Newly published threat intelligence from BlackBerry has confirmed what we already knew: critical infrastructure is under attack. And at the same time, the UK government has declared its intention to make it illegal for organisations running such infrastructure to pay ransoms.
Let’s examine the scale of the problem first. Between July and September 2024, BlackBerry said it had detected 600,000 attacks against critical infrastructure, with 45% targeting the financial sector.
Itโs essential to understand that this doesnโt mean 600,000 successful attacks. Instead, it means BlackBerry detected malicious hashes used in attempted attack scenarios against the customers it protects.
Innovative malware is often used against critical infrastructure operations in these highly targeted attacks, with threat actors investing considerable resources in their attempts. If successful, these “small” attacks can have a huge impact.
“Our attack surface has never been wider, with threat actors and nation-states broadening their horizons into cyber espionage attacks, while ransomware groups are becoming more sophisticated in their campaigns,” warned Ismael Valenzuela, Vice President of Threat Research & Intelligence at BlackBerry.
And that talk of ransomware brings me to the UK government.
UK government to make ransomware payments illegal
On Tuesday, the UK government announced proposals that would make it illegal for public sector and critical infrastructure organisations to pay ransoms.
The Home Office said that it wants to meet three objectives with this ransomware payment ban:
- Reduce the amount of money flowing to ransomware criminals from the UK, which would act as a deterrent to criminal gangs from attacking UK organisations in the future.
- Increase the ability of operational agencies to disrupt and investigate ransomware gangs, using increased โintelligence around the ransomware payment landscapeโ.
- Enhance the governmentโs understanding of the threats in this area to inform future interventions.
To be honest, the second and third of those sound pretty much the same from where I am sitting. The first? Well, itโs a nice thought.
While I am only too aware that a blanket ban on ransom payments sounds good on paper, itโs a different beast out there in the real world of business. A world when a balance must be struck between ethical/legal considerations and being able to continue trading. That may sound controversial, but itโs the harsh truth.
Andrew Whaley, Senior Technical Director of Promon, said: โLegislation is ultimately the last lever a government can pull, which might suggest the UK has half given up in its fight against ransomware gangs. Only through investment in technology, training, and cybersecurity awareness will the UK stand a chance of tackling the root cause of the problem.โ
Whaley is not wrong, but a legal ransomware payment ban could help reduce the attack map because it organisations would then have to take the threat more seriously – and put measures in place to better defend themselves from the threat in the first place.
And Iโm not alone in thinking this. โBanning the payment of ransoms for organisations, such as NHS trusts, schools and councils, sends a clear and much needed signal to hackers,โ said Simon Jelley, GM & VP of Product at Arctera, “but it may have the unintended consequence of putting massive pressure on these government organisations to implement strategies and technology to upgrade their lagging IT infrastructure and ensure high standards of data classification, management, protection and recovery.โ
More ransomware articles by Davey Winder