newsfilter.io
Interview, Fireside Chat

Why are cybercriminals richer than ever?

  • Evolution of Ransomware Tactics

    • Criminal gangs have shifted from subtle data exfiltration to "wrecking" attacks that deliberately destroy systems to maximize leverage for ransom demands.
    • This aggressive model prioritizes demanding payment not just to decrypt files, but to cease network disruption entirely, ensuring business operations can resume.
    • While early ransomware (e.g., CryptoLocker in 2013) relied on cryptocurrency for anonymity to evade traceable bank transfers, modern attacks are executed by hybrid teams.
    • A distinct cohort of young (17–20 year old), Anglophone hackers in Britain now collaborates with Russian gangs, leveraging local knowledge to target specific sectors while utilizing Russian tooling.
  • High-Impact Economic Disruptions

    • Recent major targets include Co-op, Marks & Spencer, Transport for London, and Jaguar Land Rover (JLR).
    • The JLR attack is considered the most disruptive, halting production for a company employing 31,000 people and a supplier network employing hundreds of thousands in the Merseyside and West Midlands.
    • The shutdown threatened to cause permanent damage to the supply chain, with some suppliers reporting they were "nearly folding."
    • To mitigate this economic risk, the UK government underwrote a £1.5 billion loan to prevent business collapse.
    • Discrepancy in Financial Impact: Globally, ransomware gangs generated less than $1 billion in ransoms in 2024, yet the JLR attack alone caused approximately £1.5 billion in damage.
  • Systemic Vulnerabilities and Lessons

    • Embedded Systems Risk: Businesses previously ignored security for "non-core" devices like robotic arms and room-booking screens; attackers now exploit these as entry points, necessitating comprehensive fixes across all infrastructure.
    • Supply Chain & Outsourcing Risks: Relying on cost-optimized IT security providers creates vulnerability, as attackers often use social engineering (e.g., repeated calls to call centers) to extract credentials from lower-tier handlers.
    • Resilience vs. Efficiency: The pandemic highlighted the dangers of running systems with zero slack; similarly, businesses are learning that "cheapest provider" IT models lack the resilience required for critical infrastructure.
  • Proposed Government Interventions

    • Ransom Payment Bans: A potential policy shift involves legally banning ransom payments, treating them similarly to terrorist financing to cut off the market incentive for criminal gangs.
      • This approach acknowledges that banning payments may force some businesses into insolvency ("short-term pain") to prevent long-term funding of organized crime.
      • Governments would need to accept that some companies may fail rather than comply with ransom demands to ensure the ban's credibility.
    • Transparency Mandates: Current legal frameworks allow companies to delay disclosure of hacks by months or years; stricter requirements are proposed to force immediate reporting of "wrecking" maneuvers.
      • Increased transparency is necessary to distinguish between high-disruption attacks and subtle thefts that companies currently conceal to avoid reputational damage.
    • Collective Action Problem: Governments are urged to treat cybercrime as a supply-side issue, arguing that as long as payment remains the cheapest path to recovery, market forces will sustain the criminal ecosystem.