Europol marked the sixth anniversary of No More Ransom, the European Union law enforcement agency’s anti-ransomware initiative, by releasing their figures on how many organizations they have helped stop ransomware.
In another flip-the-script story, researchers with Censys, a firm that indexes devices connected to the internet, said last week they’ve found what appears to be a ransomware command and control network capable of launching attacks, including one host located in the U.S. Further analysis that included historical data tied to those hosts led the researchers to additional hosts and connections to the MedusaLocker ransomware variant, which was the subject of a July 1 alert from the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency.
That doesn’t mean they aren’t still trying new tactics — Cozy Bear, the Russian state-sponsored hacking group, shared malware-infected files with foreign embassies in Brazil and Portugal in May using Dropbox or Google Drive storage, researchers at Palo Alto Networks said.
While tactics matter, it’s the data from Europol that I wanted to focus on. That’s a pretty sizeable number… and somehow, just a dent in the entire market. More importantly, it proves that there is a methodology for not paying. It’s intentional, however – and often left out of the anti-ransomware discussion. Sure, you talk all the time about preventing the occurrence… but how often do you speak with customers about preventing the payment? And do the legwork of that disaster planning?
I suspect not often enough.

