data governance are you doing? And security and data governance have always been two separate operations. You and I have been doing this for a long time. Security doesn't talk to the governance people, but now you really have to be able to show that that data didn't actually come from us. It is made up.

And that's got to be a particularly challenging, like if it's just let's assume it's just a simple CRM, you know, customer contact list. Well, that changes over time. What could have been gotten from for ransomware or breach may have been accurate then, but it's not accurate now. If you don't know when they got the data, you can't verify, is that really our data?

Right. Then you have to look at a combination of data structures. How is this data being stored in this particular vendor and also the reliability of the group? “Oh, this group is known to post fake data. OK. Those two things combined, it doesn't look like the data structure of any of our vendors. Also, this group are even more so than most ransomware groups, a bunch of liars. This is most likely fake.” I have medium confidence—and everybody hates analyst speak—but you really have to get into that of I have medium confidence, high confidence that this isn't real data.

And even if it's not real data, it still poses a PR risk to the company. Even if you get out there and say, “No, that's not our data. These guys are lying.” Some percentage of viewers are going to go, “No, I think you're the one who's lying.”

Well, right. Because we've seen 20 years of companies downplaying a potential breach until they can't downplay it anymore. I don't want to say dishonesty, I don't think that's the right word, but I think that that kind of CYA has really hurt the public trust in any breach announcements that come out.

There was one vendor that I was working with that—a small organization that they came out and said, “Hey, we just found out we were breached. Here's what we know. Here's what—we found this out yesterday. We're telling you today because we value our integrity. If you want to switch vendors, like, we will help you do that, but we want to let you know, like, this is what we think happened. This is what we're looking into. Here are the timetables where we're going to continue to provide you updates.”

And they did every, whatever window that they said, they came through and answered as much information as they had at each of those times. They said, “We'll provide you an update,” and made me go, “OK, yes, they had a security incident.” But also, “Yes, they're trying to manage it.” Well, as opposed to pretend it didn't happen. And hopefully it'll just go away if no one talks about it anymore.

I think that they're the valid strategy that I get the worry because if you get hit with ransomware or basically any kind of attack, you're going to get sued. I know a lot of people are afraid the loss is going to be worse. If you're more transparent, that hasn't been my experience, but you can't tell people who are trying to protect their business and survive that, “Oh, yeah, you should definitely be more transparent” if they're worried that it's going to be an existential crisis for their business.

I think lots of people, that is their perspective of, “If I don't deal with this, it's either all or nothing. Either I totally make it out of this OK, or I go out of business as a result of this.”

Unfortunately, yes.

What have you seen in terms of, like, how organizations respond to ransomware? Because we're kind of talking about that.

I'm always amazed at how people come together. When they've been hit with ransomware, especially a wide-ranging ransomware attack, like, every department wants to come in and help. I appreciate that. -Allan Liska Share on X

I think it's I'm always impressed. I don't do it as much anymore, but I did ransomware incident response for years where I was actually on site and so on. I'm always amazed at how people come together. When they've been hit with ransomware, especially a wide-ranging ransomware attack, like, every department wants to come in and help. I appreciate that.

But I also am fully aware of something like 60% of security people who have been through a ransomware attack leave that job within six months because of burnouts, because you are there, you are responsible, and you want to get this better. We all have that desire. I have been in ransomware incident response where they had to force people to go home because they wanted to keep working until they passed out.

That's just not healthy. That's why I advise every organization I talk to, make sure you have a breach coach, make sure you have somebody outside of the security organization that is kind of a go-to contact and is managing schedules, things like get food for everybody. Make sure that they have the kind of drinks that they like, but also tell people to go home.

Eventually, no matter how important this is to you, you are going to be less effective when you haven't slept for, you know, 24 hours or whatever. Managing that, I think, is really important. Eventually, it does evolve into finger pointing and so on. I do think that there's a lot of that. I also think it's really interesting how much the security budget opens after a big security attack, things that people have been asking for years.

I also think it's really interesting how much the security budget opens after a big security attack, things that people have been asking for years. -Allan Liska Share on X

Suddenly, they're like, “Oh yeah, sure, we can do that for you. We can do that for you.” It doesn't last forever, but at least for a couple of years you have budget. And that's where you have to be careful. I tell people part of your incident response plan should be if you do get hit with ransomware, which I hope doesn't happen.

Suddenly that budget does open up. Have two or three top priorities that you are going to ask for immediately because otherwise, and I've seen this again and again, so much of that suddenly free budget is going to go to consultants. I don't have anything against consultants, but that can eat up money that could have gone to something that could make a long-term difference.

And I think that's one of those challenges with any organization of how do you show the ROI on we prevented. “We can't tell you what it would have cost of the things that we prevented.”

Right. We didn't get hit with ransomware this year. We saved the company. You can say things like, “You know, the average ransomware cost the company 123 a million dollars and we didn't get hit with ransomware.” I'm making that number up. It's no workloads to that, but you can say that, but yeah, but that's not the same as when you're actually hit and dealing with that cost.

For some organizations, they look at that balance and they go, “You know what? We're not going to fully invest in security. We're willing to take that cost, or our cyber insurance will cover a lot of that recovery costs. We're going to let the cyber insurance worry about it and worry about the premium changes or getting canceled afterwards.”

I've heard a lot of small business owners talk about like, “Oh, I don't need to worry about this because I'm not a target. I'm not a Fortune 500 company. These organizations are only going after Fortune 500 companies. I don't need to worry about it.”

One of the big trends during sort of the height of the pandemic when most people were working remotely is we saw big hits against auto dealerships and dentist offices, which again, in the world of ransomware is relatively small, but you may be the biggest employer in your town, right?

And while those ransom demands were in the 20 to maybe $50,000 range, which again, compared to some of the others we've seen doesn't seem like a lot but that can put a dental office out of business, or that can put an auto dealership out of business. So yes, there are companies that are targeting you precisely because they know you don't have a security team in place, precisely because they know you don't have cyber insurance. You don't have the resources to better protect yourself.

There are companies that are targeting you precisely because they know you don't have a security team in place, precisely because they know you don't have cyber insurance. You don't have the resources to better protect yourself.… Share on X

So they can, they think they can extract the ransom from you. A lot of times it just means they shut down. They go out of business because they can't afford the ransom payment or they refuse to pay the ransom, but they also can't recover all of their customer records and everything are locked up. If you are a small business, you can absolutely be targeted and hit, and don't think that they won't try and extract every last dollar out of you that they can.

If you are a small business, you can absolutely be targeted and hit, and don't think that they won't try and extract every last dollar out of you that they can. -Allan Liska Share on X

I know in the past, there have been some very large, well-known ransomware groups that have been taken offline. Does that actually change the ransomware landscape when that's happened?

It actually does. If you look at, like, Operation Endgame, which is a joint operation between the U.S., Europe, whole and multiple other countries, they have had a lasting impact on disrupting ransomware operations. And more importantly, they've disrupted a lot of the initial access operations. We generally talk about a ransomware attack in terms of one group. Akira hit this or Kulin hit this. Generally, the way it works is a multi-phase operation.

You have groups who are called initial access brokers and they gain access to those networks. And then they turn around and sell those networks to operators that work for these different ransomware groups. So it's a whole lot of freelance economy type thing. If you can disrupt, you know, we always talk about it and I really don't like this term, but left of boom. If you can disrupt the ransomware attack earlier in the operation, you're more effective at stopping it.

If you can disrupt the ransomware attack earlier in the operation, you're more effective at stopping it. -Allan Liska Share on X

Disrupting these phishing services or these initial access brokers goes a long way to slowing down the number of ransomware attacks. We've seen real impacts on that. Now, there's always another bad guy willing to take their place. I tell people that you have to not think like Gloria Gaynor in “I Will Survive,” where she says, “I should have changed that lock. I should have taken your key. If I'd known you'd be back here bugging me.”

When you see a disruption like that, when there's a big announcement in that, that breathing room is a chance to make improvements to your security. You'll hopefully be a little less reactive for at least a short period of time. And you can go, “Oh, you know what? This thing we've been meaning to implement, let's go ahead and try and take some time to do that. And hopefully, we'll have a period of time where there aren't going to be, you know, these critical events that we have to deal with one after the other.”

Is there like—we were talking before we were recording about, like, the internet storm center of kind of, we can see the internet traffic from different places stop and go and weird things happen. That catches our attention. Is there kind of a sharing of ransomware data from threat researchers that kind of, “Hey, today, on a scale of one to 10, ransomware incidents are at a nine or a seven.” Or, “Hey, this large group got taken out and it's now a two for the next week.”

I love the ransomware.live website. Julian is a researcher in France, and he does a fantastic job of tracking what's going on with ransomware, who the latest victims are, but also what groups are up and down and stuff like that.… Share on X

I love the ransomware.live website. Julian is a researcher in France, and he does a fantastic job of tracking what's going on with ransomware, who the latest victims are, but also what groups are up and down and stuff like that. That is a really good resource for understanding where things currently are in the world of ransomware. But also if you don't mind boring, long-winded PDFs subscribing to CISA alert list and Europulse alert list.

You can get those kind of updates from them because they're really proud when they take down one of these groups or shut down one of these groups, and they will proudly announce that. Again, it's going to be in a 20-page PDF, most of which is boring, but at least you'll have that information.

I love that they are getting so much more creative and you realize how much intelligence they have on these threat actors. A lot of people are like, “Well, you can't do anything there in Russia.” But Russia's boring, man, especially now. It's not just boring. It's dangerous. These guys like to leave. Do you know the story of how they captured the guy behind the raccoon stealer?

No, I don't.

OK. So the raccoon stealer was one of these initial access tools. This guy lived in Russia and he was, you know, for $300 a month, you could rent his infrastructure. So for less than a car payment for most people, you could go after 100,000 new victims a month and potentially monetize whatever data you're able to collect from the raccoon stealer. Well, when Russia invaded Ukraine, he decided he was going to get out and he left and went to Poland.

This guy's got really good OPSEC. Unfortunately, his fiancé is an Instagram model—her title, not mine. And again, because you have all of this incredible intelligence sharing from these agencies around the world, they were tracking her movements. She posted when they got to Poland. Like from a town square, “We're starting our new life, blah, blah, blah.” They knew where they were, you know, the Europol and the DOJ reached out to Polish law enforcement.

And now he's on trial in Arizona, you know, and so there's a lot that they know. The bad guys make mistakes. We talk about that in security all the time; you have to be perfect all the time. Because if you make one mistake, there's plenty of bad guys that'll get in. It's the same for the bad guys. Every intelligence agency is watching you all. And you may be able to avoid detection from a random researcher like myself. But when GCHQ and the NSA is looking at you, man, they know what you had for lunch. They may not be able to touch you in Russia, but you step out, they know about it, and they will take you down.

We talk about that in security all the time; you have to be perfect all the time. Because if you make one mistake, there's plenty of bad guys that'll get in. It's the same for the bad guys. Every intelligence agency is watching you… Share on X

It's an interesting flip on the script, because we often think, have this mindset that like, “Oh, if they're really good at breaching systems, they have good personal security, or they can keep themselves safe in an entirely different landscape in the real world.” But just because I'm good at hacking doesn't mean I'm good at protecting my real life.

Right. There's good OPSEC and there's NSA good OPSEC, right? That’s a very different, two very different levels of OPSEC that you have to have. It is really hard to have NSA good OPSEC.

That's interesting. Do you have any interesting stories about ransomware victims that have either recovered their data kind of accidentally, so to speak, or where the threat actor has just made some massive mistake that revealed themselves?

Oh, yeah, I mean, ransomware actors make mistakes all the time. You don't hear about those, because I can't sell you a security product. If I tell you how bad the ransomware actors are, like, I would love to do a series of blog posts on how dumb some of these guys are. But again, that doesn't sell anybody anything in security.

One, so many ransomware groups are, and I hate to bring up AI again, but trying to use AI to develop these ransomware tools. But AI will do things like call fake libraries. We've seen new ransomware groups that are like, “Oh, I don't need to rent ransomware infrastructure from one of these ransomware-as-a-service operators, I'll just build my own with AI.” Then it doesn't actually encrypt. It tells the bad guy that it encrypted, “Yes, all your files are encrypted.”

But because it was calling a fake library, it doesn't actually encrypt. And that's, again, where I talked about encryption is hard. That is one of those where implementing that encryption is actually a challenge, whether you're trying to use AI to build the tool, or whether you've built the tool yourself. We've seen so many bad guys that were like, “Oh, they just use the same key for every victim.”

And once one victim pays for the key, researchers or law enforcement realizes, “I can use that for a whole bunch of them.” We also saw one of the campaigns that Cl0p did last year. They’re a ransomware group that they specialize in developing zero days, which is a vulnerability that's previously unreported. And then they mass exploit. They’ll hit 3,000-4,000 victims at once. Well, last year, they launched a campaign, and almost nobody paid, because they focused on a tool that's used by logistic companies, and the data they stole was all package tracking, which, “OK, go ahead. Publish our package tracking. Nobody cares.”

There's nothing that you can get out of that that's worth stealing. Not understanding what is an actual threat. Sometimes those bad guys run into those problems. And again, that makes life easier for the people who are trying to defend themselves. Yes, we got breached, but we don't care if you publish that data.

Are you seeing a trend of more or less organizations actually paying the ransomware or paying the ransom?

We, on average, right now, for this year, we see fewer victims paying, but when they are paying, on average, it's a higher dollar amount. Inflation has come to ransomware along with everything else. I think that's been a kind of a trend that's been ongoing where—so one of the things we're seeing is the number of victims has gone up significantly. Because there are all of these—the way you count victims is always a challenge, right?

If I breach a tool, and that tool has 8,000 customers, I now have 8,000 victims in theory, right? But the percentage of people who are paying a ransom has gone down, which is great. Unfortunately, if you are paying more on average, that means the bad guys are still making money. There are more threat actors involved in ransomware than ever before. Because when you look at things, like, you used to be able to make money selling credit cards.

Credit cards are almost—that market is dried up, because they're just not worth a lot of money because the banks have gotten really good at flagging fraudulent transactions and shutting down a card. And people are really good about watching for alerts on that. The tools are there.

My wife, anytime she makes a credit card transaction, she gets a text from the bank, because she doesn't use that card very often. She wants to know immediately if there's fraud. And so ransomware is one of those few things where you can still make money. Because business email compromise, you can make money too, but you have to have a certain type of threat actor that does that. That's why, and it's really weird to see the way different parts of the world have developed different…. Russia, which has a long history of math and software development, that's ransomware.

You go down to Nigeria and Kenya, where it's largely English speaking, that’s where BEC has really grown and developed. And then if you go to, like, Malaysia and Thailand, that's where you see the scam call centers, because you can hire a thousand people to work there and it's dirt cheap. I know you've done a show on this; I use “hire” very loosely here.

It is weird to see, and Brazil banking trojans have been like that. That’s the sort of the center of all of the banking trojans that have developed over the years that have now become info-stealers. It is weird to see how they develop in these different things. But ransomware is still one of the most profitable types and has a relatively low barrier of entry to get in. So we see more threat actors migrating to ransomware.

What is your view on countries making ransomware payments illegal?

It doesn't work, unfortunately. I did a study a while back on Italy banning ransom payments. In the 70s and 80s, there was a spate of kidnappings in Italy. And so the way that the Italian government solved the problem is they banned ransom payments. You couldn't pay kidnappers. And then they bragged about how kidnappings went down significantly.

But if you look at the number of reported kidnappings, it was already on the steep decline when they implemented this law. There is no evidence that banning payments works. If it is a multinational company, they will have a subsidiary in another part of the world that can pay it. I like the British model that they are proposing a little bit more, which is basically a license to make a payment.

You get hit with ransomware, you reach out to the British government, to the NCA, which is their National Crime something, and say, “Hey, we're hit. We can't recover. We need to make a payment.” The British government says, “Great, send us the details so we have it. And then go ahead and make the payment.” That allows GCHQ and their intelligence services to track where the money is going, how it's being spent. Then if there's a chance to get that money back or gather more intelligence about this group, they're able to do that.

I don't like the idea of payments. I wish nobody would ever make a payment because all you're doing is making them more successful. But I've seen hospitals, I've helped out at hospitals that if they don't make the payment, there's a good chance people are going to die. So far, no government I've talked to has adopted my drone strikes for ransomware actors program. But if they ever do that, then, you know, that that's kind of the better alternative.

Yeah, I mean, it really is a particular challenge, particularly hospitals of if we don't do this, someone will likely die. And how much do you about, you know, nobody wants to be the person who says, “I decided the human life is worth this amount of money.”

Right. That’s a decision that no hospital administrators should ever have to make. It sucks that they do. But if that's the reality, I mean, it's also the reality that, as concerned as we are about it, we keep not coming up with programs that help hospitals, especially rural hospitals, better secure themselves. Because you can't just drop money in a rural hospital and say, “Oh, use that for security,” because they're going to say, “Hey, man, I've got 100 heroin cases coming in every month. If you're going to give me money, I'm going to build a drug treatment facility, or I need help with our maternity ward or whatever.”

You need to have a way that you can specifically give them the resources they need to better do security. I've often thought that, in particular, we need, like, an AmeriCorps for cybersecurity, where, “Yeah, we'll pay for your four-year degree in cybersecurity. You go work at a rural hospital at, you know, reduced pay for two years, or at a rural government or something like that, where you can get real-world experience.” They can get the help that they need. Because you can't just solve the problem with technology; you need the people in place as well.

I like that. Any advice for people who want to get into ransomware research, or tracking, or kind of doing the things that you do?

Don’t. It's too depressing. Security is still one of it…. It's getting harder and harder. And security is still one of those fields where you don't necessarily need a degree in security to get involved and to start working on it. I studied sociology now, admittedly, that was 40 years ago. There was no cybersecurity program. I didn't even have a computer science program. I just studied sociology.

Do the research, understand what's going on, do not the thing that everybody thinks is super, super sexy about ransomware research is, “Oh, you can talk to some of the threat actors.” Don't do that. You don't have the proper tools and protections in place. Because the ransomware actors want to talk to you. They love talking to people. I have researchers that some of these ransomware actors consider, like, their best friends or close friends or whatever, and not realizing that the researcher’s feeding all of that information to the FBI.

Don't do that. Even though that looks like fun, it's not. You're not fully prepared for that. You could wind up with the FBI knocking on your door, or wherever you live. Focus on looking at the techniques that the bad guys are using, figuring out, “Hey, what can organizations do better to protect themselves, and understanding the cloud.”

Because right now, that's where the action is and how SAS operates and how SAS can be secured, how you can track that data, etc. Those are kind of the things that I look at all the time. Also, be part of groups, right? There are a lot of really good ransomware sharing groups that are out there. I always tell people, “Find your local B sites and go hang out there, listen to some of the talks.” Those cons are usually pretty cheap to get into.

Some of them even have free access for students. And you can start to learn a lot and build connections that way. We rely, as researchers, even though it's a lonely job, we rely on other researchers. I have a book that I contributed a chapter to that's coming out later this year called The Ransomware Gang. It's a group of other ransomware researchers that I have daily conversations with, share information, again, without violating any of my employment or, you know, contracts.

Even though we all work for competitors and different companies, we help each other out, we help make each other better. And that is what works best in this industry is when you’re working with others to make everybody more successful.

Even though we all work for competitors and different companies, we help each other out, we help make each other better. And that is what works best in this industry is when you’re working with others to make everybody more… Share on X

Awesome. If people want to connect with you, how can I find you?

The best way to get ahold of me is on LinkedIn. It's just Allan Liska on LinkedIn, little green arrow icon. That's me. Green arrow, the superhero, not like the stock green arrow.

The Ryan Reynolds green.

No, that was Green Lantern.

That was Green Lantern. I got that wrong. Wrong Marvel reference. Alan, thank you so much for coming on the podcast today.

Thank you for having me. I absolutely love your show, and I'm excited to be a part of it. And I hope more and more people watch and listen to your podcast.

About Your Host

Chris Parker

Chris Parker is the founder of WhatIsMyIPAddress.com, a tech-friendly website attracting a remarkable 13,000,000 visitors a month. In 2000, Chris created WhatIsMyIPAddress.com as a solution to finding his employer’s office IP address. Today, WhatIsMyIPAddress.com is among the top 3,000 websites in the U.S. 

Share Post:

COULD YOU BE EASY PREY?

Take the Easy Prey
 Self-Assessment.

YOU MAY ALSO LIKE

Kari
Kammel

The Counterfeit Economy

Nina
Jankowicz

The Internet is Playing You

Vanessa
Bohns

The Psychology of Yes

Dawn
Dines

Drink Spiking

Sharon
Armstrong

Love, Lies and Locked Up

PODCAST reviews

Excellent Podcast

Chris Parker has such a calm and soothing voice, which is a wonderful accompaniment for the kinds of serious topics that he covers. You want a soothing voice as you’re learning about all the ways the bad guys out there are desperately trying to take advantage of us, and how they do cleverly find new and more devious ways each day! It’s a weird world out there! Don’t let your guard down, this podcast will give you some explicit directions!

MTracey141

Required Listening

Somethings are required reading – this podcast should be required listening for anyone using anything connected in the current world.

Apple Podcasts User

Fascinating stuff!

I’ve listened to quite of few of these podcasts now. Some of the topics I wouldn’t have given a second look, but the interviewees have always been very interesting and knowledgeable. Fascinating stuff!

Apple Podcasts User

Excellent Show

Excellent interview. Don’t give personal information over the phone … it can be abused in countless ways

George Jenson

Interesting

I’ve listened to quite of few of these podcasts now. Some of the topics I wouldn’t have given a second look, but the interviewees have always been very interesting and knowledgeable. Fascinating stuff!

User22

Content, content, content!

Chris provides amazing content that everyone needs to hear to better protect themselves and learn from other’s mistakes to stay safe!

CaigJ3189

New Favorite Podcast!

Entertaining, educational and I cannot 
get enough! I am excited for more phenomenal content to come and this is sthe only podcast I check frequently to see if a new episode has rolled out.

brandooj

Big BIG ups!

What Chris is doing with this podcast is something that isn’t just desirable, but needed – everyone using the internet should be listening to this! Our naivete is constantly being used against us when we’re online; the best way to combat this is by arming the masses with the information we need to stay wary and keep ourselves safe. Big, BIG ups to Chris for putting the work in for us.

Riley

As seen on

COULD YOU BE EASY PREY?

Take the Easy Prey Self-Assessment.
close

Copy and paste this code to display the image on your site

Privacy Policy

Your privacy is important to us. To better protect your privacy we provide this notice explaining our online information practices and the choices you can make about the way your information is collected and used. To make this notice easy to find, we make it available on every page of our site.

The Way We Use Information

We use email addresses to confirm registration upon the creation of a new account.

We use return email addresses to answer the email we receive. Such addresses are not used for any other purpose and are not shared with outside parties.

On occasion, we may send email to addresses of registered users to inform them about changes or new features added to our site.

We use non-identifying and aggregate information to better design our website and to share with advertisers. For example, we may tell an advertiser that X number of individuals visited a certain area on our website, or that Y number of men and Z number of women filled out our registration form, but we would not disclose anything that could be used to identify those individuals.

Finally, we never use or share the personally identifiable information provided to us online in ways unrelated to the ones described above.

Our Commitment To Data Security

To prevent unauthorized access, maintain data accuracy, and ensure the correct use of information, we have put in place appropriate physical, electronic, and managerial procedures to safeguard and secure the information we collect online.

Affiliated sites, linked sites, and advertisements

CGP Holdings, Inc. expects its partners, advertisers, and third-party affiliates to respect the privacy of our users. However, third parties, including our partners, advertisers, affiliates and other content providers accessible through our site, may have their own privacy and data collection policies and practices. For example, during your visit to our site you may link to, or view as part of a frame on a CGP Holdings, Inc. page, certain content that is actually created or hosted by a third party. Also, through CGP Holdings, Inc. you may be introduced to, or be able to access, information, Web sites, advertisements, features, contests or sweepstakes offered by other parties. CGP Holdings, Inc. is not responsible for the actions or policies of such third parties. You should check the applicable privacy policies of those third parties when providing information on a feature or page operated by a third party.

While on our site, our advertisers, promotional partners or other third parties may use cookies or other technology to attempt to identify some of your preferences or retrieve information about you. For example, some of our advertising is served by third parties and may include cookies that enable the advertiser to determine whether you have seen a particular advertisement before. Through features available on our site, third parties may use cookies or other technology to gather information. CGP Holdings, Inc. does not control the use of this technology or the resulting information and is not responsible for any actions or policies of such third parties.

We use third-party advertising companies to serve ads when you visit our website. These companies may use information (not including your name, address, email address, or telephone number) about your visits to this and other websites in order to provide advertisements about goods and services of interest to you. For information about their specific privacy policies please contact the advertisers directly.

Please be careful and responsible whenever you are online. Should you choose to voluntarily disclose Personally Identifiable Information on our site, such as in message boards, chat areas or in advertising or notices you post, that information can be viewed publicly and can be collected and used by third parties without our knowledge and may result in unsolicited messages from other individuals or third parties. Such activities are beyond the control of CGP Holdings, Inc. and this policy.

Changes to this policy

CGP Holdings, Inc. reserves the right to change this policy at any time. Please check this page periodically for changes. Your continued use of our site following the posting of changes to these terms will mean you accept those changes. Information collected prior to the time any change is posted will be used according to the rules and laws that applied at the time the information was collected. 

COULD YOU BE EASY PREY?

Take the Easy Prey Self-Assessment.

We will only send you awesome stuff!