July 30, 2014 By Derek Brink 3 min read

Ransom, which refers to some kind of payment that is demanded in exchange for the release of someone or something that has been taken, is a simple yet effective ploy that has been used by criminals for thousands of years.

For example, on his way home from the Third Crusade in 1192, King Richard the Lionheart was captured and held for ransom by Duke Leopold of Austria. The amount demanded was so large that it took over a year for England to raise it, giving root to the now-familiar idiom “a king’s ransom.” In 1932, the 20-month-old son of famous aviator Charles Lindbergh was kidnapped and held for ransom in one of the most high-profile cases in the history of the FBI.

The dynamics of ransom are not difficult to understand: I take something dear to you, and you pay me to give it back.

Ancient Approaches, Modern Applications

Today, criminals are applying these ancient approaches to modern technologies. Ransomware, one of the fastest-growing areas of cyber crime, refers to malicious software that is specifically designed to take control of a computer system or its data and hold it hostage so the attackers can demand payment from their victims. Although ransomware initially targeted PCs, it is now migrating to mobile platforms as well. Some recent public disclosures involving demands for ransom include:

  • The town of Greenland, New Hampshire, which lost eight years’ worth of data when it fell victim to a ransomware known as CryptoLocker.
  • Brokerage and investment advisory firm Benjamin F. Edwards, which exposed data related to some 430 New Hampshire residents from a ransomware called CryptoWall.
  • Domino’s Pizza in France and Belgium, where the personal information (including favorite pizza toppings) of about 650,000 customers was compromised. The hackers responsible demanded a ransom of 30,000 euros in exchange for not disclosing the information publicly.

Cyber Extortion: Related to Ransomware

Note that, technically, this last example is not ransomware (a type of malicious software), but rather a demand for ransom for compromised customer data. It seems that cyber criminals continue to move faster than the tech industry’s ability to create new jargon to describe it. In practical terms, it shows that we should also be aware of another ancient and effective exploit: extortion, which is the crime of taking money (or something else of value) from another party by use of threat or force. The dynamics of extortion are not difficult to understand, either: I cause (or threaten to cause) you harm, and you pay me to stop.

Unfortunately, there are also ample public disclosures related to cyber extortion:

  • News aggregator Feedly was the victim of a distributed denial-of-service (DDoS) attack in which the attackers demanded payment to make it stop.
  • Move Inc., an online real estate services provider, battled DDoS attacks that disrupted its website operations. It refused to respond to a demand for payment.
  • Evernote also battled a DDoS attack that disrupted operations, although it is unclear in this case whether the attackers also demanded payment.

Although these particular examples of cyber extortion are against larger-scale targets, it’s worth noting that the tactic can also be directed at smaller, personal targets — no one is really immune.

What You Need to Do

To protect against ransomware, now is the perfect time for organizations to remind themselves of some basic best practices:

  • Back up your data regularly (from an end user’s perspective, this is the easiest way out).
  • Ensure that your endpoints and servers are patched and up-to-date.
  • Deploy appropriate endpoint protection.
  • Regularly make end users aware of safe email and Web-browsing practices, and periodically test their behavior.

To protect against cyber extortion, it is essential for all organizations to understand the importance of developing a strong incident response capability to complement their traditional prevention-oriented security strategies. Prevention cannot be successful 100 percent of the time, so it makes sense to be capable of detecting and responding to incidents more quickly when they do occur. Note that incident response is not an action that an organization needs at a specific point in time; rather, it is a capability that an organization develops and uses when needed.

More from

Zero-day exploits underscore rising risks for internet-facing interfaces

3 min read - Recent reports confirm the active exploitation of a critical zero-day vulnerability targeting Palo Alto Networks’ Next-Generation Firewalls (NGFW) management interfaces. While Palo Alto’s swift advisories and mitigation guidance offer a starting point for remediation, the broader implications of such vulnerabilities demand attention from organizations globally.The surge in attacks on internet-facing management interfaces highlights an evolving threat landscape and necessitates rethinking how organizations secure critical assets.Who is exploiting the NGFW zero-day?As of now, little is known about the actors behind the…

How TikTok is reframing cybersecurity efforts

4 min read - You might think of TikTok as the place to go to find out new recipes and laugh at silly videos. And as a cybersecurity professional, TikTok’s potential data security issues are also likely to come to mind. However, in recent years, TikTok has worked to promote cybersecurity through its channels and programs. To highlight its efforts, TikTok celebrated Cybersecurity Month by promoting its cybersecurity focus and sharing cybersecurity TikTok creators.Global Bug Bounty program with HackerOneDuring Cybersecurity Month, the social media…

Roundup: The top ransomware stories of 2024

2 min read - The year 2024 saw a marked increase in the competence, aggression and unpredictability of ransomware attackers. Nearly all the key numbers are up — more ransomware gangs, bigger targets and higher payouts. Malicious ransomware groups also focus on critical infrastructure and supply chains, raising the stakes for victims and increasing the motivation to cooperate.Here are the biggest ransomware stories of 2024.Ransomware payments reach record highRansomware payments surged to record highs in 2024. In the first half of the year, victims…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today