Ransomware: to pay or not to pay?

Cath Everett · Computer Fraud & Security · 2016

Woeful tales of seemingly endless ransomware attacks have been hitting the headlines for months now. One of the most notorious happened very recently – in February this year, in fact – when the Hollywood Presbyterian Medical Center in the US was crippled by crypto-ransomware. The malware encrypted the files of the Medical organisation's electronic medical records system, among others, and ended up denying staff access to patient data. The number of ransomware attacks is increasing rapidly. And so are the ways in which this attack vector is being used. Moreover, while the business model of the criminal gangs involved traditionally focused on volume and on hitting as many consumers as possible in blanket attacks, it is now becoming more targeted and moving into the more lucrative business market. So the big question for organisations is, does it make more sense to pay or not to pay? Cath Everett investigates.

Read the paper · More papers on PaperTik