Ransomware Hackers Are Borrowing Customer-Service Tactics, Say Experts

Advertisement
By Reuters | Updated: 13 April 2016 13:06 IST
When hackers set out to extort the town of Tewksbury, Massachusetts with "ransomware," they followed up with an FAQ explaining the attack and easy instructions for online payment.

After baulking for several days, Tewksbury officials decided that paying the modest ransom of about $600 was better than struggling to unlock its own systems, said police chief Timothy Sheehan.

That case and others show how cybercriminals have professionalised ransomware schemes, borrowing tactics from customer service or marketing, law enforcement officials and security firms say. Some players in the booming underworld employ graphic artists, call centers and technical support to streamline payment and data recovery, according to security firms that advise businesses on hacking threats.

The advancements, along with modest ransom demands, make it easier to pay than fight.

Advertisement

"It's a perfect business model, as long as you overlook the fact that they are doing something awful," said James Trombly, president of Delphi Technology Solutions, a Lawrence, Massachusetts, computer services firm that helped three clients over the past year pay ransoms in Bitcoin, the virtual currency. He declined to identify the clients.

Advertisement

Ransomware victims reported total costs from such attacks of $209 million (roughly Rs. 1,386 crores) in the first three months of this year, the FBI said, citing a tally of complaints it has received. That's up dramatically from $24 million (roughly Rs. 159 crores) for all of 2015.

(Also see:  New Generation of Ransomware Is Emerging)

Costs for victims, beyond ransom, can include large bills for technical support, consultants and security software.

Advertisement

In the December 2014 attack on Tewksbury, the pressure to pay took on a special urgency because hackers disabled emergency systems. That same is true of additional attacks on police departments and hospitals since then. But all sectors of government and business are targeted, along with individuals, security firms said.

Some operations hire underground call centers or email-response groups to walk victims through paying and restoring their data, said Lance James, chief scientist with the cyber-intelligence firm Flashpoint.

Advertisement

Graphic artists and translators craft clear ransom demands and instructions in multiple languages. They use geolocation to make sure that victims in Italy get the Italian version, said Alex Holden, chief information security officer with Hold Security.

While ransomware attacks have been around longer than a decade, security experts say they've become far more threatening and prevalent in recent years because of state-of-the-art encryption, modules that infect backup systems, and the ability to infect large numbers of computers over a single network.

Law enforcement officials have long advised victims against paying ransoms. Paying ransoms is "supporting the business model," encouraging more criminals to become extortionists, said Will Bales, a supervisory special agent for the Federal Bureau of Investigation.

But Bales, who helps run ransomware investigations nationwide from the Washington, DC office, acknowledged that the payoffs make economic sense for many victims.

"It is a business decision for the victim to make," he said.

Run-of-the-mill ransomware attacks typically seek 1 bitcoin, now worth about $420, which is about the same as the hourly rate that some security consultants charge to respond to such incidents, according to security firms who investigate ransomware cases.

Some attacks seek more, as when hackers forced Hollywood Presbyterian Hospital in Los Angeles to pay $17,000 to end an outage in February.

Such publicized incidents will breed more attacks, said California State Senator Robert Hertzberg, who in February introduced legislation to make a ransomware schemes punishable by up to four years in prison. The Senate's public safety committee passed the bill on Tuesday and sent it to the appropriations committee for further review.

Some victims choose not to pay. The Pearland Independent School District near Houston refused to fork over about $1,600 in ransom demanded in two attacks this year, losing about three days of work from teachers and students. Instead, the district invested tens of thousands of dollars on security software, said Jonathan Block, the district's desktop support services manager.

"This threat is real and something that needs to be dealt with," Block said.

The town of Tewksbury has also upgraded its security technology, but Sheehan says he fears more attacks.

"We are so petrified we could be put into this position again," he said. "Everybody is vulnerable."

© Thomson Reuters 2016

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apps, Hackers, Internet, Ransomware
Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Samsung Galaxy Z TriFold May Cost in India
  2. Realme P4x 5G Launch Today: Know Price in India, Specs and More
  3. Redmi 15C 5G Launched in India With These Specifications
  4. iPhone 16 Price Drops Under Rs. 63,000 on Croma With Bank Discounts
  5. Motorola Edge 70 India Launch Date Leaked; Might Arrive With Bigger Battery
  6. OnePlus Ace 6T With Massive 8,300mAh Battery Launched at This Price
  7. Pariah OTT Release: Vikram Chatterjee's Dog-Drama Lands on OTT Soon
  8. Red Dead Redemption Comes to Android and iOS via Netflix Games
  9. Samsung's One UI 8.5 Changelog Leak Hints at Imminent Beta Release
  1. Realme P4x 5G Launching Today: Know Price in India, Features, Specifications and More
  2. Pariah OTT Release: Vikram Chatterjee’s Heart-Wrenching Stray Dog Thriller Set for OTT Debut
  3. Dies Irae OTT Release: When, Where to Watch Pranav Mohanlal's Malayalam Horror Thriller Online
  4. A Nearby Planet May Have Formed the Moon Following a Collision With Early Earth: Study
  5. Netflix’s Gritty Frontier Drama The Abandons to Begin Streaming Soon: All You Need to Know
  6. Superman OTT Release Date Announced: Everything You Need to Know About Clark Kent's Latest Adventure
  7. International Space Station Makes History As Eight Visiting Spacecraft Simultaneously Dock
  8. Dulquer Salmaan’s Kaantha Set for OTT Debut: When and Where to Watch 1950's Period Drama Online?
  9. Motorola Edge 70 India Launch Date Leaked; Indian Variant Said to Feature Bigger Battery, Slim Design
  10. SpaceX Adds 29 New Starlink Satellites in Successful Falcon 9 Launch
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.