Another day, another multi-million-dollar ransomware attack seems to be the pattern these days with each consecutive month setting new ransomware records.

May, with 62.3 million attacks, saw the most ransomware attacks since SonicWall started tracking them in 2013, while April set the previous high at 48.3 million. In fact, between Jan. 1 and the end of May alone, SonicWall recorded 226.3 million ransomware attacks, a 116% increase over 2020.

“The bombardment of ransomware attacks is forcing organizations into a constant state of defense rather than an offensive stance,” SonicWall CEO Bill Conner said.

And the price tag on these attacks is getting steeper. Last week meat processing giant JBS said it paid $11 million in ransom to Russia-linked group REvil, following a similar move by Colonial Pipeline last month, and the $11 million payout topped last year’s record-setting ransom paid by $1 million.

“Ransomware cybercriminals are constantly innovating on better ways to get companies to pay more,” Cybereason CTO and co-founder Yonatan Striem-Amit said in an interview with SDxCentral. “We’ve seen a shift as ransomware groups adopting nation-state and APT-style technologies to encrypt whole networks, employing both zero-day and lateral movement techniques. And we’ve seen that evolve even further into double extortion.”

The True Business Cost of Ransomware

In these attacks, cybercriminals first extract large amounts of sensitive data prior to encrypting a victim’s databases. They then threaten to publish that data unless the victim pays ransom demands, thus putting extra pressure on organizations to pay up.

While law enforcement and private-sector cybersecurity professionals alike continually advise companies not to pay ransoms because it supports the booming cybercrime business, many organizations do pay to avoid disrupting critical energy infrastructure (in the case of Colonial) and protect their own IP and customers’ data.

However, despite the potential for massive business disruptions, some studies suggest that paying the ransom only makes things worse, and more costly, for the corporation hit by the attack. According to Cybereason data, companies that pay a ransom are more likely to get hit again.

“As more and more companies are paying seven- and eight-figure deals to get access to their data, the staggering impact here is that those who pay are doing two things,” Striem-Amit said. “They are putting a target on their back. And the second element: those that end up paying, when they try to use the key to recover their files, often some or all of the data is corrupted. As we said in the report, it really doesn’t pay to pay."

The global study of nearly 1,300 security professionals found more than half of organizations surveyed had been the victim of a ransomware attack, and 80% of businesses that paid the ransom demand suffered a second ransomware attack — often at the hands of the same threat-actor group.

Additionally, of the organizations that paid a ransom to regain access to their encrypted systems, 46% reported that some or all of the data was corrupted during the recovery process.

Still, this puts companies in a bind as ransomware attackers become more organized and efficient in their business models and defenders struggle to keep up.

The Role of Cryptocurrency

Security analysts agree ransomware wouldn’t be the booming business it is without cryptocurrency, and that governments need to enact stricter cryptocurrency regulations in order to curb the attacks.

“Cryptocurrency, combined with the anonymity of the internet, is the reason why ransomware exists,” Cisco Talos’ Director of Outreach Craig Williams said. “If we remove some of the anonymization of cryptocurrencies, like the Ransomware Task Force has recommended, that’s going to help prevent things like ransomware and human trafficking and all kinds of illegal enterprises that benefit from anonymity.”

The Ransomware Task Force is a private-sector led, 60-member organization that includes dozens of private companies along with the FBI, U.S. Cybersecurity and Infrastructure Security Agency (CISA), and other law-enforcement groups. Both Cisco and Cybereason are founding members.

In late April, the group published an 81-page report with 48 recommendations to combat ransomware, and these include requiring cryptocurrency exchanges, crypto kiosks, and over-the-counter (OTC) trading desks to adhere to the same regulatory standards as banks.

“Now, the good news here is that, as an industry, we’ve gotten better at tracing cryptocurrency,” Williams said. “DarkSide, and the Colonial Pipeline attack, is a perfect example of that.”

After Colonial Pipeline paid a $4.4 million ransom to ransomware gang DarkSide, the Justice Department recovered about $2.3 million of the ransom paid. Law enforcement tracked the bitcoin payment to a virtual wallet, and the FBI somehow had the private key to this wallet, which allowed the DOJ to recover the funds.

However, busting ransomware gangs by cracking down on cryptocurrency businesses doesn’t work when the government sponsors the cybercriminals, or at least allows them to operate with impunity.

Should You Buy Cyber Insurance?

While cyber insurance is not new, it has received more attention lately as ransomware attacks increase. At least one report forecasts the cyber insurance market value will hit $24.19 million by 2025. However, the cost of cyber insurance premiums went up as much as 60% in the past year as ransomware attacks skyrocketed.

“It’s important to buy cyber insurance given where we are now, however, if you look at cyber insurance for ransomware versus normal insurance, it’s quite different,” Barracuda CTO Fleming Shi said. “Normally we buy insurance for an unplanned disaster. If you look at cyber insurance, we have already been breached so many times, it’s not necessarily what we call an unplanned disaster.”

And if you buy cyber insurance, “you should absolutely not publicize it,” Talos’ Williams said, adding that cyber insurance puts a target on an organization’s back.

“It absolutely can make you a target,” he said. “In many examples we’ve seen, and even the interview we had with the LockBit operator, they love to find victims with cyber insurance. That’s the perfect end game for them because they know they’re going to be paid, they know that people are going to be brought in who know how to handle this, and then it’s going to be done in a quick and professional manner.”

Most cybersecurity professionals agree that cyber insurance has a role to play in a company’s security strategy, they also agree that insurance is unlikely to cover all of the damages suffered in case of a breach. Plus, while it’s impossible to prevent every attack, it’s still cheaper to pay for preventative tools and services rather than shell out millions after an attack.

“At the end of the day, the cost of protecting a company ahead of time is a fraction of what ransomware will cost you,” Streim-Amit said.

“When we think about how do we implement a risk-reduction program for a business, cyber insurance has a good place in that strategy, but it can’t be the only thing we rely on,” he continued. “It probably doesn’t cover all the costs, and there are costs that are hard to quantify from brand-reputation damage to loss of trust. In the most extreme case: Look at SolarWinds.”

In fact, Cybereason’s new research found that 53% or organizations said they suffered brand and reputational damage as a result of a successful attack. And 26% said it forced them to shut down their business entirely.

While the SolarWinds breach wasn’t ransomware, “now the company’s name is used to talk about an attack,” Streim-Amit said. “Their name is now one of the most notorious attacks in cyber history.”

It Always Comes Back to Security Hygiene

As with all security strategies, preventing ransomware starts with basic security hygiene, and it requires a layered defense with various tools to protect multiple access points.

“The source of these things is the same problem that the security industry has had for decades. It’s basic hygiene, and keeping stuff patched,” said Odin Olson, VP of alliances at Arctic Wolf, which provides managed security operations services including threat detection, response, and recovery. The vendor recently announced a service assurance program under which it will provide customers up to $1 million in financial assistance in the event of a successful breach.

“Whether it’s Colonial, or dozens of other examples, you go back to basic hygiene wasn’t in place. It wasn’t that they didn’t have advanced tooling — that had nothing to do with it,” Olson said.

Hackers breached Colonial Pipeline’s network by using a compromised VPN password, according to Mandiant, the threat research team that discovered the SolarWinds breach. The account did not require multi-factor authentication.

“And then after a ransomware attack, it’s about the ability to detect and respond quickly,” Olson continued. “Compromise doesn’t equal damage — the damage happens later. It’s that dwell time and the difference between the compromise and the damage.”

Dwell time — the number of days an attacker is present in an organization’s environment before detection — is typically shorter in ransomware attacks compared to other forms of malware because the attackers have to make themselves known to demand a ransom. However, the longer it takes to detect a compromise, the more time bad actors have to steal data — and even hop onto customers’ and partners’ networks.

Do You Know Your Ransomware Susceptibility Score?

“The reason that it seems like we are always behind the eight ball, that we’re always trying to play catch up with the bad actors, is that bad actors’ No. 1 goal is to make money, monetize what they’re doing,” said Bob Maley, CSO of cyber risk management vendor Black Kite. “And if they’re doing something that works, they’ll continue to do that. But if they start finding that the industry’s gotten better [at defending against attacks], I can guarantee you that they will come up with something new.”

Black Kite developed a Ransomware Susceptibility Index (RSI) that uses machine learning and data from a variety of sources including hacker forums, the dark web, and its own data lake of about 34 million companies’ publicly available information to determine the likelihood that an organization will experience a ransomware attack. The vendor recently began offering RSI ratings to companies for free, and they can use it to evaluate their own risk of attack as well as their vendors’ and third-party partners’ risk.

“And it’s not just telling you a number,” Maley said, about the RSI score. The platform also lets companies run a report on themselves or their vendors, “and it shows why they’re susceptible, it shows you all the particular controls that are failing, and it also shows you everything that the vendor would need to do to fix those controls so they can reduce that RSI into a reasonable level,” he added.

‘Have a Plan Not to Pay’

In addition to assessing internal and third-party risks that could lead to a ransomware attack, security professionals recommend conducting regular security audits and penetration tests, as well as running ransomware playbooks and having a plan in place on how to respond after an attack.

“Have a plan not to pay. Start with that,” Barracuda’s Shi said. “Assume I’m going to be attacked. Assume I’m not going to pay. So what are the things I need? Probably a critical data discovery inspection to make sure all the high-priority data is encrypted, as well as backed up in a way that the bad guys, even they get their hands on the data, they cannot see what’s in it.”

Beyond just having a plan, practice it, he added. “Constantly practice the actual attack,” Shi said. “Run the scripts, and make sure you can get your business back up as quickly as you can. All those things matter as you set a goal to not pay and hold to it.”