What is Ransomware?
Ransomware is an attack in which criminals exploit a security weakness to take control of files, locking them and demanding payment to return access. Recent attacks on companies, governments and healthcare organizations are making headlines worldwide. From Colonial Pipeline to JBS (the world’s largest meatpacker), ransomware has disrupted operations, caused shortages and cost businesses millions of dollars.
A successful attack usually starts with a phishing email that targets a person or business and entices them to click on a malicious link. From there, a malware variant is introduced to the system and can quickly spread across devices and systems. Once a device or system is infected, it begins searching for and encrypting valuable files. The attacker then leaves a note for the victim that provides instructions for how to pay them in exchange for a decryption key. Attackers are growing creative, too, often requiring nearly untraceable payments like Apple iTunes gift cards to help them stay anonymous and avoid detection.
While monetary gain still drives most ransomware attacks, the NotPetya and other instances show that attacks can be politically motivated as well. And if they involve healthcare or other public services, the damage extends far beyond financial losses to affect entire communities.
Despite the outsized profits and easy payouts for criminals, few punishments exist that are commensurate to the harm of their crimes. Even the most serious cyber crimes like hacking, which can carry a 20 year prison sentence under USC Title 18 SS 1030, have been prosecuted by agencies that are not able to keep pace with the growth of digital crime.