Connect with us

News desk

Stuck in cyberattack nightmare? Call the negotiators

Published

on

A message on LockBit's site said law envorcement agencies had taken it over
Share this:

Criminals have overtaken your computer network, they are threatening to leak your most sensitive secrets and your share price is tumbling. It’s time to call in the negotiators.

They might not wear capes, but this new breed of mediator — who often has had prior careers in law enforcement and intelligence — is increasingly on hand to help in such a nightmare scenario.

Britain’s National Crime Agency (NCA) and law enforcement partners from several other countries announced Tuesday that they had smashed the cybercrime giant LockBit, whose ransomware attacks have caused billions of dollars of damage and stolen tens of millions from victims.

The gang had targeted governments, major companies, schools and hospitals since 2020.

Institutions of all shapes and sizes are still prey to the growing criminal threat, though.

In a ransomware attack, gangs — sometimes state-backed — hack into networks and demand payment either to unlock the system or prevent the release of top-secret data.

While cybercrime may conjure up images of lawless bandits operating in a world of anarchy, they are usually rational actors, according to Ram Elboim, CEO of US-based cybersecurity company Sygnia.

“It’s not the Wild West, where people just shoot everywhere. Ransomware is a business. It’s a huge economy,” he told AFP during a London visit.

Elboim’s company responds to desperate requests from clients under attack, often Fortune 500 companies, by setting up a team and jetting in to take on the criminals.

– ‘Gun to your business’ –

Integral to this team are the negotiators, who use their experience of dealing with “real-world” criminals to act as a go-between with online crooks, either helping foil the attack, or working out a price if all else fails.

“Usually we get a call, usually it happens on a weekend or the middle of the night. This is the time where organisations let down their awareness,” said Elboim.

The first tasks are to understand the nature of the attack, how the attacker got into the network, what systems are down, how to contain the spread and recover any lost data.

“Then there is a negotiation piece,” said Elboim, a former member of Israel’s military intelligence unit known as “8200”.

“You’re talking with a criminal — it’s not a criminal who pulls a gun to your head, but there’s a criminal holding a gun to your business.

“Usually, we advise you to start negotiations as soon as possible.

“If your only goal is to reduce the price from $50 million to $48 million then… just a good salesperson can do that.

“But usually attackers have some kind of a deadline, pay within 72 hours. The goal of the negotiation is to allow yourself more time to recover.”

Another goal is to understand what the attackers are looking for and if you can attribute the attack to a specific group.

This is when the negotiators’ expertise comes to the fore, setting up a channel of communication — usually via a chat app or email — and squeezing information from the criminals.

“It’s not as if the attacker will give you information freely,” said Elboim.

– Great reward –

In the best-case scenario, “we drag on the negotiations” for long enough and glean enough information to kick out the attackers and retrieve the data.

“After a few days of this game, the organisation can just… tell the hacker ‘I’m not paying, do whatever you want’.”

In the worst case, when the system appears lost and with crucial data about to be leaked, many institutions then have to decide whether to pay.

“Some organisations do not want to pay on principal. In some cases, the organisation is willing to pay but not willing to pay so much,” with negotiators then haggling over a price.

Even if they pay the ransom and the network is decrypted, it is not plain sailing but rather the beginning of a long recovery process.

Attackers may promise not to attack again for a certain period of time, but there is no guarantee that the network is safe.

“We even had one case where we had a discussion with one attacker and he says ‘okay, I move away’ and then another came in and it’s for sure they exchanged information, they knew everything the first one did,” recalled Elboim.

But the rewards for a successful mission are great, he added.

“We had an attack… and the entire company was out, and this is a multinational organisation.”

After repelling the attackers, “one of the guards at the entrance stopped us and said: ‘Thank you for rescuing my work, now, I will not be hungry’.

“This is one of the most satisfying moments you can have.”

Share this:

News desk

EU says Apple iPad operating system to face stricter rules

Published

on

By

Apple has six months to prepare to comply with the EU's Digital Markets Act
Share this:

The EU on Monday said Apple’s operating system for iPads must comply with tougher new rules that Brussels is imposing to rein in the world’s biggest digital companies.

The European Commission designated Apple’s iPadOS system as a “core” service under the landmark Digital Markets Act (DMA), which forces companies to modify their business ways to encourage competition between online platforms.

It joins other Apple products that were already in the DMA net since September: iOS for iPhones, the App Store, and the Safari browser.

Under the DMA, digital firms designated as “gatekeepers” have to abide by a list of rules including allowing interoperability with rivals’ communication services and limiting how data is shared between products put out by the same parent company.

Apple is on the gatekeepers list, alongside the likes of Google parent Alphabet, Amazon, TikTok owner ByteDance, Meta and Microsoft. 

– EU-Apple tussle –

The inclusion of iPadOS as a core service adds to a long tussle between the European Union and Apple over the bloc’s new digital laws.

Apple has been one of the DMA’s most vocal public critics. It claims the law ushers in privacy and security threats for users.

The commission, the EU’s powerful competition regulator, said it named the iPadOS system because it locked users into the iPad operating system.

“Apple leverages its large ecosystem to disincentivise end users from switching to other operating systems for tablets,” it said.

The operating system also “locked-in” Apple’s business users, it said, “because of its large and commercially attractive user base, and its importance for certain use cases, such as gaming apps”.

Apple has six months to comply with the DMA gatekeeper rules, the commission said in a statement.

“Today’s decision will ensure that fairness and contestability are preserved also on this platform, in addition to the 22 other services we designated last September,” the EU’s competition commissioner, Margrethe Vestager, said.

Apple said in a statement after the announcement that it would “continue to constructively engage with the European Commission to comply with the DMA, across all designated services”.

It added: “Our focus will remain on delivering the very best products and services to our European customers, while mitigating the new privacy and data security risks the DMA poses for our users.”

Apple already faces a commission investigation under the DMA.

In March, Brussels said it would probe whether Apple’s App Store allows developers to present users with offers outside of its app marketplace, free of charge.

Share this:
Continue Reading

News desk

TikTok creators fear economic blow of US ban

Published

on

By

The appetite for short-form video online is expected to remain strong even if TikTok is banned in the United States, boding well for rival platforms
Share this:

Ayman Chaudhary turned her love for reading into a living on TikTok, posting video snippets about books like those banned in schools in ultra-conservative parts of the United States.

Now the online platform she relies on to support her family is poised to be banned in what entrepreneurs using TikTok condemn as an attack on their livelihoods.

“It’s so essential to small businesses and creators; it’s my full-time job,” the 23-year-old Chicago resident told AFP.

“It makes me really worried that I live in a country that would pass bans like these instead of focusing on what’s actually important, like gun control and healthcare and education.”

A new US law put TikTok’s parent, Chinese tech giant ByteDance, on a nine-month deadline to divest the hugely popular video platform or have it banned in the United States.

US lawmakers argued that TikTok can be used by the Chinese government for espionage and propaganda as long as it is owned by ByteDance.

“Everybody who’s involved in deciding whether or not this platform is going to get banned is turning a blind eye to how it’s going to affect all of the small businesses,” said Bilal Rehman of Texas. 

His @bilalrehmanstudio TikTok account, which playfully promotes his company’s interior design projects, has some 500,000 followers.

“They don’t really understand social media and how it works,” the 24-year-old added.

TikTok has gone from a novelty to a necessity for many US small businesses, according to an Oxford Economics study backed by the platform.

TikTok fuels growth for more than seven million businesses in the United States, helping generate billions of dollars and supporting more than 224,000 jobs, the study determined.

“It’s become such a huge part of our economy that taking that away is going to be devastating to millions of people,” Rehman said of TikTok.

Chaudhary took to TikTok to share her passion for reading in early 2020 while enduring Covid-19 lockdowns.

“I made a handful of videos and, long story short, one went viral,” Chaudhary said.

Opportunities to make money from sponsors or advertising came as her audience grew, and posting on her @aymansbooks TikTok account became a job.

She saw books she extolled snapped up by readers, as she shined attention on titles banned from schools or libraries in parts of the country.

– Unique vibe –

A TikTok ban would be a particularly hard blow to businesses just starting out, according to eMarketer analyst Jasmine Enberg.

“Social media has democratized the commerce landscape, and TikTok really supercharged that,” Enberg told AFP.

“It’s become a crucial platform for many small businesses, especially those that are in niche industries or sell quirky products.”

One factor setting TikTok apart from rival platforms is the potential for videos to be spread quickly by a highly engaged audience, according to Enberg.

“The potential to be discovered on TikTok is really unparalleled, and that’s largely thanks to its algorithm as well as the entertaining kind of content that it hosts,” she said.

A young generation is using TikTok as a search engine of sorts, making queries as they might on Google and seeing what the algorithm serves up, said SOCi director of market insights Damian Rollison.

“It feels like it has been created by your peers, so they’re telling you the real deal about whatever the topic might be,” Rollison said of the trend.

TikTok lovers say it has a unique style that will be missed in the case of a ban.

“There is definitely a different vibe on TikTok versus YouTube or Instagram,” said Chaudhary.

“TikTok has a lot more humor in it and a lot more creativity than I see happening on Instagram.”

“My favorite part about TikTok is, it feels almost like you’re on a FaceTime call with your friend,” Rehman said.

“It feels really raw and authentic.”

Rollison advised businesses relying on TikTok to make contingency plans in event of a ban, sticking with short-form video, given the appetite for such content.

“The demand signals are so powerful amongst younger users that I believe the usage patterns are going to survive any of the outcomes,” Rollison said.

“Learning that ecosystem is not only a useful but even critical strategy.”

Share this:
Continue Reading

News desk

Cybersecurity firm Darktrace accepts $5 bn takeover

Published

on

By

Darktrace chief executive Poppy Gustafsson (L) said the group's 'technology has never been more relevant in a world increasingly threatened by AI-powered cyberattacks'
Share this:

Cybersecurity firm Darktrace said Friday it had accepted a $5.3-billion takeover bid from US private equity firm Thoma Bravo, which highlighted the British group’s “capability in artificial intelligence”.

The cash bid comes after Thoma Bravo expressed takeover interest two years ago.

“Darktrace is at the very cutting edge of cybersecurity technology, and we have long been admirers of its platform and capability in artificial intelligence,” Thoma Bravo partner Andrew Almeida said in a statement.

“The pace of innovation in cybersecurity is accelerating in response to cyber threats that are simultaneously complex, global and sophisticated.”

Darktrace chief executive Poppy Gustafsson said the group’s “technology has never been more relevant in a world increasingly threatened by AI-powered cyberattacks”.

Darktrace, headquartered in the university city of Cambridge close to London, floated on the London stock market in 2021.

The cash deal announced Friday is worth $7.75 dollars per Darktrace share — a 44 percent premium on the group’s average share price in the last three months, according to Thoma Bravo.

Following the announcement, the share price surged 18 percent to 612 pence ($7.7).

Created in 2013, Darktrace employs more than 2,300 people around the world.

“The proposed acquisition will provide Darktrace access to a strong financial partner in Thoma Bravo, with deep software sector expertise, who can enhance the company’s position as a best-in-class cyber AI business headquartered in the UK,” Darktrace chair Gordon Hurst said in the statement.

The pair hope to complete the deal in the second half of the year thanks to shareholder and regulatory approval.

Almeida noted that Thoma Bravo has invested “exclusively in software for over twenty years” which would allow it to bring “operational expertise and deep experience of cybersecurity in supporting Darktrace’s growth”.

Prior to Friday’s announcement, shares in Darktrace has bounced back strongly after the company was cleared by independent auditors EY of having irregularities in its accounts.

Explaining its decision to go private, Darktrace said its “operating and financial achievements have not been reflected commensurately in its valuation with shares trading at a significant discount to its global peer group”.

– Takeover boom – 

The bid comes at the end of a week in which the London stock market has been gripped by takeover activity, helping the top-tier FTSE 100 index to record highs.

British mining giant Anglo American on Friday rejected a blockbuster $38.8-billion takeover bid from Australian rival BHP, slamming it as “highly unattractive” and “opportunistic”.

A battle to buy UK music rights owner Hipgnosis Songs Fund meanwhile took a fresh twist after US rival Concord increased its takeover offer, slightly beating a bid by Blackstone. 

Concord on Wednesday offered $1.5 billion for Hipgnosis, whose catalogue includes Justin Bieber, Shakira and Neil Young.

This is more than its original $1.4 billion offer that preceded a higher bid from US asset manager Blackstone.

Share this:
Continue Reading

Featured