Ahead of Hearing, House Oversight Committee Releases New Staff Memo on Ransom Attacks on U.S. Companies
In
Today's supplemental memo reveals the findings of the Committee's investigation, including:
1. Small lapses led to major breaches. Ransomware attackers took advantage of relatively minor security lapses, such as a single user account controlled by a weak password, to launch enormously costly attacks. Even large organizations with seemingly robust security systems fell victim to simple initial attacks, highlighting the need to increase security education and take other security measures prior to an attack.
2. Some companies lacked clear initial points of contact with the federal government. Depending on their industry, companies were confronted with a patchwork of federal agencies to engage regarding the attacks they faced. For example, two companies' initial requests for assistance were forwarded to different FBI offices and personnel before reaching the correct team. Companies also received different responses on which agencies could answer questions as to whether the attackers were sanctioned entities. These examples highlight the importance of clearly established federal points of contact.
3. Companies faced pressure to quickly pay the ransom. Given the uncertainty over how quickly systems could be restored using backups and whether any sensitive data was stolen, the companies appeared to have strong incentives to quickly pay the ransom. This pressure was compounded by attackers' assurances that payment of the ransom would resolve the situation and avoid negative publicity for the company. For instance, after the initial hack of JBS, REvil told the company, "We can unblock your data and keep everything secret. All we need is a ransom." Further examination is needed of the factors encouraging ransom payments, including the role of cyber insurance and the costs companies can face even after paying a ransom, especially when the cybercriminals fail to deliver on their promises.
Click here (https://oversight.house.gov/sites/democrats.oversight.house.gov/files/20211116%20Supplemental%20Memo%20on%20CORs%20Investigation%20into%20Ransomware.pdf) to read today's memo.
Click here (https://www.youtube.com/watch?v=7uDtso_jpPo) to watch the Committee hearing.



Pa. House Republicans: House Insurance Committee Advances Consumer-Friendly Legislation, Says Pickett
Cancer Action Network: North Carolina Legislature Leaves More Than 372,400 North Carolinians Without Access to Health Coverage
Advisor News
- The untapped potential of Qualified Longevity Annuity Contracts
- NYC's fiscal outlook on downslide over budget gaps
- Health insurance premium tax bill moving in Iowa House
- Rising health care costs drive sharp increase in retirement anxiety
- Health insurance premium tax bill moving in House
More Advisor NewsAnnuity News
- An Application for the Trademark “GREAT-WEST LIFE & ANNUITY INSURANCE COMPANY” Has Been Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
- The forces shaping life and annuities in 2026
- Variable annuity sales surge as market confidence remains high, Wink finds
- New Allianz Life Annuity Offers Added Flexibility in Income Benefits
- How to elevate annuity discussions during tax season
More Annuity NewsHealth/Employee Benefits News
- Data on Pain and Central Nervous System Reported by Researchers at National Health Insurance Service (Unintended Consequences of Expanded Magnetic Resonance Imaging Reimbursement: A Nationwide Analysis Revealing Low Clinical Efficiency): Pain and Central Nervous System
- Studies Conducted at Harvey L. Neiman Health Policy Institute on Managed Care Recently Reported (Increasing-Yet Varying-Radiologist Workforce Attrition Across Subspecialties): Managed Care
- Researchers at University of Pittsburgh Release New Data on Insurance (Distributed fusion R-learner of heterogeneous treatment effect using distributed medicaid data): Insurance
- Brooklyn nurses lose health care for weeks despite $15M from state
- Prime Healthcare’s hospitals could soon be out-of-network for Blue Cross and Blue Shield of Illinois members
More Health/Employee Benefits NewsLife Insurance News
- Oaktree grabs control of Atlantic Coast Life Co. in blockbuster A-Cap deal
- AM Best Removes From Under Review With Developing Implications and Downgrades Credit Ratings of Banner Life Insurance Company and William Penn Life Insurance Company of New York
- The forces shaping life and annuities in 2026
- Advantage Capital Holdings, LLC and Oaktree Sign Master Transaction Agreement
- PHL Variable liquidation: Regulators, investors pivot legal fire to Nassau
More Life Insurance News