NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Technology

A rare win in the cat-and-mouse game of ransomware

By Nicole Perlroth
New York Times·
25 Oct, 2021 07:25 PM7 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Colonial paid nearly US$5 million to hackers to recover its stolen data. Photo / Getty Images

Colonial paid nearly US$5 million to hackers to recover its stolen data. Photo / Getty Images

A team of private security sleuths, in their first public detailing of their efforts, discuss how they used cybercriminals' mistakes to quietly help victims recover their data.

In a year rife with ransomware attacks, when cybercriminals have held the data of police departments, grocery and pharmacy chains, hospitals, pipelines and water treatment plants hostage with computer code, it was a win, rare in the scale of its success.

For months, a team of security experts raced to help victims of a high-profile ransomware group quietly recover their data without paying their digital assailants a dime.

It started in late summer, after the cybercriminals behind the Colonial Pipeline ransomware attack, known as DarkSide, emerged under a new name, BlackMatter. Soon after, the cybercriminals made a glaring mistake that most likely cost them tens, if not hundreds, of millions of dollars.

Advertisement
Advertise with NZME.

Ransomware criminals encrypt a victim's data and demand a ransom payment, sometimes millions of dollars, to return access. But when BlackMatter committed a critical error in an update to its code, researchers at Emsisoft, a cybersecurity firm in New Zealand, realized they could exploit the error, decrypt files and return access to the data's rightful owners.

Emsisoft hustled to track down dozens of victims in the United States, Britain and Europe so it could help them secretly unlock their data. In the process, the firm kept millions of dollars in cryptocurrency out of the cybercriminals' coffers.

It was a short-lived victory in the cat-and-mouse game of ransomware, which is expected to cost organisations US$20 billion in losses this year, according to a report from the research firm Cybersecurity Ventures. It was so unusual, even the victims whose data was saved by the effort could not believe it. Many thought Emsisoft was running a scam.

Emsisoft officials described their operation, which has not been reported before, in a series of interviews with The New York Times.

Advertisement
Advertise with NZME.

"At first there was a lot of shock and disbelief," Fabian Wosar, the chief technology officer at Emsisoft, said last week. "Imagine you have a problem. You think it's unfixable. Everyone tells you it's unfixable. Your paranoia is in overdrive. And someone shows up at your front door and says, 'Hey, by the way I can help you.'"

A farm in Maurice, Iowa. An Iowa grain cooperative, NEW Cooperative, was hit with a ransomware assault last month. It recovered quickly, suggesting it may have had help. Photo / NYT
A farm in Maurice, Iowa. An Iowa grain cooperative, NEW Cooperative, was hit with a ransomware assault last month. It recovered quickly, suggesting it may have had help. Photo / NYT

To assuage victims' concerns, Emsisoft researchers asked their contacts at cybersecurity companies and government agencies around the world to vouch for them.

Discover more

Business

Kiwis losing millions more to cyber attacks - but reported numbers 'tip of the iceberg'

15 Sep 05:00 PM
Business

Why are our defences so shaky? The Waikato DHB ransomware attack in 20 questions

28 May 05:00 PM

While Emsisoft would not identify the victims, it said they had included key manufacturers, transportation companies and food suppliers across continental Europe, Britain and the United States.

The timeline of Emsisoft's effort overlaps with BlackMatter's ransomware assaults last month on two American agriculture organisations: NEW Cooperative, an Iowa grain cooperative, and Crystal Valley, a Minnesota farming supply cooperative. Both cooperatives recovered quickly, suggesting that Emsisoft might have helped. Neither company returned requests for comment.

Eric Goldstein, the executive assistant director for cybersecurity at the federal Cybersecurity and Infrastructure Security Agency, called the effort a model for public and private collaboration. The agency is trying to develop a comprehensive "whole of nation" plan to address cyberthreats, particularly for "critical infrastructure," most of which is owned by the private sector.

CISA recently created the Joint Cyber Defense Collaborative, which teams government agencies with tech firms like Microsoft and Amazon, telecoms like AT&T and Verizon, and cybersecurity firms like CrowdStrike and Palo Alto Networks to address threats like ransomware.

The Emsisoft operation is one of a handful of recent victories, some cursory, over ransomware. In June, the Justice Department announced that it had clawed back US$2.3 million of the US$4.4 million in cryptocurrency that Colonial Pipeline paid BlackMatter. More recently, an operation run by several governments knocked REvil, a major Russian ransomware outfit, offline. The multigovernment effort was reported earlier by Reuters.

That effort followed several smaller victories against REvil last summer. The group, which is responsible for thousands of ransomware attacks, found itself in the government's cross hairs after it pulled off a high-profile attack on JBS, one of the world's biggest meatpacking operators, and Kaseya, a Miami software company. The group used Kaseya's high-level access to its customers to hold hundreds of them hostage over this past Fourth of July holiday.

Advertisement
Advertise with NZME.

A week later, REvil's websites went dark, leading to speculation that governments may have played a role. A week after that, Kaseya announced that a mysterious "third party" had given it the key to unlock its customers' encrypted data. In fact, the FBI. later confirmed that it had secured a key but delayed giving it to Kaseya's customers while it coordinated with other agencies to take down the group. But before it could act, REvil went off-line on its own.

REvil reappeared in September, before disappearing again last week.

But recent history suggests REvil's operators could just re-emerge under a new name. As long as ransomware groups enjoy immunity in Russia and other nations, ransomware continues to plague American companies and organizations. The latest to fall victim appears to be the police in Hagerstown, Md. On Friday, the same cybercriminals who hijacked and then leaked sensitive data from the Washington, D.C., Police Department in April, claimed to have breached the Hagerstown police website and stolen the login credentials. Contacted late Friday, Hagerstown police said they did not believe that employee data was stolen, but were closely monitoring the situation and had changed passwords and taken other mitigation steps.

American cybersecurity officials concede that beyond a few brief triumphs, there has been no material shift in Russian cyberattacks since President Biden's first summit with Russia's president, Vladimir Putin, in June. Biden warned Putin that attacks on America's 16 critical infrastructure sectors — like the food suppliers hit last month — could warrant retaliation.

President Biden's summit with President Vladimir V. Putin of Russia in Geneva had little effect on Russian cyberattacks, US officials said. Photo / NYT
President Biden's summit with President Vladimir V. Putin of Russia in Geneva had little effect on Russian cyberattacks, US officials said. Photo / NYT

But last month, when BlackMatter hit NEW Cooperative, cybercriminals mocked the idea that the grain collective counted as critical infrastructure, posting sarcastically that "everyone will incur losses," in chats monitored by Recorded Future, a cybersecurity firm.

The noise around the NEW Cooperative attack created additional challenges for Emsisoft, the company said. Emsisoft had been finding BlackMatter victims through posts to a Google-owned platform, VirusTotal, which is a kind of search engine for malware.

Those posts helped link Emsisoft's teams to the chat platform that BlackMatter used to negotiate ransom payouts with its victims. Emsisoft monitored the chats to see if cybercriminals or victims dropped the name of their organization, then used that information to contact the victims.

But after NEW Cooperative's attack made headlines, unexpected visitors started leaving insults in chat rooms where BlackMatter negotiated payments. When BlackMatter threatened to leak NEW Cooperative's data online for violating its "data recovery guidelines," someone replied with an unsavory insult directed at a BlackMatter criminal's mother.

A representative for NEW Cooperative made clear in the chat that the comment had come not from them but from "random people from the internet." The exchange prompted BlackMatter to shut down access to its online chats and start vetting anyone who entered. In the process, Emsisoft lost a key way to reach the victims.

Emsisoft knew it could not publish its secret ability without tipping off BlackMatter. But the company was still able to reach several BlackMatter victims whose data had been posted online. (To add pressure, ransomware groups now post a victim's information online when it refuses to pay.) Emsisoft also worked closely with CISA and other agencies to reach as many victims as it could.

"The reason ransomware operators have gotten away with so much crime is that, until recently, there's been far too little cooperation and communication all around," said Brett Callow, a threat analyst at Emsisoft. "This shows that private/public-sector cooperation can put a significant dent in their profits."

Emsisoft knew it was running out of time. Inevitably, BlackMatter would start to wonder why so many victims stopped paying their ransoms, or why many did not even bother to respond.

Finally, last month, BlackMatter caught the mistake. It was back to the drawing board for researchers at Emsisoft and other companies.

"We are no longer really able to help victims, but we had quite a long run," Wosar said.

© 2021 The New York Times Company

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Technology

Kahu

On The Up: 'Geeks and creatives' hope award shows rangitahi they 'belong in tech'

19 Jun 03:10 AM
Premium
Business|small business

Controversial Kiwi start-up, once worth $38m, folds in New York

19 Jun 02:37 AM
Premium
Business

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Technology

On The Up: 'Geeks and creatives' hope award shows rangitahi they 'belong in tech'

On The Up: 'Geeks and creatives' hope award shows rangitahi they 'belong in tech'

19 Jun 03:10 AM

'We really have something special going on here,' the academy co-founder says.

Premium
Controversial Kiwi start-up, once worth $38m, folds in New York

Controversial Kiwi start-up, once worth $38m, folds in New York

19 Jun 02:37 AM
Premium
Fringe Benefit Tax: Should you be paying it if your business owns a ute?

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
What you need to know about Trump Mobile's ambitious phone plans

What you need to know about Trump Mobile's ambitious phone plans

17 Jun 02:04 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP