The US National Security Council organized virtual meetings this week to discuss countering ransomware operators. In total, 30 countries were invited to the conference, including Ukraine, Mexico, Israel, Germany, and the UK, however, Russia and China were not invited to the discussion.
The cyber threat posed by ransomware is increasingly worrying people at the highest level. The ransoms have already reached over $400 million in 2020 and $81 million in the first quarter of 2021.
US President Joe Biden announced in early October that representatives from more than 30 countries will work together to fight back against cybercriminals distributing ransomware. This initiative was the result of very dangerous and large-scale attacks by ransomware operators that recently hit Colonial Pipeline and Kaseya.
It is interesting to note that recently Russian Deputy Foreign Minister Sergei Ryabkov made it clear that Moscow is interested in discussing the problem of ransomware viruses with Washington, but does not want contacts to be limited only to this topic. “American colleagues are still trying to focus all their work on what interests them,” he complained at the time.
Despite the previously announced cooperation in the field of cybersecurity between Moscow and Washington, no one expected Russian official representatives at the meetings. The organizers of the meetings did not invite China and Russia.
Perhaps the reason lies in a misunderstanding that arose at a certain stage. The United States has repeatedly asked Russia to take measures against ransomware operators located in the country. White House Press Secretary Jen Psaki even promised that Washington itself would deal with these cyber groups if the Kremlin could not.
After a targeted attack, large businesses lost an average of $695,000, while small and medium businesses lost almost $32,000.
Kaspersky Lab experts have studied the cyberattacks that Russian companies have been subjected to since the beginning of the year. The collected statistics helped to identify the most dangerous type of data hacking for businessmen. The greatest damage was caused by targeted attacks.
The experts explained that these are pre-planned attacks, when attackers “purposefully attack a specific company”, having previously conducted reconnaissance and selected tools for the attack. On average, after such an attack, large businesses lost $695,000, while small and medium businesses lost $32,000 this year.
In addition, the damage to Russian business in 2021 was caused by “the illegal use of IT resources by employees.” Kaspersky Lab experts also attributed such cases to cyber incidents. The losses caused by them reached nearly $510 thousand for large companies and $30 thousand for small ones.
A little less business suffered in cases when employees did not comply with the internal information security policy. In such incidents, according to the study, the damage for a large organization was $465 thousand, and for a small one — almost $30 thousand.
DDoS attacks, according to Kaspersky Lab, in turn, deprived large businesses of $463 thousand, and owners of small companies — more than $28 thousand.
At the end of May, Kaspersky Lab announced that the new attacks differ from cyberattacks using encryption viruses in that the scammers do not use specially created malware, but the standard BitLocker Drive Encryption technology included in the Windows operating system. Several Russian companies have been hit by ransomware attacks that have blocked access to corporate data and demanded a ransom.