Ransomware poses a graver threat than nation-state cyberattacks, said CrowdStrike co-founder Dmitri Alperovitch.
“The biggest threat is actually not the nation-states. It’s ransomware,” he said during a keynote at the RSA Conference. “It’s impacting everyone on the planet, from your grandmother that now has to find bitcoins to unlock her family photos, to small organizations, school districts and the like, and hospitals to the largest companies.”
Alperovitch, former CrowdStrike CTO who also co-founded and now serves as the executive chairman of Silverado Policy Accelerator, a geopolitical and cybersecurity policy think tank, regularly details the worst global threats during his RSA keynotes. And this year (as well as in 2020), Sandra Joyce, EVP and head of global intelligence at FireEye’s Mandiant threat hunting team, joined Alperovitch for the Global Threat Brief keynote.
The Mandiant team was the first to discover the Russian SolarWinds hack back in December. And while Joyce and Alperovitch did discuss the cyberthreats coming from Russia and the other big four nation-states — China, North Korean, and Iran — they both pointed to ransomware as a particularly urgent risk and said they feared that both the tactics and ransom demands will get worse.
This sounds particularly dire following a record-setting year for both ransoms paid to criminal gangs and ransom demands. But it also echoes concerns from top private-sector and federal-government cybersecurity advisors including U.S. Department of Homeland Security Secretary Alejandro Mayorkas, who recently called ransomware a “threat to our national security.”
Joyce pointed to the evolving extortion tactics that ransomware gangs are using to “shame” companies into paying exorbitant ransoms. “They’ll threaten to dump data that they’ve found,” she said, adding that FireEye recently saw one organization hit with a $50 million ransom demand. “They’ll even call competitors, they’ll call your customers, they want to make sure they can use shame as a tool, and that puts organizations in an impossible situation.”
If companies decide to pay the ransom — like Colonial Pipeline did because, as CEO Joseph Blount told the Wall Street Journal, “it was the right thing to do for the country” — then they risk violating U.S. sanctions laws. But if they don’t pay the ransom, they risk losing intellectual property and customers’ sensitive data while destroying their own reputation.
When Ransomware Jumps Into ExtortionRansomware gangs are “becoming so aggressive on the extortion demands they’re even reaching out to journalists to give them a heads up to put further pressure on the company,” Alperovitch added. “It’s almost like ransomware is now just a side business to the to the overall extortion business.”
Most of these threat actors live in Russia, or in other countries where the government turns a blind eye to their illegal activities, which essentially means that law enforcement can’t touch these ransomware gangs, Joyce said. “Many of them are being hidden, or in some cases assisted, by the Russian intelligence service,” Alperovitch added. “In some cases, we know they actually work for Russian intelligence by day, executing operations for the state purpose, and then by night, conducting cybercrime operations.”
Looking to the future, Alperovitch said he expects ransomware business models and tactics to become more sophisticated. “We have not yet seen [attackers] try to physically destroy hardware, but that can absolutely be on the horizon,” he said. “Technically that capability exists.”
Meanwhile, Joyce said she expects these attackers to bypass ransomware all together and jump straight to extortion. “There is a path for threat actors who can, without even breaching an organization, still conduct extortion operations,” she said. “That is very lucrative and could possibly be the next steps that we see.”
Comments