How a ransomware attack can destroy a small business

INTRODUCTION

With 4,000 daily attacks since 2016, ransomware is one of the significant threats to small businesses today. As the name suggests, it is malware that takes complete control of your files, encrypts them, and holds them for ransom! In effect, your most important files and systems become inaccessible. Using ransomware, hackers can target one computer or a whole network, including servers.

Only after a victim pays the ransom will they receive the decryption key and gain back access to their systems. For any business, ransomware poses a significant threat to uninterrupted business operations. It brings the company to an absolute standstill, and many small business owners choose to pay the ransom rather than delay service to their customers, resulting in revenue loss.

While this attack sounds quite simple, it is highly effective. It can be a nuisance for a company with all its vital files, documents, network, and servers suddenly encrypted and inaccessible. What is more dangerous is that hackers can threaten to leak sensitive data that can severely damage the company’s reputation or divulge sensitive private data to its competitors.

With $5 billion in losses in 2017, it has the capability of putting them out of business. It is a common misconception that ransomware targets only large companies. Small and medium-sized businesses are often the targets as they have lower security standards and generally believe that they are too small for such attacks.

Small businesses are more willing to pay the ransom as it is much smaller than the revenue losses they will have to bear due to the attack. The cost to recover from a ransomware attack has increased by 228% from 2018-2019.

HISTORY OF RANSOMWARE

While it may seem like a new cyber threat, ransomware first emerged in 1989, where the virus was distributed via a floppy disk with a focus on the healthcare industry. It was called AIDS or the PC Cyborg Trojan. It encrypted the machine after 90 boots and demanded the user ‘renew their license’ with ‘PC Cyborg Corporation’ by paying $189 or $378 to a post office in Panama.

The first Ransomware: AIDS or PC Cyborg Trojan

The earlier versions of ransomware used simple cryptography (symmetric encryption) and usually changed the file names, making it much easier to overcome. However, the hackers quickly corrected this, and with the internet boom of the 1990s, it quickly evolved into sophisticated attacks that targeted not only individuals but large corporations.

By the middle of the 2000s, ransomware was becoming tough to break. However, the problem of receiving payments was still there. Any form of payment at that time could easily be tracked, whether through a credit card or cheque, making it extremely difficult for a hacker to cover his tracks.

Enter CryptoLocker: the first ransomware that demanded bitcoin as a payment for the ransom. Cryptocurrency matched with randomly generated email addresses and darknet pathways made it impossible to catch the hackers. Now, ransomware authors are making tens, if not hundreds, of millions of dollars through their campaigns, forcing companies to think of new strategies.

Cryptocurrency has given a tremendous boost to ransomware campaigns in the past few years. Now, companies have strategized to buy and hold bitcoins to prepare for any unforeseen attacks in the future. Since 2012, ransomware has exploded in its global presence.

HOW DOES RANSOMWARE AFFECT YOUR BUSINESS?

An innocent employee clicking on a malicious link or an attachment sent to him via an email can start a ransomware attack. Through this phishing attack, the hacker can download malicious software that starts scanning the device and encrypting the files in the background, and the user is none the wiser.

Initially, the hackers targeted individuals but soon learned that it is far more profitable to target businesses. Whether small or large, the business has a particular urgency when operations are brought to a halt, resulting in revenue loss and possible loss of data. It comes as no surprise that in 2017, 35% of small and medium-sized businesses had experienced a ransomware attack.

Other times, it can be large, sophisticated ransomware campaigns that use software exploits and vulnerabilities in their internet-facing servers or remote desktop logins to access the organization’s network. The attackers will scan the entire network, stay under the radar to capture and encrypt as many files as possible.

COST OF A RANSOMWARE ATTACK

There are three types of costs associated with a such an attack: Ransom, Revenue Loss, Future Proof.

The most visible cost, ransom, is the cost a business might have to bear if they lack back up to restore their operations. As the hackers want to incentivize you to pay the ransom quickly, they keep this cost low. Ransom can be anywhere between $200 to $10,000, depending on the size of the business.

However, the ransom cost is much lower than what the small business might incur if it loses all the data and has to restore its systems from scratch. Such activity will result in loss of data and revenue loss for days, if not weeks and months. The revenue loss will be dependent on the industry that the small business operates.

The small business needs to improve its defenses and put in suitable cybersecurity technologies and processes to ensure that it doesn’t fall prey to another attack. Again, this cost is dependent on the industry of the business.

TYPES OF RANSOMWARE

Defining the types of ransomware is a challenging task. As this malware is rapidly evolving, many new ransomware families are introduced each day, while others disappear suddenly. It is not uncommon for novel ransomware to create havoc for six months and then go out of fashion and never be used again.

Maintaining a ransomware campaign is hard work as it requires the hackers to regularly update the malware to avoid detection. Furthermore, updates can add features to the malware. For example, the ransomware Locky authors added the functionality of asking for ransom in 30 languages! It increased the malware’s reach, resulting in a more profitable campaign.

Scareware – this type of ransomware is, well, not that scary. It is more of a scam and includes some rogue software the continually bombards you with pop-ups claiming that ransomware has infected your system and that you need to make a payment immediately. In reality, your files have not been encrypted and can still be accessed. Usually, rebooting the system removes the pop-ups, and you can remove it immediately with no ransom involved.

Locker or Blocking Ransomware – as the name suggests, this variant locks you out of your computer or locks your screen so that you can’t access anything else on the system. Such types are a medium level ransomware threat and can be dealt with ease, relatively.

An example of a Locker variant is the ‘Police Ransomware’ that displays a picture claiming to be from law enforcement and that they have detected an illegal activity in your system for which you need to pay a fine.

Encrypting Ransomware – perhaps one of the most common ransomware out in the wild, this malware gains access to your files and systems, encrypts them, and demands a ransom for the decryption key. It is an extremely dangerous malware as once the files are encrypted, you can only gain back access by either paying the ransom or restoring your back up.

Famous examples of this variation are CryptoLocker, Ryuk, and WannaCry. Each of these campaigns has created major havoc across the globe and resulted in millions of losses.

Extortionware | Doxware | Leakware – Depending on the victim, a hacker can use this form of ransomware to extort money! If the victim has sensitive and private data that could have serious consequences if made public, the hackers leverage it to extract as much money as possible. Usually, this type of attack involves extensive research on the target, accessing the data, encrypting, and then publishing it.

WHO ARE THE TARGETS OF RANSOMWARE?

Similar to phishing, anyone can be a target of a ransomware attack. A ransomware campaign is often sent out at random via phishing emails to access most systems, resulting in higher revenue.

Ransomware Threatscape 2021

According to the Positive Technologies Cyber Threatscape: Q3 2020, ransomware affected all industries equally. However, the organizations that tend to pay quickly are the ideal targets for hackers. For instance, government agencies, medical facilities, or even legal firms require quick access to sensitive data – making them prime targets for Leakware attacks.

Geographically, the targets primarily lie in the western markets, with the UK, USA, and Canada ranking the top three countries targeted. The hackers follow the money and focus on areas where there is broad adoption of PCs and relative wealth.

HOW TO PREVENT RANSOMWARE ATTACK

Like any other business risk, it is best to be prepared for this attack and have contingencies for such an event. Luckily, there are several things a small business can implement to prevent and mitigate the effect of a ransomware attack. The following steps are procedural as well as technical.

  1. Ensure that all your systems are up to date when it comes to security patches. Apart from providing added features, these updates fix software vulnerabilities that can expose your network and systems to outside hackers.
  2. Install an updated version of antivirus, whitelisting software, and firewall in your network to protect against known threats. Further, do not install software or give it administrative privileges if you don’t know what it is and what it does.
  3. Train your employees to spot phishing emails. Only through regular security awareness training and developing a security culture in your organization can you protect it from various online threats.
  4. Close all insecure ports on your internet-facing devices. These are often the way hackers use to infiltrate your network and makes it easier for them to deploy malware.
  5. Protect your remote desktop access with a strong password immune to brute force attacks and even enable Multi-Factor Authentication (MFA) on the login credentials.
  6. Prevent your employees from enabling macros in Microsoft Office can go a long way in ensuring that they don’t unintentionally run a ransomware file.
  7. But perhaps the best protection against a ransomware attack is to back up your data regularly! While you can use external hard drives for the Backup, ensure that the hard disk is offline or that hackers can get access to it and encrypt it too. Many security researchers advise people to use cloud-based solutions to automatically backup data and keep it encrypted and safe from hackers. However, take this with a grain of salt, you are equally responsible for the cloud data security as the cloud company.
  8. Cyber insurance can also help cover the business’s liability in the event of an attack. But it can’t be considered a solution for all consequences or a way to get your data back.
  9. For further advice, please read the Ransomware Guide from the Cybersecurity and Infrastructure Security Agency (CISA)

WHAT TO DO IF YOU ARE VICTIM OF A RANSOMWARE ATTACK?

If you find your business under a ransomware attack, follow the steps outlined in this section to help you deal with the attack and get your business back to the pre-attack days.

First of all, don’t panic! It is always best not to react instantly in any life emergency but take stock of the situation and formulate a plan. If your business is experiencing an attack, ask yourself these questions:

  1. Is this actual ransomware or a “scareware”?
  2. Do you have all your crucial data backed up?
  3. How long will it take you to restore data from backup?

If the malware turns out to be “scareware,” then you can quickly fix the issue. In the majority of cases, scareware disables or uninstalls the antivirus program on your computer. By re-installing the antivirus program, you will be able to remove the scareware. If this solution doesn’t work, go through this link to remove the scareware.

However, if it is not scareware, there is little you can do to get back access to your data. After all, the best cure for ransomware is to prevent it. If you have a backup, initiate the recovery process as soon as possible. However, if you do not have a backup, things become a little tricky. But hope is not yet lost!

There is still a chance that you might get back your data. Some White Hat Hackers have made available free tools to decrypt your files in case of an attack. The “No More Ransomware” tool is one such example.

Available in various languages, it provides decryption keys for known ransomware! However, it is essential to note that these decryption keys are only for known ransomware attacks and will not have keys for novel ransomware. Another such tool is that of ID Ransomware.

List of Ransomware decrypted by No More Ransomware

Furthermore, various security companies such as Kaspersky, Quick Heal, Avast, McAfee, and Heimdel Security have provided free tools to decrypt ransomware! Make use of these decryptors before you pay any ransom.

Security researchers strongly advise against paying any ransom as it only perpetuates such attacks in the future. If the word gets out that your company pays ransom quickly, your business can experience more cyber attacks! Furthermore, there is no guarantee that you will regain access to your files even after paying the ransom.

Therefore, it is always a good practice to prevent ransomware attacks at all costs and invest in a good data backup strategy from which it is easy to restore your business!

CONCLUSION

Ransomware is one of the fastest-growing cyber threats, and small businesses must take notice of it. The best way to tackle it is to back up your data regularly and decrease the chances of a successful attack by updating security patches, training your employees, developing a security culture, and closing any unneeded ports on your internet-facing devices.

Small businesses are most prone to cyber attacks and must practice restoring from backups regularly. As a small business owner, if you don’t have a playbook for any other cyber threat, ensure that you have one for ransomware. The ransom, along with revenue loss resulting from lack of business activity, can severely put a dent in a small business’ financials.

Leave a Comment

Your email address will not be published. Required fields are marked *