<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ransomware firm deals with hackers ... in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Ransomware-firm-deals-with-hackers/m-p/24250#M3064</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/297159657"&gt;@Flyslinger2&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would assume and hope that some governing body will sanction (approve) vendors so that they can truthfully advertise their skills and you can be assured of getting the desired results.&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I agree that there was a gross misrepresentation on the part of the vendors, but no one can be assured of getting the desired results in cases of ransomware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the only choices you are presented with, (regardless of how you got there), of either paying ransom or losing data, few can afford to chose moral high ground and &lt;U&gt;attempt&lt;/U&gt; to recover data using 3rd party consulting services.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Paying ransom, while does not guarantee the data recovery, still has higher probability of success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hence the proliferation of the attacks that are a lot more targeted than those in the past.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jun 2019 12:38:45 GMT</pubDate>
    <dc:creator>vt100</dc:creator>
    <dc:date>2019-06-26T12:38:45Z</dc:date>
    <item>
      <title>Ransomware firm deals with hackers ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Ransomware-firm-deals-with-hackers/m-p/24248#M3063</link>
      <description>&lt;P&gt;You MUST do your due diligence even when looking for professionals to assist you with your ransomware attack.&amp;nbsp; It seems a couple companies have cashed in on the weakness of their customer and made bank.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would assume and hope that some governing body will sanction (approve) vendors so that they can truthfully advertise their skills and you can be assured of getting the desired results.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.propublica.org/article/sting-catches-another-ransomware-firm-red-mosquito-negotiating-with-hackers" target="_blank" rel="noopener"&gt;Scammers&lt;/A&gt; are everywhere.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 12:00:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Ransomware-firm-deals-with-hackers/m-p/24248#M3063</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2019-06-26T12:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware firm deals with hackers ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Ransomware-firm-deals-with-hackers/m-p/24250#M3064</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/297159657"&gt;@Flyslinger2&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would assume and hope that some governing body will sanction (approve) vendors so that they can truthfully advertise their skills and you can be assured of getting the desired results.&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I agree that there was a gross misrepresentation on the part of the vendors, but no one can be assured of getting the desired results in cases of ransomware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the only choices you are presented with, (regardless of how you got there), of either paying ransom or losing data, few can afford to chose moral high ground and &lt;U&gt;attempt&lt;/U&gt; to recover data using 3rd party consulting services.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Paying ransom, while does not guarantee the data recovery, still has higher probability of success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hence the proliferation of the attacks that are a lot more targeted than those in the past.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 12:38:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Ransomware-firm-deals-with-hackers/m-p/24250#M3064</guid>
      <dc:creator>vt100</dc:creator>
      <dc:date>2019-06-26T12:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware firm deals with hackers ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Ransomware-firm-deals-with-hackers/m-p/24281#M3066</link>
      <description>&lt;P&gt;Let me stick my oar in. Since ransomware is a form of malware, and since I've known about it since the first case in 1989 (and wrote about it in both &lt;A href="http://victoria.tc.ca/int-grps/books/techrev/bkcvp2.html" target="_blank" rel="noopener"&gt;virus&lt;/A&gt; &lt;A href="http://victoria.tc.ca/int-grps/books/techrev/bkvr.rvw" target="_blank" rel="noopener"&gt;books&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make a backup. Make multiple types of backups, if stuff is important to you. Remember layered defence. It should be part of your BCP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have some awareness. I mean, quite aside from ransomware not being new, and going back to 1989, stories are hitting the nightly TV news just about every week these days. Pay attention!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Don't pay ransom. It only encourages them. And others. Anybody who pays ransom is supporting the ransomware "industry." Period.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Well, if you think you &lt;STRONG&gt;need&lt;/STRONG&gt; to pay a ransom, then you didn't make a backup when I told you, right?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ransomware isn't one thing: it's many different programs and families, with all kinds of different capabilities.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes they encrypt without a key, and *nobody* can get your data back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes they encrypt with a single symmetric key and anybody can get your data back: even you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes they do a proper encrypting job but are too cruel or lazy to respond when you contact them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you do get hit, contact a reputable anti-virus/anti-malware company. Since ransomware is a form of malware, most such companies will be keeping track of the various ransomware programs, and can tell you whether a) the encryption is done wrong and *nobody* can get your data back, b) the encryption is done right but these guys aren't to be trusted, or c) the encryption is done sloppily and there is a quick fix that will get your data back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And don't pay ransom.&amp;nbsp; Not even second hand.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 19:00:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Ransomware-firm-deals-with-hackers/m-p/24281#M3066</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-06-26T19:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: Ransomware firm deals with hackers ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Ransomware-firm-deals-with-hackers/m-p/24355#M3075</link>
      <description>&lt;P&gt;Apparently there are &lt;A href="https://thehackernews.com/2019/06/florida-ransomware-attack.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+TheHackersNews+%28The+Hackers+News+-+Cyber+Security+Blog%29&amp;amp;_m=3n.009a.2017.el0ao0e57v.192k" target="_blank" rel="noopener"&gt;those&lt;/A&gt; that don't agree with your position.&amp;nbsp; I'm neutral to leaning pay but it still depends on the situation.&amp;nbsp; I think there are enough tools, techniques and digital forensics experts out there that can chase these perps to the ground, especially if they are paid.&amp;nbsp; Digital coins always leave a bread crumb trail so they can be tracked.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 16:34:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Ransomware-firm-deals-with-hackers/m-p/24355#M3075</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2019-06-27T16:34:53Z</dc:date>
    </item>
  </channel>
</rss>

