When the negotiators go bad!

Every ransomware incident runs on one uncomfortable assumption: that the people you bring in to help are actually on your side. A case that concluded in a Florida federal court this month blew a hole straight through that assumption. Three cyber professionals — two of them ransomware negotiators whose day job was to defend victims — have been sentenced for working as an affiliate crew of the ALPHV/BlackCat operation. One of them didn’t just moonlight as an attacker; he sold out the very clients who were paying him to protect them.

This is not another “big scary ransomware gang” story. It’s an insider-threat story, and it lands right in the middle of the incident-response industry itself. If you run an IR practice, negotiate on behalf of victims, broker cyber insurance, or you’re a CISO who will one day have to trust one of these firms on the worst day of your career — this one is worth your time.

Read more “When the negotiators go bad!”

Using shame to enable extortion

When we look at ‘sextortion’ and ’email based extortion’ tactics used by threat actors we see a common pattern, one that leverages shame & fear. I’ve worked with some victims of this and it’s really not nice for them, the impacts are not just financial, they are emotional and sometimes more. It’s fortunately (for me) don’t however deal with this in volume, however I wanted to highlight something, the similarities between extortion and what I would describe as ‘Security Scanning’ shame scamming. Now you might think, that’s a massive leap… but bear with me, I’ve been looking at this (CTI/OSINT) plus working with ‘victims’ for years…

I’ll be posting about some research I’ve done on DNSSEC shortly too, I’ve kind of figured this topic was over years ago, but it’s recently come back on my radar, you know sometimes ‘duty calls’. But let’s look at shame based extortion patterns for now:

Read more “Using shame to enable extortion”