NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Juha Saarinen: Make it illegal to pay ransomware extortionists

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
16 Jun, 2020 05:00 AM6 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

The ransomware business is getting bigger and nastier by the week. Photo / 123RF

The ransomware business is getting bigger and nastier by the week. Photo / 123RF

COMMENT:

Travelex, Toll Group, Bouygues Construction, Fisher & Paykel Appliances, Lion, Honda – these are familiar names on a growing list of companies and organisations being hit by different types of ransomware.

It really is a hit too: when ransomware strikes, it can be devastating to a company's operations as their computer systems become unusable, with the data that they need being encrypted and inaccessible.

The ransomware business is getting bigger and nastier by the week. While ransomware criminals used to take a scattergun approach and send out malware to a large number of potential victims, they now reconnoitre select targets carefully, scanning the internet for unpatched and vulnerable peripheral network devices and servers as well as sending out booby-trapped email attachments.

Once an interesting organisation has been found and compromised in some way, the ransomware criminals don't necessarily strike immediately. Instead, they bide their time, maybe wait for a company's reporting season or annual general meeting, and then activate their malware to exert even greater pressure to force an organisation to pay them.

Advertisement
Advertise with NZME.

While they wait, ransomware criminals persist in the systems and copy over sensitive and confidential data. It can be financials, privacy-sensitive records from healthcare providers, legal documents from law firms, or future product plans from manufacturers. As part of the attack, ransomware tries to delete any data backups, in order to make recovery much more difficult.

READ MORE:
• Premium - Juha Saarinen: Your data is traded by reckless idiots
• Premium - Juha Saarinen: Not going to work in viral times
• Premium - Juha Saarinen: Only you can fix fake news
• Premium - Juha Saarinen: Meet VandaTheGod, the hacker that didn't care

If a company struck by ransomware hesitates to pay the extortionists, their data will be published on a website somewhere on the internet. Sometimes the data goes up immediately after the ransomware has encrypted the information on an organisation's servers, as additional "encouragement" to pay up.

Advertisement
Advertise with NZME.

There is even "ransomware as a service" now. This is when malware developers either rent out or sell their code to others who deploy it against victims for extortion.

It would be wrong to blame the ransomware victims for what is happening. They have little or no support from anyone, with no effective local organisation currently offering advice and assistance on how to deal with ransomware attacks. If they can't find a decryptor via Interpol's No More Ransom site that's pretty much it for victims.

Discover more

Retail

It's great to have Uber Eats back - except if you're one of their delivery people

19 May 05:00 PM
Opinion

Juha Saarinen: Is Apple's new iPad Pro worth $3900?

26 May 05:00 PM
Opinion

Juha Saarinen: VandaTheGod, the hacker that didn't care

02 Jun 05:00 AM
Opinion

Juha Saarinen: When tech plays hard to get ... into

09 Jun 05:00 PM

We mustn't forget that information technology and networks are very much "black box" stuff.

Figuring out that your systems are vulnerable, either because they're missing updates or there's a newly discovered flaw that can be exploited to break into organisations' data troves, is really hard.

There's a whole industry out there making software that tries to detect and prevent intrusions, and sift through giant log files looking for anomalies that could indicate an attack is under way.

Even when such precautions are taken, ransomware gets through the defences.
Sometimes this happens as companies' trusted managed service providers, the fancy term for outsourcers, are compromised and used as convenient attack vectors against their customers.

It can take as little as one vulnerability that opens up systems to the first step in an exploit chain, and the criminals get in.

As a related aside, there are good people out there who understand the asymmetric nature of attackers versus defenders. They're security experts who think like hackers, and do penetration testing.

Advertisement
Advertise with NZME.

When the ransomware activity started to spike as the Covid-19 pandemic got worse, I spoke to one security consultant, asking if his company had been run off their feet with clients wanting to check their IT setups were as secure as they could be. To my surprise, that wasn't the case. Only a couple of organisations had come forward and requested testing.

Maybe there isn't enough awareness that IT security is a process that needs constant work and updating to remain effective; which is fair enough as IT is a tool for many organisations, and not their core business or competence. There's room for a rethink here though.

Then there's the difficulty in identifying who the ransomware criminals are. They hide behind monikers such as Snake, Maze, Nefilim, and REvil, deliberately using broken English in ransom notes to mislead cyber sleuths as to their nationality.

Some countries such as North Korea are believed by security researchers to actively launch ransomware campaigns to bring in foreign currency, and as low-level sabotage efforts.

Other nations are thought to tolerate the criminals as long as no attacks are launched in their home territories. There is ransomware that's designed not to activate if it finds computers that are set to the languages of the Commonwealth of Independent States that succeeded the Soviet Union for example.

Ransomware criminals are in it for the money, and that's the key. Photo / 123RF
Ransomware criminals are in it for the money, and that's the key. Photo / 123RF

Following the money trail is difficult too, as there are services that take the ransom amount paid in crypto currency and split it up in multiple small transactions, mix them with others, and send them via different dodgy exchanges. It's possible to trace the ransom transactions, but it takes time and effort.

There is no such thing as totally secure IT systems, and finding the criminals is slow and difficult and there's no shortage of others wanting a slice of a billion-dollar cottage industry; what do we do?

Ransomware criminals are in it for the money, and that's the key.

Paying ransoms makes the situation worse. It can be a double-bind situation where victims feel they need to pay to ensure their organisations survive, or patient data doesn't leak out and hurt vulnerable people, or legally privileged information isn't used to blackmail victims.

Maybe it's fear of reputational damage. Generally speaking, most ransomware organisations I've talked to recently have tried to keep quiet about attacks. One aspect of that is the worry that ransomware criminals will start to publish data if attacks become known, or an organisation says they won't pay. This seems pointless, as it's almost guaranteed that ransomware raiders will publish data anyway to force payment.

Instead, make it illegal to pay data ransoms, be it directly or via insurers.

It isn't currently, but paying ransoms only supports criminals and helps them refine their wares, making them even more effective and devastating. Paying ransoms also makes the business more attractive to newcomers, guaranteeing that a bad situation will become even worse.

It might hurt at first but halt the flow of money, and you stop ransomware.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Opinion

Dellwyn Stuart: The real cost of Govt's retreat on gender equity

21 Jun 03:00 AM
Premium
Retail

'The way of the future': How delivery apps are redefining supermarket shopping

21 Jun 12:00 AM
Premium
Opinion

Bruce Cotterill: Is it time to reassess our independence?

20 Jun 11:00 PM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Dellwyn Stuart: The real cost of Govt's retreat on gender equity

Dellwyn Stuart: The real cost of Govt's retreat on gender equity

21 Jun 03:00 AM

OPINION: Services for wāhine Māori and young mothers have been slashed.

Premium
'The way of the future': How delivery apps are redefining supermarket shopping

'The way of the future': How delivery apps are redefining supermarket shopping

21 Jun 12:00 AM
Premium
Bruce Cotterill: Is it time to reassess our independence?

Bruce Cotterill: Is it time to reassess our independence?

20 Jun 11:00 PM
Premium
Mary Holm: Embracing non-financial investments for a happier retirement

Mary Holm: Embracing non-financial investments for a happier retirement

20 Jun 05:00 PM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP