July 30, 2014 By Derek Brink 3 min read

Ransom, which refers to some kind of payment that is demanded in exchange for the release of someone or something that has been taken, is a simple yet effective ploy that has been used by criminals for thousands of years.

For example, on his way home from the Third Crusade in 1192, King Richard the Lionheart was captured and held for ransom by Duke Leopold of Austria. The amount demanded was so large that it took over a year for England to raise it, giving root to the now-familiar idiom “a king’s ransom.” In 1932, the 20-month-old son of famous aviator Charles Lindbergh was kidnapped and held for ransom in one of the most high-profile cases in the history of the FBI.

The dynamics of ransom are not difficult to understand: I take something dear to you, and you pay me to give it back.

Ancient Approaches, Modern Applications

Today, criminals are applying these ancient approaches to modern technologies. Ransomware, one of the fastest-growing areas of cyber crime, refers to malicious software that is specifically designed to take control of a computer system or its data and hold it hostage so the attackers can demand payment from their victims. Although ransomware initially targeted PCs, it is now migrating to mobile platforms as well. Some recent public disclosures involving demands for ransom include:

  • The town of Greenland, New Hampshire, which lost eight years’ worth of data when it fell victim to a ransomware known as CryptoLocker.
  • Brokerage and investment advisory firm Benjamin F. Edwards, which exposed data related to some 430 New Hampshire residents from a ransomware called CryptoWall.
  • Domino’s Pizza in France and Belgium, where the personal information (including favorite pizza toppings) of about 650,000 customers was compromised. The hackers responsible demanded a ransom of 30,000 euros in exchange for not disclosing the information publicly.

Cyber Extortion: Related to Ransomware

Note that, technically, this last example is not ransomware (a type of malicious software), but rather a demand for ransom for compromised customer data. It seems that cyber criminals continue to move faster than the tech industry’s ability to create new jargon to describe it. In practical terms, it shows that we should also be aware of another ancient and effective exploit: extortion, which is the crime of taking money (or something else of value) from another party by use of threat or force. The dynamics of extortion are not difficult to understand, either: I cause (or threaten to cause) you harm, and you pay me to stop.

Unfortunately, there are also ample public disclosures related to cyber extortion:

  • News aggregator Feedly was the victim of a distributed denial-of-service (DDoS) attack in which the attackers demanded payment to make it stop.
  • Move Inc., an online real estate services provider, battled DDoS attacks that disrupted its website operations. It refused to respond to a demand for payment.
  • Evernote also battled a DDoS attack that disrupted operations, although it is unclear in this case whether the attackers also demanded payment.

Although these particular examples of cyber extortion are against larger-scale targets, it’s worth noting that the tactic can also be directed at smaller, personal targets — no one is really immune.

What You Need to Do

To protect against ransomware, now is the perfect time for organizations to remind themselves of some basic best practices:

  • Back up your data regularly (from an end user’s perspective, this is the easiest way out).
  • Ensure that your endpoints and servers are patched and up-to-date.
  • Deploy appropriate endpoint protection.
  • Regularly make end users aware of safe email and Web-browsing practices, and periodically test their behavior.

To protect against cyber extortion, it is essential for all organizations to understand the importance of developing a strong incident response capability to complement their traditional prevention-oriented security strategies. Prevention cannot be successful 100 percent of the time, so it makes sense to be capable of detecting and responding to incidents more quickly when they do occur. Note that incident response is not an action that an organization needs at a specific point in time; rather, it is a capability that an organization develops and uses when needed.

More from

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

How secure are green data centers? Consider these 5 trends

4 min read - As organizations increasingly measure environmental impact towards their sustainability goals, many are focusing on their data centers.KPMG found that the majority of the top 100 companies measure and report on their sustainability efforts. Because data centers consume a large amount of energy, Gartner predicts that by 2027, three in four organizations will have implemented a data center sustainability program, which often includes implementing a green data center.“Responsibilities for sustainability are increasingly being passed down from CIOs to infrastructure and operations…

Are successful deepfake scams more common than we realize?

4 min read - Many times a day worldwide, a boss asks one of their team members to perform a task during a video call. But is the person assigning tasks actually who they say they are? Or is it a deepfake? Instead of blindly following orders, employees must now ask themselves if they are becoming a victims of fraud.Earlier this year, a finance worker found themselves talking on a video meeting with someone who looked and sounded just like their CFO. After the…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today