NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Inside the unusual world of cyber insurance where ransoms are paid to criminal hackers

Other
30 Sep, 2020 07:22 PM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Businesses increasingly rely on cybercrime insurers to protect their business against hackers. Photo / Getty Images

Businesses increasingly rely on cybercrime insurers to protect their business against hackers. Photo / Getty Images

It was an ordinary October day when startled employees of a Canadian insurance firm discovered their computer files locked and a digital ransom note left by hackers.

"Hello, your network was hacked and encrypted. No free decryption software is available on the web. Email us to get the ransom amount."

After some negotiation, with the help of a British cyber insurance firm, the criminals settled on a payment of US$950,000 (NZ$1.4 million) in Bitcoin to unlock the files. The Canadian company was left with little choice but to pay up. Fifteen days later, the files were released.

This sequence of events was described in a private High Court hearing in December which was unsealed in January.

READ MORE:
• Houseparty users claim app has been hacked – but creators deny breach
• Hackers steal photo ID and tax codes from 26,000 Generate KiwiSaver customers
• Premium - The year of the hacker: Why now, and is NZ a soft touch?
• Premium - Cyber security expert accuses hacked KiwiSaver provider of lax approach

Advertisement
Advertise with NZME.

The businesses involved chose to remain anonymous to avoid tipping off the hackers of their attempt to use the courts to get their ransom money back from a cryptocurrency exchange.

It may seem like a surreal scenario, but experts say it has become a common occurrence.

There is in fact a booming industry in cyber insurance which often involves paying ransoms to shadowy hacking groups using cryptocurrency.

Advertisement
Advertise with NZME.

Paying a ransom to regain access to critical systems has become a valid option for many executives.

Garmin, the smartwatch manufacturer, reportedly paid a multi-million dollar ransom following a hack earlier this year. And Travelex, the foreign exchange business, reportedly paid a $2.3m ransom in April following a similar attack.

American and Canadian businesses may be prime targets for hacking, but many of the world's cybercrime insurers are headquartered in London.

"The primary goal is to help them get back up and running without having to make a ransom payment, because facilitating ransom payments is complex," says Graeme Newman, chief innovation officer at CFC Underwriting, a cyber insurance pioneer.

"Under the vast majority of cyber insurance policies, there is a section to cover the reimbursement of ransom payments which are made."

Experts say the UK market for cyber insurance, with around 15 per cent of companies taking out policies, lags well behind the US where roughly 35 per cent of businesses take out the insurance.

"The UK is a large exporter of cyber insurance policies," says Graham Walsh, a policy adviser at the ABI.

The problem of hacking is becoming more widespread as online information storage increases. Photo / Getty Images
The problem of hacking is becoming more widespread as online information storage increases. Photo / Getty Images

When a company is hacked, executives contact their insurer who introduces them to specialist ransomware negotiators as well as security experts, lawyers and sometimes the police.

Advertisement
Advertise with NZME.

To prepare for attacks, many businesses purchase Bitcoin in advance so that they have a ransom payment ready and waiting. Companies are also investing in tape backups of their data, an antiquated technology which retains its appeal for a simple reason: Hackers can't encrypt it.

If a business decides that the only way to get back to business as usual is to pay a ransom, then their insurer can research whether the hacking group is trustworthy.

It might seem surreal to consider whether an anonymous hacker group could ever be trusted, but it is in the interest of ransomware gangs to build up their reputation.

One ransomware group, known as MAZE, published a press release in March promising not to target healthcare organisations during the pandemic. It also offered a discount on unlocking files.

Hackers most often demand payments in cryptocurrencies. Photo / Getty Images
Hackers most often demand payments in cryptocurrencies. Photo / Getty Images

"We are starting exclusive discounts season for everyone who have faced our product," the group wrote.

Matt Walmsley, a director of cybersecurity business Vectra says these hacking groups "want to build up brand trust. It's so that if people trust them to some degree, they're more likely to make a payment."

Insurers often consult lawyers to check that paying the ransom is legal. Most payments of this kind do not break the law, but a British business risks committing an offence under the Terrorism Act 2000 if it sends a payment to a group which is known to be linked to a terrorist organisation.

This can be a tricky area for companies. "It is usually impossible to know whether they have any connections to terrorism," says Ashley Hurst, the head of technology at law firm Osborne Clarke. "If there is a suspicion of terrorist activity, there is a risk of committing a criminal offence by paying the ransom."

Being able to legally pay ransoms, and then claiming the payment back through an insurance policy, has prompted concern that the industry is fueling a rise in ransomware attacks. Just as the payment of ransoms to kidnappers creates a moral hazard, by encouraging further activity, so the payment of ransoms to hacker groups risks escalating the problem.

Ciaran Martin, the former chief executive of the National Cyber Security Centre, has called for laws to block all ransomware payments. The current mix of regulations around these payments "doesn't make sense," he has said.

Etay Maor of cybersecurity business IntSights agrees with him. "The fact that they're getting paid is something that fuels them. I don't see any way around that," he says.

But insurers say businesses would pay the ransoms anyway and believe that offering a safe way to handle the transactions reduces the risk of money being lost.

"If a business is on its knees, they will find a way of doing it," Newman says. "We can put the proper controls and procedures in place and hopefully use that to help law enforcement catch perpetrators."

The nature of the threat cyber insurers face has recently changed. Hacking groups have switched focus in the last 18 months to prey on fears of breaching GDPR in order to extort higher ransoms stretching to millions of pounds.

Two years ago, it was common for hackers to simply encrypt files, locking the business out of its data until a ransom was paid.

Now, hackers often smuggle out a company's files and hold them to ransom. If no payment is made, the groups leak the information and force the victim to disclose a data breach to regulators.

"The criminals changed their tactics," Newman says. "They now exfiltrate the data then encrypt it."

With no change in the law imminent, and an industry of specialist ransom negotiators forming, the market for cyber insurance looks set to continue to grow.

That leaves hacked businesses, insurers and lawyers grappling with the moral dilemma of handing money to criminals.

"No one wants to support criminal activity by paying," Hurst says. "But it may still be the right thing to do to protect confidential information and personal data."

- Telegraph

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

New Zealand

Health NZ confirms 377 roles cut, despite ongoing legal challenge

15 May 07:06 AM
Premium
Shares

Market close: NZ sharemarket up as Sanford rides the wave

15 May 06:10 AM
New Zealand

‘Possible cartel conduct’: Sparky association changes policy after investigation

15 May 05:43 AM

“Not an invisible footprint”: Why technology supply chains need optimising

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Health NZ confirms 377 roles cut, despite ongoing legal challenge

Health NZ confirms 377 roles cut, despite ongoing legal challenge

15 May 07:06 AM

Legal action by PSA means some changes are currently on hold.

Premium
Market close: NZ sharemarket up as Sanford rides the wave

Market close: NZ sharemarket up as Sanford rides the wave

15 May 06:10 AM
‘Possible cartel conduct’: Sparky association changes policy after investigation

‘Possible cartel conduct’: Sparky association changes policy after investigation

15 May 05:43 AM
'Removes unnecessary red tape': NZX on new IPO rules

'Removes unnecessary red tape': NZX on new IPO rules

15 May 03:59 AM
Deposit scheme reduces risk, boosts trust – General Finance
sponsored

Deposit scheme reduces risk, boosts trust – General Finance

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP