Ahead of Hearing, Committee Releases New Staff Memo on Ransom Attacks on U.S. Companies
Ahead of Hearing, Committee Releases New Staff Memo on Ransom Attacks on
Committee Investigation Includes Cyber Attacks on
In
Today's supplemental memo reveals the findings of the Committee's investigation, including:
*Small lapses led to major breaches. Ransomware attackers took advantage of relatively minor security lapses, such as a single user account controlled by a weak password, to launch enormously costly attacks. Even large organizations with seemingly robust security systems fell victim to simple initial attacks, highlighting the need to increase security education and take other security measures prior to an attack.
*Some companies lacked clear initial points of contact with the federal government. Depending on their industry, companies were confronted with a patchwork of federal agencies to engage regarding the attacks they faced. For example, two companies' initial requests for assistance were forwarded to different FBI offices and personnel before reaching the correct team. Companies also received different responses on which agencies could answer questions as to whether the attackers were sanctioned entities. These examples highlight the importance of clearly established federal points of contact.
*Companies faced pressure to quickly pay the ransom. Given the uncertainty over how quickly systems could be restored using backups and whether any sensitive data was stolen, the companies appeared to have strong incentives to quickly pay the ransom. This pressure was compounded by attackers' assurances that payment of the ransom would resolve the situation and avoid negative publicity for the company. For instance, after the initial hack of JBS, REvil told the company, "We can unblock your data and keep everything secret. All we need is a ransom." Further examination is needed of the factors encouraging ransom payments, including the role of cyber insurance and the costs companies can face even after paying a ransom, especially when the cybercriminals fail to deliver on their promises.


AM Best Revises Outlooks to Positive for Lewer Life Insurance Company
MetLife CEO Michel Khalaf and CFO John McCallion to Speak at the Goldman Sachs 2021 US Financial Services Conference
Advisor News
- House panel advances CLEAR Forms Act backed by IRI
- Modifying life insurance based on evolving needs
- Gen X faces ‘pension envy’ as they head into retirement
- Your client wants to cash out an annuity. Here’s what to consider
- How student loan debt impacts 401(k) balances
More Advisor NewsAnnuity News
- A-Cap strikes back with lawsuit accusing SC regulators of sloppy process, leaking secrets
- AM Best to Discuss Its Views on Private Credit Surge and Risks at 2026 NAIC/NIPR Insurance Summit
- OID recovers $260M in life insurance benefits
- NUNN BILLS TO COMBAT PAYMENT SCAMS, CUT FINANCIAL RED TAPE PASS FINANCIAL SERVICES COMMITTEE
- SS&C Black Diamond Expands Annuities & Insurance Marketplace with New Insurance Capabilities and Carriers
More Annuity NewsHealth/Employee Benefits News
Life Insurance News