The Threat of Ransomware 2.0 for Law Practices
A significant paradigm shift in the cybersecurity world has seen threat actors with significantly enhanced capabilities to target individual businesses and managed service providers (MSPs) or IT companies.
February 19, 2020 at 10:00 AM
5 minute read
This article appeared in Cybersecurity Law & Strategy, an ALM publication for privacy and security professionals, Chief Information Security Officers, Chief Information Officers, Chief Technology Officers, Corporate Counsel, Internet and Tech Practitioners, In-House Counsel. Visit the website to learn more.
During the past few months, there has been a significant paradigm shift in the cybersecurity world. Threat actors from Russia, in particular, have significantly enhanced their capabilities to target individual businesses and managed service providers (MSPs) or IT companies. As of late December, hacking groups such as Sodinokibi (aka "Evil Corp") and Ryuk have been impacting thousands of businesses across the United States in a multitude of ways. It is critical that lawyers, their firms and the companies they serve be aware of these threats and take the appropriate measures to proactively secure their own—and their clients'—sensitive and private information.
|Tracking Major Recent Ransomware Attacks
Approximately 16 months ago, the FBI and Department of Homeland Security warned MSPs that certain threat actors were planning large-scale attacks against them. In August of 2019, we saw the largest distributed ransomware attack encrypt and hold hostage the data of approximately 450 businesses and impact thousands of computers and servers. During Thanksgiving week, they hit 100 businesses and then, on December 24, approximately 1,300 businesses were victims.
The ransomware encrypted almost every computer, server, external backup, cloud backup, etc., resulting in the inability to access a single file. Think about this for a minute. The second largest attack in our nation's history was against small and medium-sized businesses; not banks, large corporations or hospitals.
How does something like this happen? It is simple. The threat actors gain access to the IT company's remote management tools that they use to access a law practice's computers and servers, load their malicious code into the tool and instruct the tool to download and install the ransomware into all the computers. Within minutes, they can strike tens of thousands of computers. These attacks typically occur during the early morning hours, so the first indicator of the attack is employees' inability to log in and access any information on the computers. The result is literally every single file and database is encrypted with ransomware.
|Breaking Down the Fallout of a Ransomware Attack
Based on some of the most recent ransomware attacks, most businesses experienced a two- to four-week outage. In every case that we handled, the business experienced 100 percent encryption on every device and backup. Due to the pervasiveness of the ransomware attacks, there was no recovery option except to pay the threat actors the ransom payment. Most businesses had to pay, on average, $45,000 to the threat actors for a decryption tool. Add on top of that, the business interruption, inability to collect A/R or access critical business files and the complete rebuilding of every computer and server. The price tag for these attacks easily exceeds $100,000 for a small business and significantly more for a medium-sized business.
The financial burden that ransomware attacks place on law firms and other similarly-sized businesses is only made worse with the time lost from being able to access critical client information or operate a business effectively. Losing access to a computer system for two to four weeks is nightmarish for most victims. One business owner described the effects of the attack: "It was like driving into my office parking lot only to find the foundation of my office left. Everything else was gone."
|The Threat of Losing Client Trust
Unfortunately, hackers are only getting more malicious in their ransomware attacks. In December 2019, threat groups Sodinokibi, Ryuk and Maze announced that they were getting into the data theft and extortion business. As a means to ensure a ransom payment from the victim, these companies modified their malicious code to first steal (exfiltrate) all the data then encrypt it. This means that if their victims refuse to pay the ransom, the threat actors will release the data to a public website.
In December, this is exactly what happened in Pensacola, FL. The city refused to pay the ransom and the threat actors published two gigabytes of data. This is a terrible predicament for the law practices and the greater business community. Even if your practice takes the precaution to have valid backups and can recover from the attack, the data may still be released if you fail to pay the ransom demand. Imagine your client files, M&A documents, PII (collection firms), IP, client bank account information, real-estate transactions, corporate trade secrets, financials, proprietary corporate information, information on publicly traded companies, etc., showing up on the internet. This would be a total PR nightmare for your firm and result in your practice's reputation suffering greatly.
|Taking Steps to Protect Your Practice
What can you do to protect yourself, your firm and your clients? First, ask your MSP to provide documentation that its network is being independently audited and evaluated by a cybersecurity company to help prevent these types of attacks. Second, and now more than ever, firms need to take a proactive approach to security. Keep in mind that almost all of your colleagues impacted by these attacks have a MSP, firewall, anti-virus software and the "promise" of being protected. But they all lacked the expertise and advice of a dedicated cybersecurity company. The risk is just too great to not enhance the security posture of your firm by utilizing the advanced tools of a cybersecurity company.
Gary Salman is CEO of Black Talon Security, a Katonah, NY-based company specializing in cybersecurity solutions for firms and businesses. He has nearly 30 years of experience in information technology and software design. Gary also lectures locally and nationally on various topics related to cybersecurity.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
- 1Judge Denies Sean Combs Third Bail Bid, Citing Community Safety
- 2Republican FTC Commissioner: 'The Time for Rulemaking by the Biden-Harris FTC Is Over'
- 3NY Appellate Panel Cites Student's Disciplinary History While Sending Negligence Claim Against School District to Trial
- 4A Meta DIG and Its Nvidia Implications
- 5Deception or Coercion? California Supreme Court Grants Review in Jailhouse Confession Case
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250