# CBS News recommends paying criminals

**URL:** <https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572>\
**Category:** The BBQ Pit\
**Created:** [May 6, 2019, 4:30pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572 "2019-05-06T16:30:53Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [May 6, 2019, 4:30pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/1 "2019-05-06T16:30:53Z")

</div>

Scott Pelley says the best option to ransomware threats (sometimes) is to [pay what the criminals demand.](https://www.cbsnews.com/news/ransomware-how-cybercriminals-hold-data-hostage-and-why-the-best-solution-is-often-paying-a-ransom-60-minutes-2019-05-05/)

Pelley may be unaware that paying the untraceable ransom is no guarantee that your data can be restored (there is no honor among thieves.) **You’re just as likely to pay and get nothing in return**. Try explaining _that_ decision to your board.

Today’s news article is [here](https://www.cbsnews.com/news/ransomware-prevent-your-computer-from-being-infected-60-minutes-2019-05-05/) (note some bad links on that page due to stupid copywriters who don’t check their work).

I must be in the wrong business. Nobody pays me $40,000 for sending an email threat. Maybe the dark side is where it’s at.

---

<div class="post-metadata">

**Author:** ![Joey\_P](https://avatars.discourse-cdn.com/v4/letter/j/919ad9/32.png) [@Joey\_P](https://boards.straightdope.com/u/Joey_P)\
**Post date:** [May 6, 2019, 4:41pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/2 "2019-05-06T16:41:45Z")

</div>

I recall a hospital paying off the attackers. They lost access to their network. IT staff and outside cyber security experts couldn’t crack it. They chose to pay and I believe their system was restored.

I assume that everything was backed up, but I also assume that restoring a system that large would leave them closed for at least a few days as well as having all their data since the last backup gone.

ETA, [here’s](https://www.forbes.com/sites/thomasbrewster/2016/02/18/ransomware-hollywood-payment-locky-menace/#69b250a6408f) the (or at least one of the) places it happened to. I supposed for $17,000 it’s probably worth a shot for a business that large.

---

<div class="post-metadata">

**Author:** ![Slash1972](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slash1972/32/6461_2.png) [@Slash1972](https://boards.straightdope.com/u/Slash1972)\
**Post date:** [May 6, 2019, 4:44pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/3 "2019-05-06T16:44:07Z")

</div>

> [@Musicat](#):
>
> I must be in the wrong business. Nobody pays me $40,000 for sending an email threat. Maybe the dark side is where it’s at.

It’s not usually just a threat. Their data is actually encrypted. It becomes a choice between paying hundreds of thousands to restore, or paying a small amount to the hackers.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [May 6, 2019, 4:46pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/4 "2019-05-06T16:46:13Z")

</div>

Do you trust criminals to restore your data? The same ones who encrypted it?

---

<div class="post-metadata">

**Author:** ![Slash1972](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/slash1972/32/6461_2.png) [@Slash1972](https://boards.straightdope.com/u/Slash1972)\
**Post date:** [May 6, 2019, 4:48pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/5 "2019-05-06T16:48:43Z")

</div>

> [@Musicat](#):
>
> Do you trust criminals to restore your data? The same ones who encrypted it?

I haven’t seen a lot of stories where the DIDN’T restore it. Besides, if they don’t, the business is only out a small fraction of what they have to pay to restore it on their own. That’s why a lot of businesses are taking that route.

---

<div class="post-metadata">

**Author:** ![Czarcasm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/czarcasm/32/4050_2.png) [@Czarcasm](https://boards.straightdope.com/u/Czarcasm)\
**Post date:** [May 6, 2019, 4:54pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/6 "2019-05-06T16:54:31Z")

</div>

> [@Musicat](#):
>
> Do you trust criminals to restore your data? The same ones who encrypted it?

If they _don’t_ restore it, where is the incentive to pay the next time it happens to someone else?

---

<div class="post-metadata">

**Author:** ![XT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/xt/32/456_2.png) [@XT](https://boards.straightdope.com/u/XT)\
**Post date:** [May 6, 2019, 4:54pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/7 "2019-05-06T16:54:39Z")

</div>

> [@Musicat](#):
>
> Do you trust criminals to restore your data? The same ones who encrypted it?

Well, I’d ‘trust’ them to give the decryption key, yes. Basically, if they didn’t then it would rapidly break their business model, since no one would even bother trying to pay the ransom.

Hopefully the folks who fell for this have taken future steps to prevent it from happening again. A lot of companies, even big companies, never seemed to grasp the level of the threat and have paid the price for that. Sadly, many places still haven’t learned their lessons and still haven’t taken even minimal precautions to ensure this doesn’t happen to them.

---

<div class="post-metadata">

**Author:** ![Jasmine](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jasmine/32/2964_2.png) [@Jasmine](https://boards.straightdope.com/u/Jasmine)\
**Post date:** [May 6, 2019, 4:56pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/8 "2019-05-06T16:56:26Z")

</div>

The “best thing” is to have a properly constructed network that has protected backups that are refreshed daily so that you can tell ransom hackers to fuck off.

Since I’ve been here, we have been successfully attacked once by ransom software. We just purged the server and restored it from protected off-site backups. Problem solved before school the next day.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [May 6, 2019, 4:57pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/9 "2019-05-06T16:57:17Z")

</div>

> [@Czarcasm](#):
>
> If they _don’t_ restore it, where is the incentive to pay the next time it happens to someone else?

Stupidity?

> [@XT](#):
>
> Well, I’d ‘trust’ them to give the decryption key, yes. Basically, if they didn’t then it would rapidly break their business model, since no one would even bother trying to pay the ransom.

Ahhh…the crooks that are in it for the long haul. They have prepared a long-term business model, and presented it to the investment community, showing a favorable rate of return. Deviating from that would negatively impact their stock price and might result in are-shuffling of the board. Yep, that’s how these bastards work. Rational as can be.

---

<div class="post-metadata">

**Author:** ![excavating\_for\_a\_mind](https://avatars.discourse-cdn.com/v4/letter/e/e8c25b/32.png) [@excavating\_for\_a\_mind](https://boards.straightdope.com/u/excavating_for_a_mind)\
**Post date:** [May 6, 2019, 5:01pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/10 "2019-05-06T17:01:30Z")

</div>

> [@Slash1972](#):
>
> I haven’t seen a lot of stories where the DIDN’T restore it. Besides, if they don’t, the business is only out a small fraction of what they have to pay to restore it on their own. That’s why a lot of businesses are taking that route.

I think the OP is making a point that CBS News really shouldn’t be telling people to support crime. I have to admit, I did not pay close attention to the 60 Minutes report, but IMHO, if they felt the need to air the story, they should have pointed out that paying a ransom in untraceable bitcoin is always a sketchy thing and should be avoided.

Again, IMO, instead of telling people that paying the ransom worked, they could have recommended not to pay the ransom and given some pointers as to how to avoid being held to such an attach (making backups, virus detection, multi-network systems, etc…). I’m with the OP on this one, CBS was irresponsible.

---

<div class="post-metadata">

**Author:** ![XT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/xt/32/456_2.png) [@XT](https://boards.straightdope.com/u/XT)\
**Post date:** [May 6, 2019, 5:06pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/11 "2019-05-06T17:06:00Z")

</div>

> [@Musicat](#):
>
> Stupidity?
> 
> Ahhh…the crooks that are in it for the long haul. They have prepared a long-term business model, and presented it to the investment community, showing a favorable rate of return. Deviating from that would negatively impact their stock price and might result in are-shuffling of the board. Yep, that’s how these bastards work. Rational as can be.

It’s rationality based on keeping that going. Basically, the same rationale that loan sharks use. If you pay them back and they STILL bust your knee caps, well, they probably aren’t going to be able to get anyone else to borrow money in the future. Or drug dealers…if they adulterate their drugs to the point it kills the customers or doesn’t actually get them high then they probably won’t have repeat business. Once the cyber crooks get a reputation for a bait and switch and not actually providing the keys to de-crypt the data they basically aren’t going to get the next sucker to pay up. And really, giving the key is basically not a big deal, so I don’t see any upside in the cyber crook to NOT do it (unless they lost it or some other stupid shit). Seriously, you are talking about cut and pasting a 15 or 20 character code into a text or email. No additional exposure for you, no real risk (not greater than doing this in the first place), so why not?

---

<div class="post-metadata">

**Author:** ![Czarcasm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/czarcasm/32/4050_2.png) [@Czarcasm](https://boards.straightdope.com/u/Czarcasm)\
**Post date:** [May 6, 2019, 5:07pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/12 "2019-05-06T17:07:11Z")

</div>

> [@Musicat](#):
>
> Stupidity?
> 
> Ahhh…the crooks that are in it for the long haul. They have prepared a long-term business model, and presented it to the investment community, showing a favorable rate of return. Deviating from that would negatively impact their stock price and might result in are-shuffling of the board. Yep, that’s how these bastards work. Rational as can be.

Actually, yes-that does seem to be the way they are working. They aren’t asking for incredibly large amounts of money that can break the bank, and they are(for the most part) providing the keys needed.

---

<div class="post-metadata">

**Author:** ![Kobal2](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kobal2/32/20_2.png) [@Kobal2](https://boards.straightdope.com/u/Kobal2)\
**Post date:** [May 6, 2019, 5:17pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/13 "2019-05-06T17:17:52Z")

</div>

> [@Musicat](#):
>
> Do you trust criminals to restore your data? The same ones who encrypted it?

What’s the upside of not restoring it ?  
I suppose there could be a scenario where it goes “Pay us… ONE MILLION DOLLARS !” “Errr, that’s chump change, OK, no problem, done” “Wait, wait, wait, then, pay us… TEN BILLION DOLLARS !” but the real world doesn’t really operate on Austin Powers rules.  
OTOH there is a clear upside for L33tH4ckCr3w to restore your shit upon payment : they can then go and hijack the shit of the next guy over. And the next guy over will be more likely to pay up, because they know when the first guy paid up blablabla. Like, I’m aware you shouldn’t pay the danegeld, but the thing is : the Dane only had a small handful of possible chumps to threaten. L33tH4ckCr3w has a target rich environment because everybody clicks “remind me later” on their software security update. Even IT guys.  
Get rid of the Dane. He \*might \*be back… in 20 years. Which hopefully gives you some time and motivation to invest in ITsec in the meantime. File it under “the cost of doing business while being an idiot on the internet”.

[QUOTE=Musicat]  
Ahhh…the crooks that are in it for the long haul. They have prepared a long-term business model, and presented it to the investment community, showing a favorable rate of return. Deviating from that would negatively impact their stock price and might result in are-shuffling of the board. Yep, that’s how these bastards work. Rational as can be.  
[/QUOTE]

… yes ? I mean, you have to be at least a little smart to do cybercrime. Not _very_ smart, but at least a little. Why do you assume tech ransom crews are irrational, terminally short-sighted morons ? I mean, even Attila the Hun (reasonable, famously measured and moderate guy that he was) knew there was absolute value in not breaking his mass-murdering racketeer’s word.

If even _I_ can see the column A, column B assessment, why wouldn’t they ? I’m too dumb to do any kind of crypto, FTR. Anything more complicated than a straight alphabet cipher and I’m out.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [May 6, 2019, 5:21pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/14 "2019-05-06T17:21:50Z")

</div>

Here’s why you might not want to pay the ransom.

> [@](#):
>
> **You Are Marked as a Sucker (Repeatable Target)**
> 
> One concern with paying off criminals is that you will be known to pay, and once money is exchanged, malicious actors may continue to target your organization. This could potentially make you and other payees a frequent target in efforts to infect a machine. An article in SC Magazine covers a company that found themselves in this position:
> 
> The company, having little other option, chose to pay up: “No-one said it was a bad idea, although there was a level of feeling uncomfortable to ‘giving in’ to the thieves but by that stage we were out of ideas and it seemed to be the only decision we could make.” It took most of the night to complete the decryption, even after which roughly 10 percent of the files were unrecoverable. The saga cost the business three days of work, at least £25,000 pounds and a tenth of their data. Their IT provider was soon replaced, and new security policies and staff training put in. The company was targeted with ransomware several times in the months after “Apparently there was an upsurge in ransomware aimed at us in the months following the attack, we think this is because we were put on a ‘Suckers List’ by the criminals and others were trying to cash in by seeing if we’d fixed our problems.”
> 
> **There Is No Guarantee They Will Give Your Data Back**
> 
> The people that create and distribute ransomware are criminals. By nature, they are performing unethical and illegal activities to profit off other people’s misfortune. With that in mind, if you pay the ransom, how do you know if they will actually send you the code to unlock your data? Bleeping Computer published an article that gave an interested statistic:
> 
> The survey, carried out by research and marketing firm CyberEdge Group, reveals that paying the ransom demand, even if for desperate reasons, does not guarantee that victims will regain access to their files.
> 
> […]
> 
> Of the 38.7% who opted to pay the ransom, a little less than half (19.1%) recovered their files using the tools provided by the ransomware authors.
> 
> **You Enable Ransomware Crime To Continue**
> 
> The FBI and others believe that if organizations pay a ransom, it not only encourages current cyber criminals to target additional organizations, it also entices other criminals to get involved in ransomware as they will see it as a lucrative activity. In addition, by paying a ransom, it has been noted that this money could inadvertently be funding other illicit activity.

There’s more, [here.](https://www.riskbasedsecurity.com/2018/10/ransomware-to-pay-or-not-to-pay-that-is-still-a-real-question/)

---

<div class="post-metadata">

**Author:** ![Kobal2](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/kobal2/32/20_2.png) [@Kobal2](https://boards.straightdope.com/u/Kobal2)\
**Post date:** [May 6, 2019, 5:29pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/15 "2019-05-06T17:29:00Z")

</div>

**You Are Marked As A Sucker** :  
Sure. But again, now you know which exploit they used to infiltrate you, so that’s one option they don’t have any more. And you’ve patched up all of your other shit while you were at it, because I’m going to assume you’re not a moron. And Debbie from Accounting has probably been sacked so she won’t click on the dodgy email attachment again, either. So you might be a sucker, but now you’re a difficult to reach sucker. There are a million other suckers out there. Why harass you specifically ? Not to mention, repeating the scam on you makes you all the less likely to pay up - fool me once, you can’t fool me again and that. What’s one lone, isolated upside of doing it again ?

**No Guarantee** : adressed already

**Enable Crime to Continue** : yup. But it’s not your job or responsibility to stop it. You’re a victim, not an enforcement agency. Why should you suffer just so others can prosper ? The FBI can suck it and do its fucking job.

---

<div class="post-metadata">

**Author:** ![pulykamell](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pulykamell/32/3166_2.png) [@pulykamell](https://boards.straightdope.com/u/pulykamell)\
**Post date:** [May 6, 2019, 5:33pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/16 "2019-05-06T17:33:06Z")

</div>

To me, that sounds like a good reason to pay. You have about a 50-50 chance of getting your data back (if you link down, 19.1% paid the ransom and got their data back, and 19.6% paid and didn’t get their data back.) Versus not getting your data back or paying way more money to try to recover, it’s the rational choice, in my opinion. I mean, yes, they’re assholes. Back up your data to avoid this.

---

<div class="post-metadata">

**Author:** ![Musicat](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/musicat/32/20189_2.png) [@Musicat](https://boards.straightdope.com/u/Musicat)\
**Post date:** [May 6, 2019, 5:36pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/17 "2019-05-06T17:36:05Z")

</div>

If you look past the text from the site I quoted above to “Why you should consider paying,” you will find [(positive) reasons to pay the ransom,](https://www.riskbasedsecurity.com/2018/10/ransomware-to-pay-or-not-to-pay-that-is-still-a-real-question/) which I did not quote. That site doesn’t appear to be as biased as I might have suggested – not that I agree with either conclusion.

Personally, although I am not the admin for a large hospital, I would spend all the time and money it might take to restore my data, even if that were more than the ransom amount, just on the principle of the thing.

---

<div class="post-metadata">

**Author:** ![Hermitian](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hermitian/32/470_2.png) [@Hermitian](https://boards.straightdope.com/u/Hermitian)\
**Post date:** [May 6, 2019, 5:43pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/18 "2019-05-06T17:43:27Z")

</div>

If it is a large business and the ransom is (relatively) modest, paying the ransom is a no-brainer.

It is no different than handing a thief your wallet when he has you at gunpoint. Yea, he might shoot you after he gets your wallet, but it is the option with the best likely outcome.

If it does work out, consider it a lesson that your security sucks and needs an upgrade.

If it doesn’t work out…well, the lesson is the same.

---

<div class="post-metadata">

**Author:** ![Hermitian](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hermitian/32/470_2.png) [@Hermitian](https://boards.straightdope.com/u/Hermitian)\
**Post date:** [May 6, 2019, 5:45pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/19 "2019-05-06T17:45:43Z")

</div>

> [@Musicat](#):
>
> Personally, although I am not the admin for a large hospital, I would spend all the time and money it might take to restore my data, even if that were more than the ransom amount, just on the principle of the thing.

Yea, you can take the moral high road. I just hope you have a good lawyer for when someone gets hurt.

---

<div class="post-metadata">

**Author:** ![asahi](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/asahi/32/8693_2.png) [@asahi](https://boards.straightdope.com/u/asahi)\
**Post date:** [May 6, 2019, 5:46pm UTC](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572/20 "2019-05-06T17:46:54Z")

</div>

> [@Musicat](#):
>
> Do you trust criminals to restore your data? The same ones who encrypted it?

Maybe not, but in some cases, your choices aren’t very good. Criminals who take sensitive computer systems hostage are no different than criminals who take humans hostage. They hold something of value that people want returned in good condition. The hijackers want your money, and you want your access back. It’s possible they’re acting in bad faith, but trusting them, even if you don’t want to, them may be your best option. There are worse options.

[Next page](https://boards.straightdope.com/t/cbs-news-recommends-paying-criminals/833572.md?page=2)
