Why Can't the U.S. Stop Ransomware Attacks?

349.0K views
•
June 9, 2021
by
CNBC
YouTube video player
Why Can't the U.S. Stop Ransomware Attacks?

TL;DR

Ransomware became criminals' top malware choice because it can fully disrupt enterprises and infrastructure, entering through phishing emails or unsecured connections to encrypt victims' files. In 2020, victims paid nearly $350 million in cryptocurrency, a 311% jump from the prior year, and attackers operating freely from Russia and former Soviet states are notoriously hard to attribute or prosecute.

Transcript

Unknown: This is probably the most significant ransomware attack on one of our critical infrastructures ever. Colonial Pipeline is the operative largest pipeline Last month, hackers took our gasoline hostage now they're carrying fuel from the Gulf Coast to the northeast, it was hit with a ransomware attack. attacking our meat supply. JBS says units... Read More

Key Insights

  • Ransomware is a program hackers use to hold digital information hostage, and it has become the top choice of malware for criminals, entering via phishing emails or unsecured network connections and encrypting victims' files to block access.
  • The total ransom paid by victims in 2020 reached nearly $350 million worth of cryptocurrency, a 311% increase compared with the previous year, showing how rapidly the criminal industry expanded.
  • Double extortion became a new trend at the start of 2020, where attackers not only encrypt data but also steal it and threaten to leak or post it if the ransom isn't paid, driving demands higher.
  • Bitcoin accounted for 98% of ransomware payments in the first quarter of 2019, though U.S. officials later seized $2.3 million in Bitcoin paid to the hacker group Darkside after the Colonial Pipeline attack.
  • Ransom payments concentrate among few criminals: a study found 199 deposit addresses received 80% of all funds in 2020, and just 25 addresses accounted for nearly half.
  • Attribution is the core obstacle, as many groups operate freely within Russia or former Soviet states as long as they don't hit targets in that country, so without political cooperation the threat won't fade.
  • Recovery often costs more than the ransom itself, with the average cost of recovery ballooning to $1.85 million in 2021, roughly 10 times bigger than the size of the actual ransom payments.
  • Federal law does not directly address ransomware; it falls under broad cybercrime statutes like the Electronic Communications Privacy Act and the Computer Fraud and Abuse Act, while Congress focuses on funding state and local governments.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is ransomware and how does it work?

Ransomware is a program that hackers use to hold digital information hostage, and it has become the top choice of malware for criminals. It usually makes its way in via a phishing email or a network connection that isn't secured, then encrypts the victim's files to prevent access. The malicious actor then demands a ransom in exchange for decrypting the files held hostage. What makes it so effective is its capability to entirely disrupt an enterprise or infrastructure like the Colonial Pipeline.

Q: How much did ransomware victims pay in 2020?

In 2020, the total amount of ransom paid by victims reached nearly $350 million worth of cryptocurrency, a 311% increase compared with the previous year. Beyond the ransom itself, there are heavy recovery costs: the average cost of recovery from ransomware attacks ballooned to $1.85 million in 2021, more than doubling from the previous year, making the average recovery about 10 times bigger than the size of the actual ransom payments. Barron's estimated ransomware's total cost at roughly $11.5 billion in 2019 and about $20 billion in 2020.

Q: Why is it so difficult to catch ransomware hackers?

It's notoriously difficult to attribute cyber attacks, which is an ongoing challenge for governments. Whether it's a criminal group or a nation-backed group, an attack often carries little consequence for the attacker. Many of these organizations are allowed to operate freely within Russia or other former Soviet states, as long as they don't hit anybody within that country or former Soviet state. Without cooperation at the political level, experts don't see the threat going away anytime soon.

Q: What is double extortion in ransomware attacks?

At the beginning of 2020, a new trend emerged where attackers not only encrypt your data but also steal that data, then threaten to post or leak it if the ransom isn't paid. This has driven up ransom demands significantly, because from the victim's perspective they must consider whether they are paying to get their data unlocked or paying to keep it from being leaked. Negotiations then take place in a chat room on the dark web, accessed via a unique identifier included in a digital ransom note.

Q: How are ransomware payments made and which cryptocurrency is used?

If a victim decides to pay and the amount is negotiated, the payment is made via cryptocurrency. Bitcoin is the most popular choice, accounting for 98% of ransomware payments in the first quarter of 2019. Once payment is made, the criminals send a decryption key. That reliance on Bitcoin has a vulnerability, however: U.S. officials were able to seize $2.3 million in Bitcoin paid to the hacker group Darkside following the Colonial Pipeline attack, showing payments can sometimes be traced and recovered.

Q: Which industries are hit hardest by ransomware?

Ransomware is pretty indiscriminate in terms of the industry sectors it targets. In 2020, professional and public service and manufacturing were the three industries hit the hardest, followed closely by healthcare, technology and finance. The attacks have grown sophisticated enough to target government entities and critical infrastructure, causing costly shutdowns. In 2020, a ransomware attack may have claimed its first life after taking a hospital offline in Germany, underscoring that the consequences extend well beyond financial cost.

Q: Is it legal to pay a ransomware ransom in the U.S.?

The U.S. government has historically discouraged individuals and businesses from paying their hackers in order to stop money flowing into the industry. According to the Department of Treasury, paying the ransom is illegal if the hackers demanding it were subject to U.S. sanctions. This leaves many businesses in a tricky situation, because paying fuels criminal organizations, yet not paying still leaves the cost of recovery, which often exceeds the ransom demand itself.

Q: How did the U.S. government respond to the Colonial Pipeline attack?

The 2021 Colonial Pipeline incident sent shockwaves across the oil industry and the U.S. government, alerting them to the severity of cybersecurity concerns. Shortly after, President Biden signed an executive order to strengthen U.S. cybersecurity defenses. With nearly half of congressional districts across America hit by some sort of ransomware attack from 2013 to 2020, support for more regulation is growing. Federal law doesn't directly address ransomware; it's instead covered under broader cybercrime laws like the Electronic Communications Privacy Act and the Computer Fraud and Abuse Act.

Summary & Key Takeaways

  • Ransomware, which hackers use to hold digital information hostage, has become criminals' top malware choice. It usually enters through a phishing email or unsecured network connection, then encrypts the victim's files and demands a ransom for a decryption key, disrupting enterprises and infrastructure like the Colonial Pipeline.

  • The industry has exploded financially: victims paid nearly $350 million in cryptocurrency in 2020, a 311% rise from the prior year. Barron's estimated ransomware's total cost at about $11.5 billion in 2019 and around $20 billion in 2020, while recovery averaged $1.85 million in 2021.

  • Fighting back is hard because attacks are notoriously difficult to attribute and many organized groups like Evil Corp and Darkside operate freely from Russia or former Soviet states. Paying is illegal if attackers are under U.S. sanctions, and Biden signed an executive order after Colonial Pipeline.


Read in Other Languages (beta)

Share This Summary 📚

Summarize YouTube Videos and Get Video Transcripts with 1-Click

Download browser extensions on:

Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator

Explore More Summaries from CNBC 📚

Summarize YouTube Videos and Get Video Transcripts with 1-Click

Download browser extensions on:

Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator