Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 18 submissions in the queue.
posted by jelizondo on Sunday July 27 2025, @05:37PM   Printer-friendly
from the still-vulnerable dept.

Arthur T Knackerbracket has processed the following story:

The country also wants to force businesses to inform the government when they plan to make a ransom payment.

Ransomware gangs might have to scratch a few targets off their lists. The UK High Office and National Cyber Security Centre (NCSC) announced proposals to ban ransom payments in an effort to "crack down on cyber criminals and safeguard the public."

According to the announcement, the proposals would prohibit "public sector bodies and operators of critical national infrastructure, including the [National Health Service], local councils and schools," from making ransomware-related payments. They would also require other businesses planning to pay a ransom to notify the UK government so it can "provide those businesses with advice and support" before the payment is made. (Including a heads-up if such a payment would violate sanctions on Russia.)

The proposals wouldn't require companies to inform the UK government of a ransomware attack if they didn't plan to pay the ransom. But the announcement indicated that a mandatory reporting policy is in the works, too, in a bid to "equip law enforcement with essential intelligence to hunt down perpetrators and disrupt their activities" and "better protect British organisations and industry." That should make it more difficult to deploy ransomware in the UK without risking law enforcement's ire.

"The new package of measures will lead the way in tackling ransomware and are designed to strike against cyber criminals’ business model, bolstering our national security and protecting key services and businesses from disruption - delivering on our Plan for Change," the Home Office and NCSC said in the announcement. "They follow an extensive consultation with stakeholders across the UK, which showed strong public backing for tougher action to tackle ransomware and protect vital services."

The UK and Singapore previously said in January 2024 that they "strongly discourage anyone from paying a ransomware demand" because doing so:

  • Does not guarantee the end of an incident, or the removal of malicious software from your systems
  • Provides incentives for criminals to continue and expand their activities
  • Provides funds that criminal actors can use for illicit activity
  • Does not guarantee you will get your data back

Now the UK is looking to outright ban those payments rather than merely "strongly discouraging" them. The news follows reports earlier this week that a 158-year-old UK company was forced to shut down following a ransomware attack, at the cost of 700 jobs.

"Cyber criminals have not only cost the nation billions of pounds but in some cases have brought essential services to a standstill," the Home Office and NCSC said. "The devastating consequences are not just financial but can put lives in danger, with an NHS organisation recently identifying a ransomware attack as one of the factors that contributed to a patient’s death. These attacks have brutally exposed the alarming vulnerability at the core of our public and private institutions, from flagship British retailers and essential supermarkets including the Co-op to NHS hospitals."


Original Submission

This discussion was created by jelizondo (653) for logged-in users only, but now has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 4, Insightful) by looorg on Sunday July 27 2025, @06:17PM (2 children)

    by looorg (578) on Sunday July 27 2025, @06:17PM (#1411750)

    Will that even work or matter? After all most governments doesn't negotiate with terrorists, pays ransoms etc. They have someone else do it on their behalf. Preferably with a minimum of ties to them. You might not be able to get "ransomware" insurance. But you will, it will just be called something else. The funds will be kept in some other country that can deal with such issues. Just have a look at the whole "kidnap and ransom insurance business", living in its own little ecosystem. This is that. Just for computers and data instead of people.

    One would think if they all stopped paying this would go away. But it won't, in both cases -- they'll keep paying cause they had shit security and have no secure backups. The scumbags keep extorting cause it's almost risk free and they do get paid. It's like spam and scams. Some idiots, somewhere click and buy and think they have won millions from their Nigerian prince friend they have never heard from before or they just keep traveling to hellhole countries run by gangs that kidnap people for fun and profit.

    • (Score: 2) by aafcac on Sunday July 27 2025, @08:43PM

      by aafcac (17646) on Sunday July 27 2025, @08:43PM (#1411765)

      That's hard to say, but if they do have any luck with it, there will likely be an extremely painful period of adjustment for everybody that's being banned from paying. I think how well this works is going to depend a lot on how effectively they can get at those back channel payments schemes and get everybody on board with actually securing their stuff. The best case is probably for everybody not in something like medicine or banking to stop keeping so much sensitive information that could lead to being targeted in this fashion.

    • (Score: 0) by Anonymous Coward on Sunday July 27 2025, @11:27PM

      by Anonymous Coward on Sunday July 27 2025, @11:27PM (#1411772)

      hellhole countries run by gangs that kidnap people for fun and profit

      Yeah, too bad that industry is completely globalized now. No place left to run anymore.

  • (Score: 2) by VLM on Monday July 28 2025, @05:15PM

    by VLM (445) on Monday July 28 2025, @05:15PM (#1411831)

    I think this will open some doors for financial fraud while closing other doors. Interesting to think about.

    Another interesting trend: Consider a powned local fileserver vs a cloud provider with extensive auditing, versioning, rollback abilities, etc. If your "fileserver" is Google Workspace "business plus" tier, you pretty much laugh at the idea of ransomware? The idea of not storing files anywhere but in the synced cloud might become more popular. Much as businesses have pretty much given up on running their own mail servers or running their own active directory servers, fileservers might be next on the block. Businesses have repeatedly for decades proven themselves utterly incompetent at storing files locally... Regardless if its a "good idea" or not, this might be coming our way.

(1)