{"id":11862,"date":"2019-12-06T09:30:49","date_gmt":"2019-12-06T14:30:49","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=11862"},"modified":"2020-12-10T09:53:37","modified_gmt":"2020-12-10T14:53:37","slug":"going-after-the-good-guys-the-governments-ransomware-identity-crisis","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/going-after-the-good-guys-the-governments-ransomware-identity-crisis\/","title":{"rendered":"Going After the Good Guys: The Government\u2019s Ransomware Identity Crisis"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Why fixing that ransomware attack might get you indicted<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Editor\u2019s\nNote: We\u2019re pleased to publish this article from attorney Ryan Blanch, sharing\nan expert perspective on some of the legal issues in the cybersecurity\nindustry. <\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When it\ncomes to ransomware, malware, and hackers, the government is finding it\ndifficult to keep pace with the quickly evolving landscape of cybercrime. And\nsometimes, the government seems to be going after the good guys instead of the\nbad guys, as evidenced by the recent CoalFire debacle in which Iowa arrested\nand charged the same cybersecurity professionals it had contracted to try to\nbreach the state\u2019s security systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As a criminal\ndefense attorney, I\u2019ve been involved in myriad cybercrime cases. There were the\n<a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-ddos-attack\/\">DDoS attacks<\/a> on the Church of Scientology, and then the infamous Blackshades\nmalware allegedly used to spy on Miss Teen USA. We defended a <a href=\"https:\/\/www.theblanchlawfirm.com\/press\/software-developer-accused-of-aiding-and-abetting-illegal-gambling\/\">sports gambling software company\naccused of conspiring with the mob<\/a> abroad, which went to trial and was ultimately dismissed.\nLater, we handled a cryptocurrency hacking case, an online currency arbitrage\nplatform; and, more recently, the allegedly illegal deployment of scores of\nBitcoin ATM machines around high crime neighborhoods \u2013 to name a few.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In most\ncases, it\u2019s at least apparent why prosecutors are focusing on our client. But\nin other cases, prosecutors are barking up the wrong tree\u2014they\u2019re going after\nthe targets they can find instead of looking for the actual bad guys. After all,\ncareer hackers can be nearly impossible to track down and apprehend. In the\nsports gambling case I handled, my client reported that the New York district\nattorney\u2019s office wanted to strongarm him into hacking into his clients\u2019\nsystems to turn over personal data on gamblers and their bookmakers who may be\ninvolved in illegal gambling.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another area\nwhere prosecutors seem to be struggling to find and prosecute the right parties\nis with ransomware attacks. If you should fall victim to a ransomware attack,\nbe very careful how you navigate your crisis. And that goes double for those\nwho try to help you. The government may be looking to indict you both. And the <a href=\"https:\/\/www.theblanchlawfirm.com\/practice-areas\/major-felonies\/distribution-of-malicious-software\/\">penalties<\/a> are steep.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How Ransomware Attacks Work: From Attack to Prosecution<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Ransomware\nbrings companies to their knees in an instant as it encrypts user data and\nfiles irretrievably. In some cases, the only way to resume business as usual is\nto pay the ransom outright and most of them only take crypto.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Phase 1: The Attack<\/h3>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/12\/fake-fbi-ransomware-1024x576.png\" alt=\"Fake FBI screen from ransomware\" class=\"wp-image-11863\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/12\/fake-fbi-ransomware-1024x576.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/12\/fake-fbi-ransomware-300x169.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/12\/fake-fbi-ransomware-768x432.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/12\/fake-fbi-ransomware.png 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You show up\nto work to find a message like this one filling all 100+ displays of your\ncompany\u2019s employee workstations. Your CTO and IT administrator are in a panic. Your\nentire company has been locked out of its servers, computers and files. The company\nstands to lose hundreds of thousands of dollars each week that this persists. There\nis a countdown clock on the monitor, and IT cannot find any way to access the\nsystem. All you can think is, \u2018What would Kiefer Sutherland do?\u2019&nbsp; <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Phase 2: The Fallout<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s day two\nand the losses have already exceeded $40K. Clients are taking flight as they\nfear the worst. Employees are asking whether they should come to work, and the IT\ndepartment is pulling its collective hair out. &nbsp;You wonder what you have them around for if\nthey can\u2019t fix your computer-related problems. Arnie, Head of IT (for now), has\nresorted to Googling (from his personal cell phone) \u201cransomware help\u201d to look\nfor outside companies that might be able to lend a hand.&nbsp; <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The 5 bitcoin\ndemanded hasn\u2019t yet increased, but it might as well have because the volatile\nbitcoin market has already added $5,753 to the price (some companies are\nstarting to keep an emergency bitcoin account to offset the risk of price\nfluctuations). &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Someone\nreminds you that you have business insurance that may cover this sort of thing.\nYou call your insurer. They do in fact cover ransomware attacks and have a list\nof \u201capproved providers\u201d aka cybersecurity firms who can help.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Phase 3: The White Knight Arrives<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It looks as\nthough all that panic-driven Googling may have paid off. Arnie has already\nfound a cyber security firm and is on the line with them. As luck would have\nit, this firm is also on your insurance company\u2019s \u201capproved provider\u201d list. &nbsp;The firm thinks they may be able to resolve\nthe problem remotely. But when asked, they admit that no one can actually decrypt\nthe files. &nbsp;More pointedly, if you were\nto marshall the combined forces of Homeland Security, the NSA, M.I.T., Kaspersky\nLabs and Elliot Gunton to the singular purpose of retrieving the electronic\nfiles of your trading house and photos of your mini labradoodle wearing a tutu,\nthey would all wind up with zilch. That\u2019s how hard it is to unencrypt what\u2019s\nbeen properly encrypted. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So how can\nthis cybersecurity firm help? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Pay the\nransom, of course. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So then, what\ngood are they? Well, for starters, they have a bitcoin wallet on the ready. You\ndon\u2019t. Secondly, they actually know how to deploy a decryption key. You don\u2019t\n(and neither does Arnie). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Turns out\nmost ransomware, eh hem, artists don\u2019t restore your files for you when you pay\nthe ransom. They merely send you a key. Technical support doesn\u2019t exist. It\u2019s\ndo it yourself. And you wouldn\u2019t want your attackers fixing it for you even if\nthey offered. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here is why\nit makes sense to hire the cyber security firm rather than pay the ransom\nyourself in a nutshell:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>They can pay immediately.<\/li><li>They may be able to get the attackers\nto lower the ransom. Probably not enough to decrease your cost but enough to\noffset the cost of the firm\u2019s fee.<\/li><li>You shouldn\u2019t be dealing with your attackers.\nThey may expand the problem to other systems if you let the wrong information\nslip. <\/li><li>Once you get the key, if you don\u2019t\ndeploy it correctly you could corrupt your files forever. Some of these keys\nrequire several steps to deploy them. And you need to make sure you back up\nyour files first, etc. <\/li><li>After you get your files back you\nneed to close the proverbial back door. Your attackers could come back if you\ndon\u2019t. The honor of your extortionist ends with the promise to send you the\nkey. It does not include a promise to never return.<\/li><li>The best firms will issue and update a\nwhite paper to make sure that you continue to follow best practices to avoid\nsubsequent attacks.<\/li><li>An honest firm will tell you if the\nstrain of your ransomware variant is actually undecryptable. Some variants are old,\nand the decryption key has already been disseminated publicly. If your firm has\nthe key, they may just deploy it for you at little or no cost.<\/li><\/ol>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"708\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/12\/ransomware-screen-1024x708.png\" alt=\"Ransomware screen\" class=\"wp-image-11864\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/12\/ransomware-screen-1024x708.png 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/12\/ransomware-screen-300x208.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/12\/ransomware-screen-768x531.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/12\/ransomware-screen.png 1431w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Phase 4: \u00a0The White Knight Gets Indicted<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">All good? Not so fast. Now the cyber security firm\u2019s principals and employees are contacted by the FBI\u2019s Cyber Division. The U.S. Attorney\u2019s Office wants to talk about a turn-in date and because they know this is a real company with generally law-abiding individuals, they wanted to call and invite them in to \u201cself-surrender\u201d so they can forgo the unpleasantness that comes with a 3AM home arrest warrant execution. \u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Looks like\nyour company\u2019s savior is going to need to hire a great criminal defense\nattorney.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Why? Turns\nout the government doesn\u2019t look kindly on paying ransoms. The reasons\nthemselves are not objectionable: <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>&nbsp;The money could go straight to terrorist\norganizations and other criminal cartels <\/li><li>&nbsp;The money is difficult to trace when\ntransferred through bitcoin.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">But the\ngovernment also knows that juries don\u2019t like to convict victims for paying\ntheir extortionist. It\u2019s like arresting the mother of a kidnapped child for\npaying the kidnappers their ransom to get her baby back. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>It would never fly. <\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How The Government Views Paying Computer Ransoms<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Lost\ncomputer files, lost business revenue and even stolen intimate photos are less\nsympathetic reasons to sponsor a crime cartel than say, getting a real live\nchild back. But, just the same, the DOJ doesn\u2019t like to lose. And prosecuting\nvictims is a losing strategy. So, for now, victims can (probably) pay ransoms\nback directly (as ill-advised as that is) to their attackers. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But if you\nhire an intermediary, that\u2019s where the government is testing a prosecutorial\ntheory. The theory is if they can prosecute the cyber firms who pay the ransoms\nthen they can get a pelt for what they view as an ugly business. Hey, somebody\nhas to pay. Cybercrime is the new bank robbery and it\u2019s turning into an\nepidemic. The government\u2019s so-called ransomware \u201cexperts\u201d are in the stone\nages. But prosecuting cyber security firms makes it look like they are doing\nsomething about this epidemic (spoiler alert: they aren\u2019t).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Strangely\nenough, the FBI has made multiple statements encouraging or allowing companies\nto pay off ransomware attacks:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Joseph\nBonavolonta, Assistant Special Agent of the FBI\u2019s Cyber and Counterintelligence\nProgram, <a href=\"https:\/\/news.softpedia.com\/news\/this-is-the-fbi-s-official-position-on-ransomware-502475.shtml\">said that<\/a> in most cases, because the FBI can&#8217;t\nhelp these companies recover files, their agents often end up recommending them\nto pay the ransom to get their data back.<\/li><li>An\n<a href=\"https:\/\/www.ic3.gov\/media\/2019\/191002.aspx\">official statement from the FBI<\/a> said they don\u2019t \u201cadvocate\u201d paying\nransoms, but that the \u201cFBI understands that when businesses are faced with an\ninability to function, executives will evaluate all options to protect their\nshareholders, employees, and customers.\u201d<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">They haven\u2019t yet publicly announced a policy of indicting companies for paying ransoms or started issuing mass indictments. But they are hovering around the periphery, looking for instances where they think they might be able to dirty-up the white knight cyber security firm to make them a public example of the perils of paying ransoms as a business model. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What if they succeed? What does that accomplish? It doesn\u2019t stop the ransomware attacks. It doesn\u2019t stop the victims from paying those ransoms directly. But it takes out a middle man would-be protector, leaving the victim to their own devices.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Making the Good Guys Prosecutable: Dirtying up the White Knight<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If juries\ndon\u2019t like to convict victims, how would they feel about their heroes? As a\nmatter of public policy, do we want to criminally prosecute the saviors of\nthose who have otherwise irretrievably lost their businesses? &nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The answer\nis <em>it depends<\/em>. We should not criminalize the only people that offer any\nprotection whatsoever to the victims of ransomware. They also provide a\nmechanism for insurance companies to insure the losses of such an attack. The\ngovernment is putting this in jeopardy (more on this to come). In order to make\na white knight prosecutable, the government needs to shift our view of them. The\nprosecution will want the jury\u2019s perception of the white knight to be that of\nan opportunistic broker of shattered dreams. Instead of saving their victims\nfrom further attack, they provide a surcharge to further exploit them. As\nridiculous as this sounds, this is what in fact is being kicked around at DOJ\noffices everywhere. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Insurance Companies as Co-Conspirators? <\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">So, if the\ncybersecurity firm is recommended and, in some instances, paid for by the\nvictim\u2019s insurance company, doesn\u2019t that make said insurance company an\naccomplice in the conspiracy to pay ransoms to possible crime cartels? &nbsp;After all, the insurance company knows exactly\nhow the cyber security firm addresses the problem &#8211; by paying ransoms. So, will\nthe government start prosecuting Allstate for providing ransomware protection\nto its insureds?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Probably\nnot. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But, by\ntaking the cyber security firm out of the equation, it would force the\ninsurance company to pay the ransom to the insureds or even worse, pay it\ndirectly to their attackers. Knowing that would result in potential\nprosecution, they would have to stop insuring businesses and individuals from\nransom attacks all together, compounding the victim\u2019s losses exponentially. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">No Good Deed Goes Unpunished<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">So if the\nreasons listed above are all valid reasons why you SHOULD hire a cyber security\nfirm in a ransomware attack and if billion dollar insurance companies are\nrecommending that their insureds hire these companies (knowing full well that\nthose companies will pay the ransoms), then how in the world can the government\nlook to criminally charge these very same companies for doing what it has\nfailed to do &#8211; rescue victims of\nransomware?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For now, the government is limiting its\nprosecutorial powers to low hanging fruit; looking at smaller cyber security outfits\nthat they believe make easy targets to test-flex their muscles.&nbsp; They have yet to rope in the insurance companies\nwho refer them business. And their internal (and informal) policy of the moment\nseems to militate against charging ransomware victims who pay ransoms\ndirectly.&nbsp;&nbsp;&nbsp; <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But it\u2019s\n\u2018victim beware\u2019 when it comes to paying ransoms. You don\u2019t know where the money\nis going\u2014and the U.S Treasury\u2019s Office of Foreign Assets Control (OFAC)\nmaintains a nearly <a href=\"https:\/\/www.treasury.gov\/resource-center\/sanctions\/Programs\/Pages\/faq_10_page.aspx\">incomprehensible and ever changing\nlist of thousands of countries, individuals and entities to whom it\u2019s a crime\nto send funds<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The takeaway: If you fall victim to ransomware, hire a cyber security\nfirm to handle it.&nbsp; If you are such a\nfirm, proceed with caution and consult with legal counsel about best practices.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Why fixing that ransomware attack might get you indicted Editor\u2019s Note: We\u2019re pleased to publish this article from attorney Ryan Blanch, sharing an expert perspective on some of the legal&#8230;<\/p>\n","protected":false},"author":25,"featured_media":11866,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16,10200],"tags":[11473,167,7387,263],"class_list":["post-11862","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","category-monthly-digest","tag-attorneys","tag-cybercrime","tag-fbi","tag-ransomware","post-with-tags"],"views":10361,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2019\/12\/fbi-building.png","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11862","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/25"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=11862"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/11862\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/11866"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=11862"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=11862"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=11862"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}