Bitcoin Forum
April 18, 2024, 03:48:38 PM *
News: Latest Bitcoin Core release: 26.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: US government imposing fines for those companies paying ransomware  (Read 179 times)
Yaunfitda (OP)
Hero Member
*****
Offline Offline

Activity: 2828
Merit: 574



View Profile
October 03, 2020, 10:32:24 AM
Merited by Kemarit (1)
 #1

In a ironic move by the US federal government, companies that are going to cooperate and pay ransom to cyber threat actors are going to be liable as "even if it did not know or have reason to know it was engaging in a transaction with a person that is prohibited under sanctions laws and regulations administered by OFAC."



https://home.treasury.gov/system/files/126/ofac_ransomware_advisory_10012020_1.pdf

I guess what the US want is to really stop this attack on US soil specially those coming from state backup attacks, specially from North Korea. And now they are encouraging victims to contact relevant government agencies first before dealing with this cyber actors.

███████████████████████████████
███████████████████████████████
███▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀███████████
█████████████▀▀        ▀▀██████
██████▀▀▀▀▀▀              ▀████
██████████▀     ▄▄██▄▄     ▀███
██████████      ██████      ███
██████████▄     ▀▀██▀▀     ▄███
██████▄▄▄▄▄▄              ▄████
█████████████▄▄        ▄▄██████
███▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████████
███████████████████████████████
███████████████████████████████
.
|
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
SSC NAPOLI
OFFICIAL EUROPEAN
BETTING PARTNER
|.ROLLBOTS.|
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████▄
▄█████████▀████████▀████▄
██████▄▄▄█████▄▄█████████
█████████████████████████
██████▀▀▀█████▀▀█████████
▀█████████▄████████▄████▀
▀██▄▄▄▄▄▄▄▄▄▄▄▄▄▄█████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
ROLLBIT COIN
TRADE RLB NOW!
|...PLAY NOW...
You get merit points when someone likes your post enough to give you some. And for every 2 merit points you receive, you can send 1 merit point to someone else!
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1713455318
Hero Member
*
Offline Offline

Posts: 1713455318

View Profile Personal Message (Offline)

Ignore
1713455318
Reply with quote  #2

1713455318
Report to moderator
1713455318
Hero Member
*
Offline Offline

Posts: 1713455318

View Profile Personal Message (Offline)

Ignore
1713455318
Reply with quote  #2

1713455318
Report to moderator
Kemarit
Legendary
*
Offline Offline

Activity: 3066
Merit: 1351



View Profile
October 03, 2020, 10:39:29 AM
Merited by Yaunfitda (1)
 #2

They consider this a threat to their national security and they attacks have been growing, even hospitals and educational system has been attack as well. The criminals knows no boundaries and the US wanted it to stop at all cost to even imposing fines to those victims, because not only they are cooperating, but encouraging it as well. We all know what their stance on any terrorists, "NO Ransom".

So I wouldn't be surprised if they are going to apply it to cyber criminals as well. So we will see how this goes in the future. I think the best prevention for now is for those companies to update everything including hospitals, which is one of the most frequented target by organized crimes because of the total lax on their systems. And then educate the users not on proper security hygiene.

▄▄███████▄▄
▄██████████████▄
▄██████████████████▄
▄████▀▀▀▀███▀▀▀▀█████▄
▄█████████████▄█▀████▄
███████████▄███████████
██████████▄█▀███████████
██████████▀████████████
▀█████▄█▀█████████████▀
▀████▄▄▄▄███▄▄▄▄████▀
▀██████████████████▀
▀███████████████▀
▀▀███████▀▀
.
 MΞTAWIN  THE FIRST WEB3 CASINO   
.
.. PLAY NOW ..
dothebeats
Legendary
*
Offline Offline

Activity: 3626
Merit: 1352


Cashback 15%


View Profile
October 03, 2020, 12:44:51 PM
 #3

This is actually making a statement to those cyber terrorists that targeting US-based companies would be fruitless, and would, most of the time, result to them getting nabbed or getting tracked. It would be best if the US gov't also provide assistance to private companies facing these type of hacks, as they are the ones who imposed that no ransom shall ever be paid in order to get those files backed. If this wouldn't be the case, everyone would be forced to upgrade their security systems and do better in terms of handling their data, which is pretty good overall considering that some of these companies are still using old tech in maintaining their database and file systems.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
btc_angela
Hero Member
*****
Offline Offline

Activity: 2590
Merit: 542



View Profile
October 03, 2020, 09:27:41 PM
 #4

I'm seeing that US wanted to get involved, because this is already a cyber war. It's not just for the money here, but the criminals are also stealing information and very often that it could be consider an attack on their home soil itself. And they want to US companies not to pay the ransom but they will go after this criminals and send the message not just that their effort will be fruitless, but not to mess with them because they are going after them, regardless if they are from Russia or North Korea.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
Harlot
Hero Member
*****
Offline Offline

Activity: 1806
Merit: 671


View Profile
October 03, 2020, 11:26:19 PM
 #5

They aren't actually stopping the companies hit by the ransomwares themselves but they are actually trying  to stop companies being the middleman for both the victim and the hacker as they are treated as some kind of "cyber actors" in the part of the crime. And I do agree with that, these companies who are helping on making the payment for this criminals are making money while doing so, technically this looks bad on them as like I said they are helping them earn the blackmail money. Discouraging them with a fine will just allow the company to do it on their own and handle the situation themselves without a help of any kind of middleman.
posi
Hero Member
*****
Offline Offline

Activity: 2240
Merit: 579


Degens.bet - On-chain 1000x Futures


View Profile
October 03, 2020, 11:53:17 PM
 #6

The statement made by the US Treasury office may seems harsh by some people but it definitely a way to stop the US citizen from being a victim of the ransomware attacker cause despite the strategy used by the hackers been exposed some people will still be silly enough to fall their tricks and the funny thing is that even with this public announcement of penalization some people will fall for the ransomware attack.

They aren't actually stopping the companies hit by the ransomwares themselves but they are actually trying  to stop companies being the middleman for both the victim and the hacker as they are treated as some kind of "cyber actors" in the part of the crime.
According to the gravity of this announcement, I believe the US government is already involved cause the information stole by the hacker worth more than the money involved.

.DEGENS.BET.     ████████████████
     ████████████████
██████████████████████████
██   ████████████████   ██
███  ████████████████  ███
 ▀██████████████████████▀
   ▀▀████████████████▀▀
      ▀████████████▀
         ████████
        ▄▄██████▄▄
      ██████████████
    ██████████████████
      ██
      ██
  ██  ██  ██       ██
    █████████████████
█████████████████  ██  ██
                 ██████
                   ██
           ██
           ██
       ██  ██  ██
         ██████
           ██
      ██
    ██████
  ██  ██  ███████████
      █████████████████
█████████████████  ██  ██
                   ██
                   ██
           ██
         ██████
       ██  ██  ██
           ██
           ██
..TRADE NOW..
TravelMug
Hero Member
*****
Offline Offline

Activity: 2618
Merit: 832



View Profile
October 04, 2020, 12:31:29 AM
 #7

They aren't actually stopping the companies hit by the ransomwares themselves but they are actually trying  to stop companies being the middleman for both the victim and the hacker as they are treated as some kind of "cyber actors" in the part of the crime.

It's just the same though, what the US want is to really stop paying this "cyber actors", regardless if you are an entity that facilitates or companies paying directly, you are in violation OFAC Regulations.

And I do agree with that, these companies who are helping on making the payment for this criminals are making money while doing so, technically this looks bad on them as like I said they are helping them earn the blackmail money. Discouraging them with a fine will just allow the company to do it on their own and handle the situation themselves without a help of any kind of middleman.

Yes, this is what the US government wanted, to prevent and discouraged cooperating with cyber threat. They already have a black list, including hackers or cyber criminals from North Korea (Lazarus group and it's sub groups) and  Evil Corp, a Russia-based cybercriminal organization. Can this stop cyber criminals? I don't think so, they will continue to engage and attack US. But at least the US can have the legal means to come after this groups in the future.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Lucius
Legendary
*
Offline Offline

Activity: 3220
Merit: 5619


Blackjack.fun - Free Raffle - Join&Win $50


View Profile WWW
October 04, 2020, 10:51:19 AM
 #8

This is in line with that famous saying "US does not negotiate with terrorists", and here they want to make it clear to their citizens not to cooperate with online terrorists, thus encouraging them to carry out similar attacks.

This definitely makes sense if it is going to raise the level of protection that many companies neglect quite a bit when it comes to computer security that includes not only software solutions, but also regular data backup and education of their employees. Instead of spending money on ransom payments, it's definitely better to invest in prevention - and it seems to be the only way to convince someone to change their bad habits of punishing them if they continue to work the old way.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
Harlot
Hero Member
*****
Offline Offline

Activity: 1806
Merit: 671


View Profile
October 04, 2020, 07:32:11 PM
 #9

They aren't actually stopping the companies hit by the ransomwares themselves but they are actually trying  to stop companies being the middleman for both the victim and the hacker as they are treated as some kind of "cyber actors" in the part of the crime.

It's just the same though, what the US want is to really stop paying this "cyber actors", regardless if you are an entity that facilitates or companies paying directly, you are in violation OFAC Regulations.

And I do agree with that, these companies who are helping on making the payment for this criminals are making money while doing so, technically this looks bad on them as like I said they are helping them earn the blackmail money. Discouraging them with a fine will just allow the company to do it on their own and handle the situation themselves without a help of any kind of middleman.

Yes, this is what the US government wanted, to prevent and discouraged cooperating with cyber threat. They already have a black list, including hackers or cyber criminals from North Korea (Lazarus group and it's sub groups) and  Evil Corp, a Russia-based cybercriminal organization. Can this stop cyber criminals? I don't think so, they will continue to engage and attack US. But at least the US can have the legal means to come after this groups in the future.

Basically the US government is treading the ransomware hackers as some kind of terrorist where if they deny the payment transfer they would be discouraging more future attacks to happen which I don't think is the case. From the news I have been seeing ransomware related attacks are increasing now not only in companies but also to personal computers, if they just deny or fine people paying the ransomware I believe that ransomware attacks would increase just for this people for them to have any income. Anyways if the US government wants to be involve I think they should just be tracking down the people doing the hacks and not concentrating on the victim.
btc_angela
Hero Member
*****
Offline Offline

Activity: 2590
Merit: 542



View Profile
October 04, 2020, 10:04:05 PM
 #10

^^, Yes, I have said, this is already a cyber war, the game has shift to online attacks on US soil. So just the same stance whether online or offline attacks, they won't tolerate and will not pay any ransom to this cyber terrorist. I'm sure that they have been tracking this terrorist already, then already name North Korea and Russia as the main 'source' of attacks to US soil. And US government, specifically FBI are doing a lot of monitoring and issues advisories:

https://www.fbi.gov/investigate/cyber

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
Lucius
Legendary
*
Offline Offline

Activity: 3220
Merit: 5619


Blackjack.fun - Free Raffle - Join&Win $50


View Profile WWW
October 05, 2020, 10:21:58 AM
 #11

I'm sure that they have been tracking this terrorist already, then already name North Korea and Russia as the main 'source' of attacks to US soil.

It is not at all strange that the two main suspects are North Korea and Russia, given that both are marked as highly problematic and under sanctions. But the attacks come from all over the world, because hackers who want money are not exclusively politically motivated, although the US's actions create a lot of enemies around the world. I wonder what is in this story with China or Iran who are being far more powerful than one North Korea that has become the main culprit for every trouble that happens in the world.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
avikz
Legendary
*
Offline Offline

Activity: 3066
Merit: 1498



View Profile
October 05, 2020, 11:12:27 AM
 #12

It's because US government wants to get more insughts about such attacks which many companies are not reporting. There is a fair reason for the companies not to report such attacks to the government and related cybersecurity departments because it involves the reputation of the company. From a customer point of view it's less secure to continue with the business with such victim companies.

But unless and until such incidents are reported, there will be no way the cybercrime department will be able to get to the root of such things. Probably that's the reason such notification is issued!

sheenshane
Legendary
*
Offline Offline

Activity: 2394
Merit: 1212


Cashback 15%


View Profile WWW
October 05, 2020, 11:18:08 PM
 #13

I find this unfair for any organization and people who are innocent but the fingers are pointed to them because of this act.
I don't think that this one is timely. I would recommend the government to help the mid-man identify these first. Why? It's too hard to identify when someone is using your platform for making transactions with hacking. Unless there is a software that will be created specifically for this.

But on the other side, this is good to them as well. It will probably lessen the cybercriminal cases once criminal knows this announcement, they might afraid doing transaction online. Most likely they are going offline but they will encounter difficulties.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
cryptomaniac_xxx
Hero Member
*****
Offline Offline

Activity: 1484
Merit: 561



View Profile
October 06, 2020, 05:52:41 AM
 #14

This is a interesting article, Ransomware victims aren't reporting attacks to police. That's causing a big problem. This is Europol though, but I'm just wondering if in the US soil nobody reports a crime to US agencies?

Quote
Many victims of ransomware aren't reporting attacks to police, making it harder to measure the level of crime and to tackle the gangs involved.

Europol's Internet Organised Crime Threat Assessment 2020 report details the key forms of cyber crime which pose a threat to businesses right now and ransomware remains one of the main concerns, especially as these gangs increasingly display high levels of skill and sophistication.

In many cases, ransomware gangs don't just encrypt the network with malware and demand hundreds of thousands or millions of dollars in bitcoin, they'll also threaten to leak stolen sensitive corporate files or personal data if they don't receive a payment.

And while ransomware is one of the most high profile forms of cyber attack, Europol's report warns that it remains an under-reported crime as many organisations still aren't coming forward to law enforcement after falling victim.

Several law enforcement agencies across Europe say they've only heard of ransomware cases via reports in local media.

What if the companies paid the ransom already to criminals and then the news just surface on the media? Will US still charge those that didn't report it and instead pay the ransom themselves and try to keep quiet?

.
.airbet.
██
██
██
██
██
██
██
██

██

██

██

██

██
.

▄████▄▄▄██████▄
███████████████
███████████████
███████▀▀▀▀████
██████████████
▀███▀███████▄██
██████████▄███
██████████████
███████████████
███████████████
██████████████
█████▐████████
██████▀███████▀
▄███████████████▄
████████████████
█░██████████████
████████████████
████████████████
█████████████████
█████████████████
███████░█░███████
████████████████
█████████████████
██████████████░█
████████████████
▀███████████████▀
.
.
.
.
██▄▄▄
████████▄▄
██████▀▀████▄
██████▄░░████▄
██████████████
████████░░▀███▌
░████████▄▄████
██████████████▌
███░░░█████████
█████████░░░██▀
░░░███████████▀
██████░░░██▀
░░▀▀███▀

   
6,000+
GAMES
|
WEEKLY
PROMOS
.
....100%....
1ST DEPOSIT
BONUS
....
....125%.....
2ND DEPOSIT
BONUS
██
██
██
██
██
██
██
██

██

██

██

██

██
.
.PLAY NOW.
Yaunfitda (OP)
Hero Member
*****
Offline Offline

Activity: 2828
Merit: 574



View Profile
October 06, 2020, 07:03:52 AM
 #15

I find this unfair for any organization and people who are innocent but the fingers are pointed to them because of this act.
I not seeing this as unfair, what US wants is to have total control because it curtails national security according to them. So no US citizens can just pay this ransom period.

I don't think that this one is timely. I would recommend the government to help the mid-man identify these first. Why? It's too hard to identify when someone is using your platform for making transactions with hacking. Unless there is a software that will be created specifically for this.
They can't help if the man in the middle is not cooperating on their side, hence they are including as well.

But on the other side, this is good to them as well. It will probably lessen the cybercriminal cases once criminal knows this announcement, they might afraid doing transaction online. Most likely they are going offline but they will encounter difficulties.
And that is what US wanted to see, and they are sending a clear message to criminals now. Online criminals will not go offline with payments, they know the paper trail and tracking them will be easy for US government.

███████████████████████████████
███████████████████████████████
███▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀███████████
█████████████▀▀        ▀▀██████
██████▀▀▀▀▀▀              ▀████
██████████▀     ▄▄██▄▄     ▀███
██████████      ██████      ███
██████████▄     ▀▀██▀▀     ▄███
██████▄▄▄▄▄▄              ▄████
█████████████▄▄        ▄▄██████
███▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████████
███████████████████████████████
███████████████████████████████
.
|
▄▄███████▄▄
▄████▀▀▀▀▀▀▀████▄
▄███▀▄▄███████▄▄▀███▄
▄██▀▄█▀▀▀█████▀▀▀█▄▀██▄
▄██▄██████▀████░███▄██▄
███░████████▀██░████░███
███░████░█▄████▀░████░███
███░████░███▄████████░███
▀██▄▀███░█████▄█████▀▄██▀
▀██▄▀█▄▄▄██████▄██▀▄██▀
▀███▄▀▀███████▀▀▄███▀
▀████▄▄▄▄▄▄▄████▀
▀▀███████▀▀
SSC NAPOLI
OFFICIAL EUROPEAN
BETTING PARTNER
|.ROLLBOTS.|
▄▄███████▄▄
▄███████████████▄
▄███████████████████▄
▄██▀▀▀▀▀▀▀▀▀▀▀▀▀▀█████▄
▄█████████▀████████▀████▄
██████▄▄▄█████▄▄█████████
█████████████████████████
██████▀▀▀█████▀▀█████████
▀█████████▄████████▄████▀
▀██▄▄▄▄▄▄▄▄▄▄▄▄▄▄█████▀
▀███████████████████▀
▀███████████████▀
▀▀███████▀▀
ROLLBIT COIN
TRADE RLB NOW!
|...PLAY NOW...
Theb
Hero Member
*****
Offline Offline

Activity: 1680
Merit: 655


View Profile
October 06, 2020, 10:54:57 PM
 #16

It's because US government wants to get more insughts about such attacks which many companies are not reporting. There is a fair reason for the companies not to report such attacks to the government and related cybersecurity departments because it involves the reputation of the company. From a customer point of view it's less secure to continue with the business with such victim companies.

But unless and until such incidents are reported, there will be no way the cybercrime department will be able to get to the root of such things. Probably that's the reason such notification is issued!

From what I know companies especially the ones that are publicly listed in the US are obligated to notify several departments as well as other businesses (i.e. insurance companies) about the ransomware attack they are experiencing even companies covered in the health sector are obligated to notify such attacks as they carry out personal date from their clients so I don't think this is the reason why they are doing this. For the US government trying to impose penalties to companies that help with the payments I think this is justifiable as like what others have said they are profiting from something that is illegal and imposing a fine would simply discourage businesses to handle payments for companies that are victimized by these kinds of attacks. 

..bustadice..         ▄▄████████████▄▄
     ▄▄████████▀▀▀▀████████▄▄
   ▄███████████    ███████████▄
  █████    ████▄▄▄▄████    █████
 ██████    ████████▀▀██    ██████
██████████████████   █████████████
█████████████████▌  ▐█████████████
███    ██████████   ███████    ███
███    ████████▀   ▐███████    ███
██████████████      ██████████████
██████████████      ██████████████
 ██████████████▄▄▄▄██████████████
  ▀████████████████████████████▀
                     ▄▄███████▄▄
                  ▄███████████████▄
   ███████████  ▄████▀▀       ▀▀████▄
               ████▀      ██     ▀████
 ███████████  ████        ██       ████
             ████         ██        ████
███████████  ████     ▄▄▄▄██        ████
             ████     ▀▀▀▀▀▀        ████
 ███████████  ████                 ████
               ████▄             ▄████
   ███████████  ▀████▄▄       ▄▄████▀
                  ▀███████████████▀
                     ▀▀███████▀▀
           ▄██▄
           ████
            ██
            ▀▀
 ▄██████████████████████▄
██████▀▀██████████▀▀██████
█████    ████████    █████
█████▄  ▄████████▄  ▄█████
██████████████████████████
██████████████████████████
    ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
    ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
       ████████████
......Play......
aioc
Hero Member
*****
Offline Offline

Activity: 2884
Merit: 564



View Profile
October 08, 2020, 10:56:37 AM
Merited by vapourminer (2)
 #17

In a ironic move by the US federal government, companies that are going to cooperate and pay ransom to cyber threat actors are going to be liable as "even if it did not know or have reason to know it was engaging in a transaction with a person that is prohibited under sanctions laws and regulations administered by OFAC."



https://home.treasury.gov/system/files/126/ofac_ransomware_advisory_10012020_1.pdf

I guess what the US want is to really stop this attack on US soil specially those coming from state backup attacks, specially from North Korea. And now they are encouraging victims to contact relevant government agencies first before dealing with this cyber actors.

I hope they can back it up, if they impose fines then they should offer what kind of solutions are they going to offer to those who ignore and refused to pay these cyber criminals, can they solve or fix the issues if the victim contact the authorities, if they can show potential victims and victims that they have the resources to fix the issues then they will not pay these criminals and ask for their help.

Lorence.xD
Sr. Member
****
Offline Offline

Activity: 1624
Merit: 315


Leading Crypto Sports Betting & Casino Platform


View Profile
October 10, 2020, 07:01:19 AM
 #18

It's because US government wants to get more insughts about such attacks which many companies are not reporting. There is a fair reason for the companies not to report such attacks to the government and related cybersecurity departments because it involves the reputation of the company. From a customer point of view it's less secure to continue with the business with such victim companies.

But unless and until such incidents are reported, there will be no way the cybercrime department will be able to get to the root of such things. Probably that's the reason such notification is issued!
The imposed fine is pretty reasonable in my opinion because if there were no consequences for the people who pays the ransomware attackers, then the companies mentioned by quote above will do what any company will do to protect their reputation. The fine serves as a sign for these companies to not slack off in regards to their security and backups.

█▀▀▀▀▀











█▄▄▄▄▄
.
Stake.com
▀▀▀▀▀█











▄▄▄▄▄█
   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
█▀▀▀▀▀











█▄▄▄▄▄
.
PLAY NOW
▀▀▀▀▀█











▄▄▄▄▄█
Karartma1
Legendary
*
Offline Offline

Activity: 2310
Merit: 1422



View Profile
October 10, 2020, 08:38:26 AM
 #19

The US are simply confirming without any reasonable doubt that they will act the same way they usually do with other crimes. As Lucius wrote US does not negotiate with terrorists. If they did, we wouldn't know anyway and they would deny any possible ransom. This news is a no news, they clearly extended what they already do on a different topic.
https://en.wikipedia.org/wiki/Government_negotiation_with_terrorists

For victims, though, this is very bad: they will suffer huge losses, twice.
coolcoinz
Legendary
*
Online Online

Activity: 2604
Merit: 1102



View Profile
October 11, 2020, 11:02:41 AM
Merited by vapourminer (1)
 #20

This is in line with that famous saying "US does not negotiate with terrorists", and here they want to make it clear to their citizens not to cooperate with online terrorists, thus encouraging them to carry out similar attacks.

This definitely makes sense if it is going to raise the level of protection that many companies neglect quite a bit when it comes to computer security that includes not only software solutions, but also regular data backup and education of their employees. Instead of spending money on ransom payments, it's definitely better to invest in prevention - and it seems to be the only way to convince someone to change their bad habits of punishing them if they continue to work the old way.

But will it work, that is the question. Take that recent case of CWT company, that paid the ransom and got their files decrypted. They chose this way because they knew that doing otherwise would mean bankruptcy. Most companies will be willing to pay the ransom and a fine imposed by the government, just to keep the boat afloat.
If they go down it will not matter if they save a million dollars or not since they will be unable to make any money from that point.

Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!