[ad_1]
Ransomware has made headlines in recent weeks after criminal hacking networks, for the time being ties to Russia, launched attacks on the major US meat packing plant JBS and the country’s largest fuel pipeline.
Joe Biden and his administration struggle to face the growing threat, press Vladimir Putin in a much-anticipated meeting on Wednesday to take action against the rise of ransomware attacks. Biden said he gave Putin a list of 16 areas, mostly in critical infrastructure – that are off limits to cyber-attacks.
Ransomware has long been a cybersecurity threat to businesses and infrastructure, but experts say the problem has exploded in recent years. Last year was especially outrageous, with ransomware victims in the US paying out almost $350m, according to the global security group the Institute for Security and Technology an increase of 311% from 2019.
FBI Director Christopher Wray highlighted this surprising figure during a congressional hearing. Ransomware alone, the total volume of money paid for ransomware has tripled in the past year. wray said:. We think the cyber threat is growing almost exponentially.
Experts attribute the rise to a number of factors, but they say one of the most critical has been the shift to remote working during the pandemic.
Working from home means you’re no longer behind the castle walls, says John Hammond, a cybersecurity researcher at security firm Huntress. You work with your own devices, away from the secure perimeter of corporate networks.
Criminals have found an increasingly lucrative path in ransomware attacks, where a hacker breaks into a corporate or government network and seizes data or systems and demands payment for their return. Employees on computers outside the security of office networks are more at risk. Corporate networks generally only allow trusted devices to connect, reducing the risk of third-party actors or malware. They also often have stronger protections than the average consumer Wi-Fi network.
The move to work from home has contributed greatly to the increase in successful ransomware attacks, said Israel Barak, the chief information security officer at security firm Cybereason. There are many more open doors to access networks now that employees are working remotely.
One of the most sweeping ransomware hacks in recent months, on the Colonial Pipeline that shuts down systems that supply 45% of the fuel in the eastern United States, is now being blamed on a virtual private network breach, which is often used by remote workers to connect to a corporate system.
VPNs are the safest way for employees to connect to a corporate network from home, but they can pose their own risks if they are outdated or do not use multi-factor authentication.
A spokesperson for Colonial Pipeline said the compromised VPN was an older model and not the VPN that employees were actively using to access the Colonial network remotely.
But experts say that any time employees work offsite with their own networks, there are risks involved. There are a number from documented to attack on companies that have been running through VPN access since the start of the pandemic, including about Japanese game developer Capcom and a European industrial company.

In June 2020, the judiciary identified a Russian ransomware group which purposefully targeted people working from home during the pandemic to access corporate and government networks.
Corporate and government offices have taken a number of measures to keep bad actors out, said Joseph Carson, the chief security scientist at the cloud security firm. thycotic. That includes secure Internet routers with unique passwords, firewalls that monitor incoming traffic and keep threats out, and corporate devices with added security.
Most of those safeguards are virtually useless once the devices are moved to the public internet, he said.
While it wasn’t a ransomware attack, the Twitter hack in July 2020 was more directly attributed to remote work. Hackers called several Twitter employees who claimed to be employees of the IT department and offered to help connect through the company’s virtual private network used by employees who work from home. The 17-year-old hacker behind that robbery $117,000 raised in bitcoin from the attack.
Security breaches in general have also increased in the past year. The vast majority of IT teams 82% experienced an increase in cyber attacks in 2020, according to a study from security company Sophos.
The number of attacks is increasing not only because of remote working, but also as criminals become more organized and ransomware attacks are easier to carry out, said Rahul Telang, a professor of information systems at Carnegie Mellon. The rise of cryptocurrency, which is easier to send online and less traceable than traditional money orders, has facilitated the trend.
Bitcoin has made it much easier for these people to extract money, he said. We have the combination of information security that is getting significantly worse with the rise of cryptocurrency.
Meanwhile, the House Homeland Security Committee recently introduced several bills aimed at improving cybersecurity in the wake of the colonial pipeline hack.
The Biden administration is also working to improve cybersecurity responses. It issued a letter to business leaders and business leaders about what the private sector should do to protect against ransomware threats, including practices such as multi-factor authentication, encryption, and skilled security teams. Companies were also advised to regularly back up data and test systems.
The threats are serious and growing, Anne Neuberger, a cybersecurity adviser at the National Security Council, said in the letter. We urge you to take these critical steps to protect your organizations and the American public.
[ad_2]
picture credit