Ransomware Attacks Today are Changing – Here’s How
You may have heard of ransomware before. This type of cyberattack gets into your device (or a company network), encrypts everything, and demands a ransom to get your files back. But ransomware attacks today aren’t just encrypting your files and hoping for a payout. Criminals are finding new ways to pressure victims. They’re using AI to move faster than ever before. And they are finding ways to target you without ever having to get into your systems. Understanding how these attacks work and knowing what to do when it happens has never been more important.
See Ransomware Evolution with Allan Liska for a complete transcript of the Easy Prey podcast episode.
Allan Liska is an information security expert and ransomware research. With over three decades of experience in InfoSec and over a decade working specifically on malware, he’s provided recommendations to global corporations and government agencies, sits on national ransomware task forces, and has been cited in The New York Times, Bloomberg, The Washington Post, Wired, NBC News, and more. Currently, he is the Field CISO at Recorded Future, a threat intelligence company.
Allan first became interested in ransomware while working for FireEye. They had just released a major report on Chinese nation-state activity, but Allan found most companies weren’t interested in that problem– they saw a much bigger problem with ransomware. He brought it up to the detection team at FireEye, but they weren’t very interested in working on that problem. But when FireEye acquired Mandiant, some Mandiant researchers had noticed the same thing. Allan started a small team figuring out how to build detection and offer solutions. He’s been immersed ever since.
How Ransomware Attacks Have Evolved
When Allan first started looking into ransomware, even attacks against big corporations would just hit a single computer and ask for a few hundred dollars. IT departments wouldn’t pay, they’d just wipe the device. But sometimes people got embarrassed that it had happened and paid the ransom themselves. Even today, the most prolific ransomware attack is still STOP/DJVU, which encrypts a single machine and asks for around $500. It doesn’t usually hit even moderately-protected machines, but it’s prolific in places like India and Bangladesh.
Overall, the biggest change is going from attacking single machines to entire networks. In 2016, a ransomware group hit Hollywood Presbyterian Hospital, took out the entire hospital, and asked for $17,000. At the time, that amount was unheard-of. But the bad guys quickly realized that they could make a lot more money from encrypting entire networks than individual devices.
In 2019, the Maze ransomware added another component – releasing data. Criminals had always been stealing data with ransomware attacks, but before this, nobody knew what they were doing with it. Allan thinks they didn’t even know what to do with it. But with the Maze ransomware, the criminals set up a website and threatened to publish all the data if the company didn’t pay. Before this, companies tended to deny they’d been hit by ransomware. But now threat actors had proof. All of the sudden, the bad guys were doing PR operations. All of this led to an explosion in ransomware.
It’s Not Just About Your Data
A few years into the explosion of ransomware, criminals started to realize that it’s actually hard to do effectively. Ransomware has a trust paradox – the people behind it are thieves and criminals, but they need to get their victims to trust them enough that they believe paying the ransom will get their files back and keep them from getting published. If you get a reputation for not decrypting the files even after the victim pays, nobody is going to pay.
Anybody who does ransomware response will tell you that a lot of the time, the tools the criminals give you just don’t work. Just because they give you the decryption key doesn’t mean it will actually work. The bad guys figured out that if they can steal the right data, they’re just as likely to get paid. Then they realized that they don’t even necessarily have to get into your network. If they can break into your partners’ networks or your partners’ partners’ networks and get some data with your name on it, they can pretend you’re the victim and people will believe it.
The marketing department hates the analogy, but Allan compares it to the STD PSAs from the 1990s, where they say it’s not just about who you sleep with, but who they slept with and who those people slept with. Ransomware attacks today aren’t just about how you’re securing your data, but how well your partners and service providers and how their partners and service providers are securing it.
It’s not just how is your data secured, but how is your partners’ data secured and your partners’ partners’ data secured.
Allan Liska
Sometimes the Data is Fake
The newest thing Allan is seeing in ransomware attacks today are ones that don’t even involve actual ransomware. Criminals are using AI to create fake data and claiming companies are “victims” when they never attacked them at all. Now companies have a new challenge of trying to prove the negative. If a criminal says they stole your data, how do you prove that it’s not actually your data? That’s where data governance comes in. In the past, security and data governance have always been separate and not really talked. But now they have to be able to work together to figure out if the data is even real.
It takes a lot of factors to make an educated guess about whether or not the data is real. Some data tends to change frequently, so even if it doesn’t match current data, it’s possible that it’s real and just old. Then, you have to look at the data structure to see if it matches any of your vendors. You also have to check the reliability of the ransomware group making the claim to see if they’re known for posting fake data.
Ultimately, it’s hard to prove a negative. But if you can’t find evidence of a breach or attack, the data structure doesn’t match anything you’d expect, and the group is known for posting fake data, there’s a good chance it’s not real. Even though it’s not real, though, it can still be a PR risk to the company. For decades, companies downplayed or denied potential breaches until they couldn’t anymore. Even if you announce that it’s not really your data, some people are still going to believe you’re the one lying.
Ransomware Attack Response Today
Allan did ransomware incident response for years, and he’s always amazed with how people come together. Every department wants to come to help. But almost a third of security people who have been through a ransomware attack leave that job within six months because it burns them out. They’re responsible and want to fix it, but it’s a lot of work. Allan has been in incidents where he’s had to force people to go home because they wanted to keep working until they dropped. And that’s not healthy. No matter how crucial you are, you’re going to be less effective if you haven’t slept for 24 hours.
Something like 60% of security people who have been through a ransomware attack leave that job within six months because of burnout.
Allan Liska
It’s also interesting that the security budget tends to expand after a big attack. Often the security department has been asking for things for years, and after an attack, they suddenly get approved. It doesn’t last forever, but they tend to get at least a couple years of improved budget. Allan recommends part of an incident response plan include a few top priorities to ask for when that budget opens up. Otherwise, it tends to go to consulting. Allan doesn’t have anything against consultants, but they can eat up budget that could otherwise have gone to something that might make a real long-term difference.

Ransomware Attacks Today Target Everyone
Some small businesses assume that ransomware only goes after big companies that can afford millions in ransom, so they’re not targets. But that’s not true. During the pandemic, there were a lot of big ransomware attacks against places like auto dealerships and dentist offices. These are relatively small businesses in the grand scheme of things. And the ransoms, in the $20,000-$50,000 range, aren’t much compared to more high-profile attacks. But that can be enough to put a small or medium-sized company out of business.
Criminals will gladly extract money from small businesses. In fact, ransomware attacks today are specifically targeting smaller businesses. They target them specifically because they know these businesses don’t have security teams, cyber insurance, or other tools to protect themselves. They assume because of this, smaller businesses will be more likely to pay. But unfortunately, it often means these businesses just shut down, either because the payment took too much of their budget or because they didn’t pay and couldn’t keep operating without the locked files.
If you are a small business, you absolutely can be targeted, and don’t think they won’t try and extract every last dollar out of you that they can.
Allan Liska
People are Still Paying Ransoms
On average, fewer ransomware victims today are paying the ransom. But the ones that do are paying a larger amount on average. There is an ongoing trend where the number of victims keeps going up, too, so even though a smaller percentage are paying, that’s still a lot of people. Unfortunately, that means the bad guys are still making a profit.
Ransomware is one of those few things where [criminals] can still make money.
Allan Liska
There are also a lot more criminals doing ransomware attacks today than in the past. That’s because it’s one of the few places where they can still make money. Selling credit card numbers used to be profitable, but banks have gotten good at flagging fraud and people are paying more attention to alerts. Business email compromise (BEC) can make money, too, but only a certain type of criminal does that.
As security gets better and defenders get better at detection and prevention, there are fewer and fewer profitable crimes out there. They tend to be clustered in different parts of the world based on available resources. Russia has a long history of math and software development, and a lot of ransomware comes from there. Nigeria and Kenya are largely English-speaking and specialize in BEC. Southeast Asia has cheap labor and is the center of scam call centers. Ransomware is still one of the most profitable types of cybercrime, and it has a low barrier to entry, so a lot of cybercriminals are doing it.
Ransomware is still one of the most profitable types [of cybercrime] and has a relatively low barrier of entry to get in.
Allan Liska
Making Paying Illegal Doesn’t Work
Some countries have tossed around the idea of making ransomware payments illegal. But it doesn’t work. If a company is multinational, they’ll have a subsidiary in a place where they will be able to pay. And there’s no evidence that it actually deters either the payment or the crime.
Allan likes the model that the United Kingdom is proposing more. Essentially, it’s a license to make a payment. If you get hit with ransomware, you reach out to an agency of the British government and say you want to make a payment. They ask for the details, then approve you to make the payment. Then they can track it. If there’s a chance to get your money back or learn more about the ransomware group, that will help with that.
Allan doesn’t like the idea of paying ransoms. All you’re doing is making ransomware attacks more successful. But he’s also helped hospitals where if they didn’t make the payment and get their systems back, people would die. No hospital administration should ever have to decide the dollar value of a human life, and it’s awful that sometimes they have to. That’s why Allan is also a big proponent of finding programs that help hospitals, especially rural ones, secure themselves and get resources for better security.
I wish nobody would ever make a [ransomware] payment because all you’re doing is making them more successful.
Allan Liska
The Criminals Make Mistakes
Cybercriminals make mistakes all the time. We don’t hear about them because it’s harder for security companies to sell products if they share how bad some of these criminals really are. But they’re not all as skilled as we think. In security, there’s the saying that we have to be perfect all the time, because if we make one mistake, the bad guys are getting in. But the same is also true for the bad guys.
Ransomware actors make mistakes all the time. You don’t hear about those because [then] I can’t sell you a security product.
Allan Liska
When Russia invaded Ukraine, a Russian cybercriminal (known for his info-stealer program) decided to leave. He moved to Poland with his fiancé. He paid a lot of attention to privacy and security. But his fiancé posted a photo on Instagram from a town square in Poland. Europol was watching her, figured out where they were from the picture, and reached out to Polish police. He’s now on trial.
Some criminals use AI for their ransomware attacks, and the AI doesn’t actually encrypt anything but says it did. Lots of ransomware actors use the same encryption key for every victim. Last year, the ransomware group Cl0p launched a campaign where almost nobody paid – because the data they stole was package tracking data from a logistics company, and nobody cared. Sometimes bad guys make mistakes and run into problems, which makes it easier for people trying to defend against ransomware attacks today.
Learn more about Allan Liska and connect on LinkedIn.
