Register For Our Mailing List

Register to receive our free weekly newsletter including editorials.

Home / 428

Ransomware threatens home, office and national security

Tobias Vernon of the UK owns two small galleries that sell 20th-century ceramics and artworks. Thanks to marketing efforts, the business has almost 50,000 Instagram followers.

In May 2021, an email appeared from Instagram congratulating the business for getting a ‘blue tick’, which bestows on the account ‘authentic presence’. Vernon clicked the link in the email and logged in. Not long after, a message soon appeared:

“We have seized control of your Instagram account …We require US$1,000 to grant you your account back.”

Even the hackers want to be 'trustworthy'!

Vernon eventually paid US$750 in bitcoin to Russians, who released the account. But get this. Three days later, Vernon got an Instagram message from a bakery in Australia that had been hacked by the same group. The baker had been told to contact Vernon for a Tripadvisor-style testimonial that the hackers were trustworthy, so to speak, in that they would release the kidnapped device when paid.

Such traumas are proliferating because the malware-based crime known as ransomware is reaching menacing proportions. Criminally installed encryption that is reversed only by ransom is rising "almost exponentially” in the words of FBI Director Christopher Wray because the virtual private networks that enable working from home have made business systems more vulnerable.

US cyber-security firm Mimecast found that 61% of the 1,225 global IT firms it surveyed suffered ransomware attacks in 2020, a 20-point jump from 2019. The Australian Cyber Security Centre, a government agency, said ransomware attacks in Australia rose 15% last financial year to 500 incidents. Global security group, Institute for Security and Technology, estimates 2,400 ransomware victims in the US paid nearly US$350 million in ransom in 2020, a 311% jump in payments from 2019.

Ransomware “is an urgent national security risk” because “attacks on the energy grid, on a nuclear plant, waste-treatment facilities … could have devastating consequences,” the Institute cautioned. As such warnings signal, ransomware has evolved from a cottage industry into something resembling a “criminal franchising arrangement”, according to the Australian Cyber Security Centre.

Nothing is safe from virtual kidnappers

Among notable attacks this year, in March, US insurer CNA Financial reportedly paid a then-record US$40 million ransom. In May, ransomware disrupted Colonial Pipeline, which carries 45% of US east coast fuel supplies, for 11 days until a US$$4.3 million ransom was paid for a malfunctioning decrypter key. In July, a ransomware attack on the US-based software company Kaseya was notable for gifting up to 1,500 global victims to the criminals and that the ransom demand was a record US$70 million. The biggest ransomware attack in terms of victims is still the ‘WannaCry’ one in 2017, when up to 300,000 computers were infected though the criminals received limited payment.

Ransomware is flourishing because the risk-reward calculation favours the attackers. What choice do companies have but to pay a government-protected group that might destroy their mission-critical computer system?

Paying the ransom, however, often fails as a solution. The Mimecast survey found that 52% of ransomware victims paid the ransom but only 66% of those recovered their data – the others were double-crossed.

The hope is that the risk part of the calculation might increase to the detriment of the scammers because western governments are enhancing and coordinating efforts to stop ransom attacks. Officials too are warning internet users to be better prepared for these attacks.

Eradicating the threat seems far off. Computer systems are impossible to secure and it’s expensive to try. Phishing emails and other scams too easily trick people into installing malware. Enough employees are willing to sell passwords on the ‘dark web’. Perhaps, though, the greatest asset ransomware criminals have is that cryptocurrencies are hard to trace. Many advise that a government crackdown on cryptos is the best way to reduce the menace.

The US’s unprecedented move in September to blacklist a Russian-owned crypto exchange shows Washington might agree. Something needs to tackle this mobster shakeout for using the web before the damage reaches national-security proportions.

Even if defensive efforts increase, ransomware appears unbeatable when five billion people are connected to the internet. As ransomware is online, the public seems to be unable to come to terms with the magnitude of the threat, which hampers the fightback. It’s true that ransomware would exist even if cryptos didn’t but it might barely register as a danger because how would the criminal be paid?

Some victims refuse to pay and the criminals back down. The ‘WannaCry’ attack emanating from North Korea generated little ransom for the attackers but according to the world’s anti-laundering body caused an estimated US$8 billion in damages to hospitals, banks and businesses across the world.

Attack the problem at the payment end

Such calculations show that the ransomware threat needs to be taken much more seriously. The non-virtual world provides the clue to defeating the menace. Kidnapping is a rare crime nowadays because the police caught kidnappers when they spent the cash. The solution to ransomware might be to regulate cryptocurrencies, possibly – as is the intention of China’s ban on crypto activities – to the point where they are unviable.

Such actions might mean the world loses the (disputed) benefits of cryptocurrencies. But that’s part of the cost-benefit analysis governments need to undertake to defeat the scammers that hound legitimate users of the internet, be they UK gallery owners or bakers in Australia.

 

Michael Collins is an Investment Specialist at Magellan Asset Management, a sponsor of Firstlinks. This article is for general information purposes only, not investment advice. For the full version of this article and to view sources, go to: https://www.magellangroup.com.au/insights/.

For more articles and papers from Magellan, please click here.

 

RELATED ARTICLES

Fight cybercrime by investing in cybersecurity

Cybercrime response may slow internet

banner

Most viewed in recent weeks

2024/25 super thresholds – key changes and implications

The ATO has released all the superannuation rates and thresholds that will apply from 1 July 2024. Here's what’s changing and what’s not, and some key considerations and opportunities in the lead up to 30 June and beyond.

The greatest investor you’ve never heard of

Jim Simons has achieved breathtaking returns of 62% p.a. over 33 years, a track record like no other, yet he remains little known to the public. Here’s how he’s done it, and the lessons that can be applied to our own investing.

Five months on from cancer diagnosis

Life has radically shifted with my brain cancer, and I don’t know if it will ever be the same again. After decades of writing and a dozen years with Firstlinks, I still want to contribute, but exactly how and when I do that is unclear.

Is Australia ready for its population growth over the next decade?

Australia will have 3.7 million more people in a decade's time, though the growth won't be evenly distributed. Over 85s will see the fastest growth, while the number of younger people will barely rise. 

Welcome to Firstlinks Edition 552 with weekend update

Being rich is having a high-paying job and accumulating fancy houses and cars, while being wealthy is owning assets that provide passive income, as well as freedom and flexibility. Knowing the difference can reframe your life.

  • 21 March 2024

Why LICs may be close to bottoming

Investor disgust, consolidation, de-listings, price discounts, activist investors entering - it’s what typically happens at business cycle troughs, and it’s happening to LICs now. That may present a potential opportunity.

Latest Updates

Shares

20 US stocks to buy and hold forever

Recently, I compiled a list of ASX stocks that you could buy and hold forever. Here’s a follow-up list of US stocks that you could own indefinitely, including well-known names like Microsoft, as well as lesser-known gems.

The public servants demanding $3m super tax exemption

The $3 million super tax will capture retired, and soon to retire, public servants and politicians who are members of defined benefit superannuation schemes. Lobbying efforts for exemptions to the tax are intensifying.

Property

Baby Boomer housing needs

Baby boomers will account for a third of population growth between 2024 and 2029, making this generation the biggest age-related growth sector over this period. They will shape the housing market with their unique preferences.

SMSF strategies

Meg on SMSFs: When the first member of a couple dies

The surviving spouse has a lot to think about when a member of an SMSF dies. While it pays to understand the options quickly, often they’re best served by moving a little more slowly before making final decisions.

Shares

Small caps are compelling but not for the reasons you might think...

Your author prematurely advocated investing in small caps almost 12 months ago. Since then, the investment landscape has changed, and there are even more reasons to believe small caps are likely to outperform going forward.

Taxation

The mixed fortunes of tax reform in Australia, part 2

Since Federation, reforms to our tax system have proven difficult. Yet they're too important to leave in the too-hard basket, and here's a look at the key ingredients that make a tax reform exercise work, or not.

Investment strategies

8 ways that AI will impact how we invest

AI is affecting ever expanding fields of human activity, and the way we invest is no exception. Here's how investors, advisors and investment managers can better prepare to manage the opportunities and risks that come with AI.

Sponsors

Alliances

© 2024 Morningstar, Inc. All rights reserved.

Disclaimer
The data, research and opinions provided here are for information purposes; are not an offer to buy or sell a security; and are not warranted to be correct, complete or accurate. Morningstar, its affiliates, and third-party content providers are not responsible for any investment decisions, damages or losses resulting from, or related to, the data and analyses or their use. To the extent any content is general advice, it has been prepared for clients of Morningstar Australasia Pty Ltd (ABN: 95 090 665 544, AFSL: 240892), without reference to your financial objectives, situation or needs. For more information refer to our Financial Services Guide. You should consider the advice in light of these matters and if applicable, the relevant Product Disclosure Statement before making any decision to invest. Past performance does not necessarily indicate a financial product’s future performance. To obtain advice tailored to your situation, contact a professional financial adviser. Articles are current as at date of publication.
This website contains information and opinions provided by third parties. Inclusion of this information does not necessarily represent Morningstar’s positions, strategies or opinions and should not be considered an endorsement by Morningstar.