The Times Australia
The Times World News

.
The Times Real Estate

.

Australia is considering a ban on cyber ransom payments, but it could backfire. Here's another idea

  • Written by Jeffrey Foster, Associate Professor in Cyber Security Studies, Macquarie University
Australia is considering a ban on cyber ransom payments, but it could backfire. Here's another idea

First Optus, now Medibank; in less than two months we’ve experienced two of the largest personal data breaches in Australia’s history. In both cases the hackers attempted, and failed, to extort a ransom in exchange for not releasing personal data.

So far the Optus hackers have released only a small sample of data, and claim to have deleted the rest[1]. On the other hand, the Medibank hackers have released the records of more than one million people – and have threatened to release more data on Friday[2].

Read more: Medibank hackers are now releasing stolen data on the dark web. If you're affected, here's what you need to know[3]

With this looming threat, the Australian government is looking to bolster its cybersecurity defences — including through a taskforce set up to retaliate against[4] the Medibank hackers.

Minister for Cyber Security Clare O'Neil has said the government is also considering making ransom payments to cybercriminals illegal[5]. The idea has picked up steam – but would this cure be worse than the disease?

The response to the Medibank hack

The group behind the latest Medibank hack, currently being called “BlogXX”, has been linked to Russian cybercriminal organisations[6] by the Australian Federal Police. It has known links to the notorious REvil cyber gang[7] (which was dismantled by[8] Russia’s Federal Security Service in January).

Large-scale cybercriminal gangs are able to extort high ransom payments from their victims. During REvil’s arrest[9], authorities seized the equivalent of A$12.8 million in cash, $7 million in crytpocurrency and 20 luxury cars.

There are multiple ways to decrease the profitability of data breaches for criminal organisations. The first is to make hacks more difficult, making it more time-consuming for the hackers to break into computers.

This could be achieved by increasing fines for organisations that fail to follow best practices in cybersecurity – a privacy reform that[10] was recently introduced in Australia and has passed through the lower house.

A second potential solution is to make ransomware payments illegal in Australia. Under some circumstances, it may already be illegal[11] for Australian organisations to pay a ransom, such as if the payment funds further criminal or terrorist activity of groups under sanction by the United Nations.

However, the attribution of cyberattacks[12] is difficult, and it’s not always possible to know whether paying a particular group would be a crime. An organisation may pay a ransom, only to find out much later it has broken the law.

When banning ransom payments works

The idea of banning ransom payments isn’t new. In April, Nigeria criminalised ransom payments to kidnappers[13]. However, not paying kidnap ransoms in Nigeria has also resulted in deaths, which suggests this approach may end up punishing victims[14].

Still, survey results show citizens and cybersecurity experts are generally in favour of banning ransomware payments. In a recent survey of UK residents by security firm Talion[15], 78% of respondents from the general public supported a ban, as did 79% of cybersecurity professionals.

A ban on ransom payments could quickly reduce the profits racked up by criminal gangs targeting Australia.

In cases like the recent Optus and Medibank hacks, where the ransom was demanded to “not leak” sensitive information, banning ransom payments may be a good idea. It could take the burden of making a decision away from the organisation targeted, and mitigate the public’s judgment of that decision.

It would also reduce (but not entirely remove) the possibility of criminals receiving ransom payments – and therefore make their operations less profitable.

The problems with a ban

However, unlike the Optus and Medibank breaches, many ransoms are paid to unlock encrypted computers. Some ransomware attacks involve the hackers encrypting all of the computers, data and backups a company has. Failing to restore those data can, in many cases, cause the business to collapse.

In such instances, banning ransom payments may discourage organisations from declaring breaches. They may pay the ransom to be able to move on with business – even if it is a crime. Should this happen, it would reduce the overall transparency of reporting on breaches, and could lead to hackers blackmailing victims to not divulge the hack.

This particular concern has led the US Federal Bureau of Investigation to recommend to the US Senate Judiciary Committee to not ban all ransom payments[16].

For a ban on ransom payments to be effective, the penalties for paying the ransom would need to be more severe than the impact of the ransom itself. If the penalties are inadequate, organisations may simply pay the ransom and deal with the legal consequences so they can move on with normal operations.

An alternative solution

Cyberinsurance policies often provide reimbursement for ransomware payments. In fact, it’s a common tactic for cybercriminals to demand a ransom equivalent to the insurance reimbursement[17]. While this means the organisation suffers fewer losses, the cybercriminals still profit.

A more nuanced approach may be to ban cyberinsurance reimbursements for ransom payments, which would reduce the overall percentage of breaches that result in a payment. This could reduce profits for criminal gangs, while still allowing a company to salvage its operations under the worst-case scenarios.

The decision to ban or not to ban ransomware payments is complicated, and a blanket ban is likely to cause more problems than it fixes. We need change, but the best solution would be a case-by-case approach.

In the end, these kinds of cybercrimes are unlikely to be eradicated by any single policy change. They will require a wide range of policies, laws and regulations that each chip away at specific problems. If we do this, eventually the cost to criminals could outweigh the profits.

Read more: Budget 2022: $9.9 billion towards cyber security aims to make Australia a key 'offensive' cyber player[18]

References

  1. ^ deleted the rest (theconversation.com)
  2. ^ data on Friday (www.theguardian.com)
  3. ^ Medibank hackers are now releasing stolen data on the dark web. If you're affected, here's what you need to know (theconversation.com)
  4. ^ to retaliate against (www.sbs.com.au)
  5. ^ to cybercriminals illegal (au.finance.yahoo.com)
  6. ^ Russian cybercriminal organisations (www.abc.net.au)
  7. ^ REvil cyber gang (theconversation.com)
  8. ^ was dismantled by (www.bbc.com)
  9. ^ REvil’s arrest (www.bbc.com)
  10. ^ privacy reform that (www.theguardian.com)
  11. ^ already be illegal (www.homeaffairs.gov.au)
  12. ^ attribution of cyberattacks (www.wired.com)
  13. ^ ransom payments to kidnappers (www.aljazeera.com)
  14. ^ punishing victims (theconversation.com)
  15. ^ security firm Talion (talion.net)
  16. ^ ban all ransom payments (edition.cnn.com)
  17. ^ the insurance reimbursement (www.homeaffairs.gov.au)
  18. ^ Budget 2022: $9.9 billion towards cyber security aims to make Australia a key 'offensive' cyber player (theconversation.com)

Read more https://theconversation.com/australia-is-considering-a-ban-on-cyber-ransom-payments-but-it-could-backfire-heres-another-idea-194516

The Times Features

Why Roof Replacement Is the Best Solution for Roofs with Major Leaks

When your roof is leaking extensively, the situation can be both frustrating and worrying. The constant drip-drip-drip of water, the potential for structural damage, and the risi...

Why Your Tennis Game Isn’t Improving (And How to Fix It)

Tennis is a sport that demands precision, endurance, strategy, and mental toughness. Whether you play casually or competitively, you may reach a frustrating point where your prog...

Can you get sunburnt or UV skin damage through car or home windows?

When you’re in a car, train or bus, do you choose a seat to avoid being in the sun or do you like the sunny side? You can definitely feel the sun’s heat through a window. Bu...

Want your loved ones to inherit your super? Here’s why you can’t afford to skip this one step

What happens to our super when we die? Most Australians have superannuation accounts but about one in five[1] of us die before we can retire and actually enjoy that money. I...

Home Safety 101: What You Shouldn’t Ignore

Overloaded outlets, unattended cooking, and faulty smoke alarms are common fire hazards that many homeowners overlook. Poorly maintained appliances, including electrical cords...

Here's How to Pick the Best Hair Loss Treatment for Your Needs

Hair loss can be frustrating, probably an emotional experience, and only with appropriate types of treatments is one able to restore one's confidence level, showing results that ...

Times Magazine

What to Look for When Booking an Event Space in Melbourne

Define your event needs early to streamline venue selection and ensure a good fit. Choose a well-located, accessible venue with good transport links and parking. Check for key amenities such as catering, AV equipment, and flexible seating. Pla...

How BIM Software is Transforming Architecture and Engineering

Building Information Modeling (BIM) software has become a cornerstone of modern architecture and engineering practices, revolutionizing how professionals design, collaborate, and execute projects. By enabling more efficient workflows and fostering ...

How 32-Inch Computer Monitors Can Increase Your Workflow

With the near-constant usage of technology around the world today, ergonomics have become crucial in business. Moving to 32 inch computer monitors is perhaps one of the best and most valuable improvements you can possibly implement. This-sized moni...

Top Tips for Finding a Great Florist for Your Sydney Wedding

While the choice of wedding venue does much of the heavy lifting when it comes to wowing guests, decorations are certainly not far behind. They can add a bit of personality and flair to the traditional proceedings, as well as enhancing the venue’s ...

Avant Stone's 2025 Nature's Palette Collection

Avant Stone, a longstanding supplier of quality natural stone in Sydney, introduces the 2025 Nature’s Palette Collection. Curated for architects, designers, and homeowners with discerning tastes, this selection highlights classic and contemporary a...

Professional-Grade Tactical Gear: Why 5.11 Tactical Leads the Field

When you're out in the field, your gear has to perform at the same level as you. In the world of high-quality equipment, 5.11 Tactical has established itself as a standard for professionals who demand dependability. Regardless of whether you’re inv...

LayBy Shopping