Share this article
The British Library has confirmed that its personal HR data has been posted online, for sale to the highest bidder. The attack, which took place in October, has been claimed by known ransomware group Rhysida. They’ve set the “exclusive, unique, and impressive” data for sale with a starting bid of 20 bitcoins (around £596,000) and a deadline of 27th November.
This incident serves as a stark reminder that, as one of the most common forms of cybercrime, ransomware poses a significant threat to businesses across the UK, regardless of size and industry. Despite advances in tech and a nationwide push to school organisations on the importance of effective cybersecurity, the threat of ransomware is more prevalent than ever.
We’re going to take a closer look at the figures surrounding ransomware, exploring what risks businesses face and what you can do to ensure that your data remains protected.
A new assessment from the National Cyber Security Centre (NCSC) reveals the ransomware industry has evolved into a sophisticated supply chain that continues to defy western governments and put unprotected businesses at risk. Ten years after the first widespread ransomware attack – Cryptolocker – the crime continues to take advantage of business’ weak online security.
The main perpetrators existing in Russia, Belarus, and several other former Soviet Union countries, but operators have also been detected in India, West Africa, and South-East Asia.
A recent operation – Qakbot – infected millions of computers with its malware, leaving countless businesses on the back foot. Chester Wisniewski, field chief technology officer at Sophos, says ransomware has proven itself “a tried and true method of extorting money from victims”, describing it as “an everyday part of the criminal threats we face.”
In recent months, hacker group CLoP made headlines by hitting dozens of western company that rely on the MOVEit software, including the BBC, British Airways, Boots and more.
Ransomware is one of the most common kinds of cybercrime. It is a type of malware that prevents you from accessing your own device and data, usually due to external file encryption. In most cases, a criminal group will encrypt your data and demand a ransom in exchange for decryption, hence the crime’s name.
Often, hackers will threaten to delete or leak the data they’ve stolen. This can be particularly damaging if the data in question includes sensitive customer information, as businesses can face hefty fines for failing to keep customer data protected and confidential.
Following on from the British Library’s data theft, the institution said, “We have taken targeted protective measures to ensure the integrity of our systems, and we continue to undertake an investigation with the support of the National Cyber Security Centre (NCSC), the Metropolitan Police, and cybersecurity specialists.”
The NCSC adds: “We are working with the British Library to fully understand the impact of an incident. Ransomware is the key cyber threat facing the UK, and all organisations should take immediate steps to limit risk.”
These steps, however, rarely include paying hackers the money they demand. Ransomware has three key stages: access, activation, and ransom demand, and payment is usually demanded via an anonymous web page and usually in cryptocurrency.
Law enforcements do not encourage victims to pay a ransom because:
Like most cybercrimes, it is much easier, cheaper, and less damaging to prevent ransomware rather than dealing with the fallout. As such, it’s important to take key steps to ensure your business data is safe and secure.
Some of the key actions to protect against ransomware include:
Certain programs like App Locker can be used to limit which applications can be accessed, meaning malware can’t access all data even if it reaches your device. Investing in effective data protection software can also deter criminals.
Even with all the necessary defences in place, you should still prepare for the worst. Create a plan of action should you fall victim to ransomware.
This should include:
Your DR plan should be regularly tested and updated, to make sure it still applies to the way your business runs and stores data. That way, should disaster strike, your team can act decisively and speedily.
If you’re looking for effective data protection for your business, or have any questions about the threat of ransomware on your organisation, don’t hesitate to get in touch. Click here to reach out to the SRM team and we’ll be happy to help.