This podcast from the National Cybersecurity Centre discusses ransomware as a major cyber threat, explaining it as software that encrypts data to extort payments, often alongside data theft. The impact on victims varies: less cyber-mature organizations may face existential crises, while larger ones with backups can recover but remain at risk from data leaks. Ransomware has evolved from targeting individual devices to "big game hunting" of large entities, driven by cryptocurrency and professional criminal networks. Recent trends show a move toward data extortion without encryption, as criminals adapt to improved victim defenses. High-profile incidents like WannaCry and Colonial Pipeline highlighted severe disruptions, but many groups now operate discreetly to avoid law enforcement attention. The ecosystem is complex, involving affiliates, brokers, and ransomware-as-a-service models, making attacks opportunistic and attribution challenging. The discussion emphasizes ransomware as an adaptive criminal business, continuously evolving to maximize profits.
[Music] Hello and welcome to the first ever podcast from the National Cybersecurity Centre. Today we're talking about ransomware, one of the biggest cyber threats facing the UK and the focus of our recent report on the changes to the cybercrime ecosystem. My name's James Stewart, Director of Communications at the NCSC, and I'm really excited to be joined by Eleanor Fairford, Deputy Director of our Insta Management team, and Martin P., Cybercrime Operations Lead here, and one of the authors of our report. Welcome to both of you. Thank you. Thanks James. So first of all, let's just start from the kind of top. What is ransomware? So, it is basic, ransomware is just a piece of software that will encrypt all your data. The way it's typically used by criminals is to encrypt all your data and then demand impairment, often coupled with stealing all of your data and also part of the demanding impairment. Sometimes you get a bit of a mix-march, sometimes they decide to only steal the data, which technically isn't ransomware, it's extortion, but it's used in the same. It's all part of the same ecosystem, it's all part of the same technique to get your money. And Eleanor, on a sort of day-to-day basis, you're dealing with victims of cyber incidents, including ransomware incidents. What is the feeling if you're a victim? How does it feel to be a victim? I think the impact of ransomware berries, according to the type of organisation that suffers the attack. For the least cyber-mature organisations, for those who cyber-defences are the least advanced, they are more likely to find the kind of encryption event that Martin is describing to be truly kind of annihilating, an extinction event is sometimes described as. Something that has a really detrimental impact on their ability to conduct their business. And in those circumstances, potentially considering getting hold of the decryption key through pay in the ransom is sometimes the only way they might get back on their feet. However, for a larger organisation who has more extensive cyber-defences in place and who is potentially better set up to deal with this kind of a cyber attack, they may be able to rebuild from backups, they may be able to somehow get around the encryption, they might be able to deal with the encryption event themselves, certainly if they've implemented the NCSE's preparatory guidance and advice. However, they will still be vulnerable if their data has been taken and if they're being extorted for a demand for payment in exchange for not leaking that data. There's a way to think about this from a sort of personal perspective, if you're not a business owner, it's easy to imagine that, oh well, you should have been better prepared from cyber security, blah blah blah. But if you think about from a personal point of view, if you go hit with something such as this and it encrypted all of your personal photos, loved ones, grandparents, perhaps grandparents that you'll never see again, and the only way for you to get that back is by paying the encryption. It's really good-ranging for an individual. Expand that to a small business or a medium-sized business where this is like an existential crisis, as I said. That's the same sort of feeling you've worked for quite a long time to build this business that you care quite a lot of these people who are depending on payment and their livelihoods depend on this. It can be quite a motive if you think about it in all sorts of terms. And now just take us back a bit to, because ransomware is not a new phenomenon, is it? But we see it evolving all the time. So just take us back to how it initially started as a phenomenon and then we'll get into how it's developed over recent years. Some of the earlier examples go back to 2010 to 2013 sort of period, but it mostly focused on encrypting single user devices. Sometimes those were within businesses, it was just a single device. We haven't got any other way of making money out of this company, so we'll break the device. As times gone on, people have noticed, hey, if I can take out a whole network, I can get a whole lot more money. And add that to the availability of cryptocurrency, which is a lot easier for criminals to handle and exchange. You don't have to worry about if someone makes a payment in dollars to a bank account, it's a lot less anonymous. And even though blockchains are available to be able to dress up with that, the anonymity of personal attribution to cryptocurrency is a lot bigger than it is with traditional currencies. So it's really sort of grown out of us. And it always started to really become a big problem in this way and sort of live 2017, 2018 sort of period where we really started to grow. And so we're seeing an evolution between encrypting single devices to what. In the report we've recently put out with the National Crime Agency, you call big game hunting. And what does big game hunting mean? It's the act of targeting large organisations for the bigger payouts. In the same sort of way as you would go to Africa to hunt big game. It's the same sort of thing bigger rewards for hitting large organisations. And so Eleanor, we're seeing a sort of different model of operation from ransomware criminals towards encrypting data as well as disabling systems. Can you say a bit about that? Yeah, absolutely. So typically a ransomware threat actor will spend time conducting reconnaissance through a victim's networks in order to identify how to effectively encrypt them and the best way to go about it. But also what is the valuable data that is held? What are the crown jewels? And potentially what is the PII, the personally identifiable information? And also financial data that might be able to be used to obtain financial rewards in some fashion. These are criminal gangs that we're talking about after all. So during that process they will be looking for the things that they are able to translate into financial gain or to make money from. And although the encryption event historically has also has usually been the main method of securing financial gain, actually increasingly is being recognised that that data that they are getting hold of, they can successfully threaten to make that publicly available. albeit it's usually as part of a dark web leak site sort of process and it's not the front page of the sun. But nonetheless it is made publicly available and they will threaten to do that unless a ransom is paid and that's the sort of data extortion trend that is becoming increasingly common these days. And we've seen quite a few very high profile ransomware incidents in recent years haven't made. Do you want to talk through a couple of those examples? Then I just start off with the main one that got everyone very excited back in 2017 when WannaCry hit the NHS. And I think that really, you know, was the start of the high level concern here. However it turned out that WannaCry itself wasn't actually a classic ransomware attack in so far as although it encrypted networks across the globe and utterly indiscriminate and sort of mass propagated way. The Bitcoin wallets didn't work properly so the actual payment processes didn't work. And there was speculation at the time that the only people actually making payments were like law enforcement agents trying to get hold of, you know, track down the bad guys. But ultimately it was actually a sort of false ransomware attack. But it's thought that everyone remembers because it was a very widespread encryption event. And it demonstrated really vividly across across the globe, but particularly in the UK to the UK government and others that really important critical institutions in this case, the National Health Service could fall victim to this kind of attack. So it was a really salutary lesson that some of our most fundamental infrastructure in the UK is vulnerable to this kind of activity. And of course, there have been many, many other attacks in the intervening years, most of which do not make it to the headlines in the same way. Those that have attracted a lot of publicity have, of course, included things like colonial pipeline in the US. And what happened there? Colonial pipeline in the US was another ransomware attack where a gang successfully encrypted the systems of an industrial pipeline, but it was their corporate billing and payment systems that were impacted. We often worry that a cyber attack is going to effectively take out operating technology. You'll switch off the pipeline or it'll do other stuff like switch off a power grid. In this instance, it did not successfully do that, but by virtue of encrypting the payment systems and encrypting the corporate networks, the company was actually forced to switch off the pipeline. So it had direct operational impact, which ultimately in the US translated to things like petrol stations, not being able to sell gas to you to vehicle owners, etc. So it had real world impacts and was kind of their version of what I suppose it was their version of really seeing what this sort of attack could do in terms of day to day impact on people's lives. And thereby raised up the political agenda and it made it something that the Biden administration was very exercised about and turned it into a topic that governments worldwide are now looking at how's it got after? And the health service in Northern Ireland also had a significant ransomware attack, didn't it? It did. It had a really significant ransomware attack and I believe and Martin may have a different additional details, but we're talking about an affiliate group of a broader umbrella OCGE organised crime group who ultimately long story short didn't retain the encryption and gave back the key to decrypt the networks, having realised they've taken out a health organisation and not wanting to sort of go ahead with their threats. So they gave them back the key and the health service was able to get back on its beat without paying a ransom. I believe that was how that all played out yet. Yeah, it was really interesting to watch some of the player back from the actors themselves and the ones who conducted the attack actually were really, really excited because they thought they'd only hit a hospital at first. But when it turned out they did a whole national health care service, they thought it was great fun and this was a great opportunity. The company they were working with who provided them with the ransomware realised the significance of actually taking out national health service, one could massively impact threat to life. They also the level of law enforcement attention that you've got is very, very different. And with all of these, they do also have a little bit of reputation that they have to maintain. So they were quite clear where, no, I'm sorry, you'll give the key back. They weren't quite as polite as that, but there was very key with it and you will not continue. Which is a really interesting example of how these threat actors don't really want to hit the headlines and they don't want to attract the attention of the law enforcement agencies or others. When the gang behind the colonial pipeline attack attracted the attention of law enforcement, the FBI managed to find a way to recoup parts of the ransom payment. And some of this I think casts a long shadow over the activities of these groups. They recognise that it's not in their interests to hit the really big targets, to attract the national headlines, to have a nationally significant impact. So instead, the way that I would characterize it now is you're much more likely to see these attacks happening to smaller organisations outside of the national picture amongst whom it's now actually becoming kind of endemic. It's just part of day-to-day business life. And by staying out of the headlines, they can just keep it on going in the background. So it's a broad mix. There are some that are in the UK and US recently in the news, the scutted spider group who have recently done ransomware attacks using Alfie. The majority of them, however, are we tend to say Russian speaking is the best way of describing it. Not necessarily Russians, but Russian speaking community, either in Russia or near Russia or in since the Ukraine war started recently fled Russia. Part of that is they're less likely to come under prosecution because they're not targeting people in Russia and it's broadly considered its okay. Also partly because the Russian criminal community and much more professional, they have a lot more of the support mechanism around them. They have criminal forums that almost exclusively Russian speaking in some cases where they can get help support by services that enable them so they don't need to be able to do the whole end to end piece. So ransomware has been around for a while. Why are we discussing this now? So after a few peaks in the interest in ransomware and recent years as we described earlier with the really large scale events took place, numbers have continued to increase over time. And in terms of recent trends, what we're seeing is in addition to addition to the encryption that we've been talking about, the data extortion now is becoming more and more effective as a tool of acquiring ransom payments given the value that has now been recognized by the ransomware groups. So increasingly data extortion is rising as a trend, sometimes without even encryption taking place. And this is the mo that the groups now are typically targeting. From a criminal perspective, you have to think of it as obviously the business business as well of all what's the best way to get the money out and we have seen criminals that have considered some of this. And while sometimes they will target manufacturing systems, we're actually losing the ability to produce is really important. In a lot of cases, things like PII is far far more effective is a lever. And actually in some cases, because people are getting better at having backups, that is having a big driver on how criminals approach the problem. So lots of companies can recover from backups and that is resulting in a lot of payments. The conversion rate from victim to payment from a criminal's perspective is far far lower than it used to be. It is typically somewhere between sort of 10 to 25%, which is relatively small when you consider, which also means you then need a large volume of victims. And there's no point was deploying the encryption if people are going to recover it. So we'll just go for the extortion because that's what people are actually carrying out. They carry about the reputation, they carry about the PII damage that's going to happen with their customers. So essentially the business model is changing. Yes, it'll always continue to adapt. It is a business like any other. It will evolve as and when there is a need to get more money or as and when they spot an opportunity to get more money. Part of the reason for us writing the paper now is to while the paper covers quite a long period, because it's the first one we've wrote since 2016. The thing that we really want to highlight as part of that is that this is a business. It is a series of businesses. There's a much more complex ecosystem that's going to continue and evolve all the time. Because a lot of people do just focus on this ransomware variant or that ransomware variant and see that as the totality of the threat, where in reality they're just the brand that you see at the front with a whole series of businesses behind them that drive and continue to evolve, which is why you see so much variety in the hopeless. Thinking about them as a kind of criminal like business is interesting because they also have kind of customer help lines and things like that don't they? Yes. Some of them consider themselves pan-testers, which is really insulting to pan-testers. They consider what they do is a relatively legitimate service that they're providing to you. The fact that they've just destroyed your business means nothing to them. They feel like they're entitled to payment for the service they rented you by pointing out the holes in your network. And there's at least one group who after an instant was paired up, they followed through with here's our security advice complete with which companies they recommend for security products and everything. A nice pan-test type report. It's an unusual view on the world. So who are the big guys in this space? Who are the main group? So the main groups that we see most frequently tends to be Lockbitt and Alfie have been pretty consistently towards the top of the list of that we see so see in the UK. And these Russian speaking groups? They are Russian speaking groups here. They've been consistently there for probably the last few months if not the last year possibly. I think the only thing I would add is that it's really hard to know who is actually behind any given ransomware attack. And although the strains themselves as Martin describes can be tracked to a certain extent, there's a huge amount of chaos and fluidity in movement between them. And with the affiliate model where you have, you know, random people leasing the infrastructure to deploy themselves, sometimes not even very much to the knowledge of the original group. It creates a really murky ecosystem and the possibility of attributing any given attack to any given individual group individuals is really low and it's something that's a very difficult exercise city. Yeah, that's a really important point. In some cases, there can be as many as five different groups involved in a ransomware incident because of the way the ecosystem is sort of set up in a almost microservice. Is this what we mean when we hear ransomware as a service being used? Yes, so ransomware as a service is the selling of ransomware and some of the support infrastructure like the leak site, it usually communications platform to talk to the victims, those sorts of services. What they don't typically do is they don't target anyone. They sell lots to other people who do. And even when I say targeting targeting is very, very loose in that sense, often the affiliates who deploy the ransomware, are dependent on initial access brokers who will gather large scale accesses across the world and sell laws on it profits to the affiliates. So when we say targeting really it's choosing from the available accesses that they think will generate the most profit. They rarely pick an organization and persistently go after them in the same way you would see would say advanced persistent threats. It's very much opportunity basis, what is available, what can I get the most profit out of and they're very, very invested in a return on investment. The persistent attack against an organization doesn't work out profit wise because you can waste six months trying to get into an organization who may or may not pay up. I think all I would add to that is that we commonly get asked after a ransomware attack happened, you know, is it targeted? I just mean a particular sector is under attack and like more is going to happen. And generally speaking, just as Martin says, like the entire enterprise is opportunistic in discriminate. And it's about where you've got these open doors and which ones you might choose to go through. However, there is one school of thought around whether paying a ransom makes you more likely to be identified as a sort of follow up sector or a target that you may go after in future. And there is a suggestion that if some areas are known not to pay, then they may well be avoided. It will be that calculation that Martin describes where as they go down the list and they wonder which ones are they most likely to generate a profit from. They can just scratch off certain ones because they're like, well, they never pay, right? So ideally that would be the case and that's certainly something that we bear in mind. One of the really interesting things I thought in the report that we've recently published was about just how commercial organizations these organizations are, the fact they've got customer service, call help lines and things like that. Can you say a bit more about the model they use and how they how they engage with victims? Yes. So the whole service as professional as they can be even holidays. It largely depends on the organization. So the ransomware as a service groups tend to be a little less like that. So there's two real models for running ransomware these days. There is a third that we talk about in the paper, but it's not used very commonly anymore. The two main models I I caricature is being kind of the air bond model versus the car sales model. So ransomware as a service is kind of the air bond model. You are basically buying into a franchise while you rock up to someone's door and you sell them a product or in this case, you give them ransomware. Brand that they see as air bond in reality, you are a franchise, you are self employed. And those guys don't necessarily get holiday pickers. All they are doing is they're entirely self deployed. It's up to them. And in that model, what you typically get is the affiliate will take up to 90% so in occasionally it's been as high as 95% of the profit because they're doing all of the work in that. And the ransomware group, the lock bit of the world gets the smaller cut. If you go back to when they started as a trend, it used to be a case of the affiliate got maybe 60% now it's down to as much as the affiliate gets 90% because it is such a competitive environment. The car sales model is kind of the more the bigger groups that are more internal, they recruit stuff, they train the stuff, they provide them with the, they provide them with the access as they provide with the tools, they provide them with the playbooks. And they are often much more business like they will operate out of offices, they will they'll have holiday here, they'll have sick here, they'll have a salary and they are encouraged to do better by getting a commission of those that pay up. Some of them can be very, very wolf of Wall Street almost of their expected to do 14 odd days in the in the office, but in exchange they are given perks such as drugs and alcohol and other illicit goods that you wouldn't normally get in a normal work environment. I was going to say so not that wolf of Wall Street or maybe it is. So Ellen, you mentioned that the targeting wasn't sector by sector specific, but are there any sectors or types of organisations that we see this happening to more than others? So Martin's described the process whereby the the accesses or the open doorways as I think of them are assessed to see which ones are going to bother going through. I think the decision as to whether or not one will be more profitable than the other. I think how far sector plays into that is probably minuscule right. I don't think sector is a big part of that decision making process. I think it'd be more about size, profit margins, how easy it was to get in the first place, how widespread the encryption event could be. It's all of those kinds of calculations that will really be the way in which they determine who to pursue and who not to pursue. I don't know, I imagine one of the first questions that victim organisations when they come to you ask is should we pay a ransom? What's your advice on that? That's a really difficult question. The really high concern amongst the UK government is that payment of ransom effectively fuels more ransomware. So clearly the more effective the business model is and as you've been hearing from Martin, it's a really lucrative and effective business model. The more it will grow, the more it will bloom and blossom and the more these groups will continue to perpetrate ransomware attacks. It's a genuinely strategic problem for the UK and globally speaking that this continues in the way that it does. However, from the perspective of an individual organisation that has just been hit by a ransomware attack, it's difficult for them to take account of the broader strategic problem. From their immediate point of view, it's about the viability of their organisation. Can they keep afloat? What is the right thing to do from the point of view of their organisation? And although me and my colleagues and law enforcement teams will of course reinforce the UK's position that we really do not support the payment of ransom, that will sit alongside other considerations around what decisions need to be taken into the organisation's best interests. So if the worst happens, the most important point is to have implemented all the best practice around preparing for these kinds of scenarios. So this is about ensuring that you've got your backups offline, that you know that you have tested and developed an instant response plan, and that you know and that you're ready for when this kind of event happens. Then if you are hit by ransomware, ideally you should implement your instant response process. Often this will require some sort of technical support, there are companies that can help you do this. The most important part of that is the investigation. It's finding out how it happened in the first place, how they got into your networks, and ensuring that they are fairly secured and this cannot happen to you again. So that's a really important part of responding to the incident, and ensuring that you are more resilient going forward and your defence is a hardened. So there's lots of services that you can draw upon to help you prepare for when the worst happens. A really good one that I would point to you is exercise in a box, which precisely helps you step through as an organisation. Exactly the steps that you need to take when you're confronted with the possibility or with the reality of a cyber attack having been conducted against your system. Having thought through what it would mean, having policies in place that you know how they actually work, because policies in sort of theory and then policies in practice, make sure you know how they work, make sure that they can be implemented fully. And make sure you've taken all of those defensive steps that the NCC helps you to work out to make sure that you're ready should the worst happen. We also have the early warning service, which is free for anyone in the UK to sign up to if they have a static IP or their own domain name. And we receive a combination of our own data and from industry partners tip off to this IP or this domain, maybe a victim of XYZ malware. Some of that will lead to ransomware, people who sign up to that service will get an early tip to let them more potentially before it becomes such a big problem as you've already been encrypted in your businesses in Ashes. In fact, early warning now definitely we can point to actual instances where we have prevented ransomware attacks just as you say where precursor indicators of malware have been notified before the attack is able to take place and people are able to act on it thanks to the warnings that they have received. So the NCC also certifies certain organizations to show that they've taken steps to keep themselves cyber secure. So we have cyber essentials, cyber essentials is five basic controls that if applied will give you a reasonably good cyber hygiene, you won't be protected from everything will protect you from a lot. And in ransomware case, it will reduce the possibility of a attack by quite a significant margin. So some of those controls include things like having a firewall which limits access which it not just limits your doesn't just limit your external threat surface of ways in the actors potentially have it also prevents them from moving all the way around your network and taking out the entire network at once if they were to get in. So it also includes things like user access control and making sure you have things like multifactor authentication a huge portion of how ransomware actors get in is the whole part of the ecosystem that drives from stolen credentials. Credential Steelers were very, very cheap they're easy to deploy the lost of law level criminals, the ones that aren't very technical savvy at all can get away with running these unsullying the credentials onto others whether that's through a marketplace or through initial access broker. But there is a bit of a disconnect between the people gathering it and running that piece of malware and the people buying it who are just buying the credentials. So even though there are ways around multifactor authentication such as using the malware to steal the authentication token, it doesn't necessarily work very well in these sorts of models. So there are other services criminals can use to work around the multifactor authentication problem such as push notification push overload basically they keep sending a request at one o'clock in the morning and once you've received a hundred of these notifications at one o'clock in the morning almost any administrator is going to roll over hit accept just so they can get back to sleep. And it's a perfectly acceptable understandable human response to that but then much, much more noticeable when you have to go to the laws extends to avoid the security controls similarly includes things like running antivirus criminals have aware have ways around testing to make sure they avoid antivirus. However, antivirus vendors are really good really quick at recovering a lot of that so the ground that is lost to act a testing that their product doesn't set off antivirus it's quite a short window sometimes sometimes as early as hours sometimes sometimes a couple of days oftentimes antivirus these days use behaviors that mean it's caught anywhere it just didn't show been testing so having products like that really really help. All of all so covered within the cyber essentials accreditation great and we know the stats from this year show that organizations that properly implement cyber essentials are 80% less likely to make an insurance claim for ransomware. Eleanor what happens when you're hit with ransomware what what do we encourage organizations to do. So I appreciate that for organizations that have just been hit by ransomware can be really hard to find the right sources of support and does it in CSE website is obviously a great place to start if your systems have been taken down it might be quite hard to get to it. And one of the main ports of core that you should turn towards is a cyber instant response company and we recognize there are lots of different companies out there all offering different types of services and if you if you are new to this world which potentially you are there's no reason why you would why you would have come to it before. It might be very difficult to identify the right source of support. This is where the NCSE's CIR level one and level two accreditation scheme comes in and this is where we have accredited cyber instant response companies who are available to support you through the cyber attack that you have experienced. The level one scheme has some of the nationally recognized company so are able to help out with APT level attacks but also really significant ransomware attacks as well they can guide you through the response that you need to do for your organization. But additionally we have recently launched the cyber instant response scheme level two and this is for organizations across all the UK nationally who stand ready to provide accredited support to organizations who may have fallen victim such as to ransomware attacks and who are available to help you through that response process. So I would strongly encourage organizations to to look out for these accredited schemes in order to know that you are actually turning to the best possible source of support and not to the more ad hoc options that might be out there. Having the right support available is really important to make sure you get the right response and that's partially why these certifications exist. If you get someone who can help you clean up and get your network back running again will meet the immediate business needs but if they haven't done the proper investigation to work out how to get in the first place you're leaving the door open for it to happen again. We've seen numbers of reports of people saying people who pay the ransom are more likely to get hit again and that's often misconstrued is criminals keeping lists of people who have been ransomed and are more likely to pay up. That's not really true. Criminals don't really work like they don't have this big shopping menu of companies that are known to pay up. They just don't work like that. The reality is what's probably happened is the company has been hit cleaned up got themselves working but they haven't had that support to close off the halls in the first place and someone's come back in either through the same hall or through another hall that you also didn't know your heart. So what's your kind of having worked in this sector for several several years, both of you? What's your kind of reflection on the type of criminals that we're dealing with? I would say they are a combination of ruthless and brazen. So some of them are in it. Most of them are in it for the money. That's all they really care about. They care about themselves. We have seen in the past where law enforcement have done sanctions and indictments and put up videos from their social media of them doing donuts in their Lamborghini in the middle of Moscow. They care about their lifestyle and the money that's needed to fund it. But the decisions they make to get there can be really brutal and ruthless. So we hit a point it was in the middle of Covid. I won't say it was the summer of 2020 where there was one particular group who were desperate for money and they really want to make more money. So they had a bit of discussion about which sectors and areas do they have access to already that they could monetize the fastest and the response was healthcare in the US. It's got lots of money. We have plenty of access and it appears up quickly and they went down that decision of let's target that better healthcare. The FBI put out a really good advisory at the time and thankfully mitigate a lot of the potential impact off the back of that. But the fact that they were willing to do that for the pure purposes of making money. They didn't care about the chaos or the potential to life that that would cause. While criminals have moved away from that to some degree and they're trying to show more to come of morals and say we won't target healthcare. They don't necessarily know or care about the damage that they could do. So we regularly see them hitting companies that provide software or services. And you don't necessarily know criminals don't know who that company is providing software and services to. There was an instant area this year with Southwest ambulance services being affected not because they targeted the ambulance service. They targeted a supplier and that supplier happened to supply to the ambulance service and I had a big impact on the ambulance service. There's nowhere criminals can get away from that and they draw the line up while we didn't hit the hospitals. So we're all good guys not hitting healthcare and it's just not true. Their morals are surface deep at best and they really are quite ruthless all they care about is making that money such an awful criminal approach and I know anything else to say. I think my sort of final thought would just be not to underestimate what a dreadful experience it can be to come in and to have that screen of you know your systems are encrypted right now. You know that big red screen of death they got during want to cry or others and just to you know everything to be down everything to be inaccessible. Your phone book to be inaccessible because it's a little bit encrypted your business continuity plan potentially or that was online or that's being encrypted to you and to find yourselves resorting to pen and paper unable to pay staff. Unable to conduct whatever day to day business you need to conduct it potentially having you know really significant impacts on on services such as the ambulance services might describe. The real kind of massive impact of what that can feel like as you go through it is truly I think you know from all the different organizations who've supported over the years. The scars they bear from going through it are truly you know significant. And where you've got the overhanging threat as well of data publication and the possibility that the sensitive data that you that you hold. Particularly if you hold data relating I don't to vulnerable people or personally or your staffs data and that risks turning up at some point on the dark web that's a whole additional layer of sort of. Of pressure and stress and you know leaves organizations in a really horrific situation so I would you know I would really strongly encourage listeners to take this very seriously and to look out for options to prepare for this should the worst happen. So when an organizations hit do they have any responsibility to the people whose data they hold in the event of any ransomware attack. You can be confident that your data has been accessed all ransomware attacks count as a data breach in terms of data being accessed. You may not have concrete evidence of exfiltration which you may attempt to take some comfort that potentially data has not been taken. But invariably we do find in all attacks access has certainly been achieved in order to deploy the encryption event and usually laterally some form of exfiltration becomes apparent as well. In all cases these are actually reportable as data breaches to the information commissioners office particularly or exclusively where personally identifiable information is involved. So as long as there's some sort of PII which is usually the case because if nothing else is your staff data or it's your clients data or it's even just names and addresses or even email addresses I think counts. So you know most of the time some sort of requirement will be in place by virtue of the data having been accessed through a ransomware attack this is a reportable incident to the ICO and the ICO has a breach reporting form where you can report and let them know that it has happened. If you wish additionally to seek additional help and advice and support that's where the NCC comes in and we can help those organizations to get back on their beat in the ways that we have described. Great thanks both of you for your time and for those of you at home listening and we really hope you've enjoyed the first NCC podcast and come back for more. If you want to know more about what we've covered in the session whether it was about cyber essentials the cyber incident response companies or some of our advice and guidance please go to NCC. www.ncsc.gov.uk
Podcast Summary
Key Points:
Ransomware is malicious software that encrypts data, demanding payment for decryption, often combined with data theft for extortion.
The impact varies
Ransomware has evolved from targeting single devices to "big game hunting" of large organizations, fueled by cryptocurrency and professional criminal ecosystems.
Trends show a shift toward data extortion without encryption, as criminals adapt to improved victim backups and seek higher profits through reputational damage.
High-profile attacks like WannaCry and Colonial Pipeline demonstrated widespread disruption, but many groups now avoid headlines to maintain ongoing, low-profile operations.
The ransomware ecosystem is complex, involving affiliates, initial access brokers, and ransomware-as-a-service models, making attribution difficult and attacks opportunistic.
Summary:
This podcast from the National Cybersecurity Centre discusses ransomware as a major cyber threat, explaining it as software that encrypts data to extort payments, often alongside data theft. The impact on victims varies: less cyber-mature organizations may face existential crises, while larger ones with backups can recover but remain at risk from data leaks. Ransomware has evolved from targeting individual devices to "big game hunting" of large entities, driven by cryptocurrency and professional criminal networks.
Recent trends show a move toward data extortion without encryption, as criminals adapt to improved victim defenses. High-profile incidents like WannaCry and Colonial Pipeline highlighted severe disruptions, but many groups now operate discreetly to avoid law enforcement attention. The ecosystem is complex, involving affiliates, brokers, and ransomware-as-a-service models, making attacks opportunistic and attribution challenging.
The discussion emphasizes ransomware as an adaptive criminal business, continuously evolving to maximize profits.
FAQs
Ransomware is malicious software that encrypts a victim's data, demanding payment for decryption. Criminals often combine this with stealing data to extort money, making it part of a broader cybercrime ecosystem.
The impact varies by organization; less cyber-mature ones may face existential threats, while larger ones with backups can recover. Victims often feel devastated, especially if personal or critical business data is lost, leading to pressure to pay ransoms.
Ransomware started by encrypting single devices but evolved to target entire networks for bigger payouts, aided by cryptocurrency. Recent trends include 'big game hunting' against large organizations and data extortion without encryption.
Data extortion involves stealing sensitive data and threatening to leak it unless a ransom is paid. This method is becoming more common as criminals recognize its effectiveness, especially when victims have backups to recover from encryption.
Prominent groups include LockBit and ALPHV, often linked to Russian-speaking communities. However, attribution is difficult due to affiliate models and fluid movement between groups in the ransomware-as-a-service ecosystem.
RaaS is a model where developers sell ransomware tools and infrastructure to affiliates, who then carry out attacks. This creates a complex ecosystem with multiple parties involved, making attacks opportunistic rather than highly targeted.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.