Chinese shopping platform Pandabuy told BleepingComputer it previously paid a a ransom demand to prevent stolen data from being leaked, only for the same threat actor to extort the company again this week.
has worked 100% percent of the time (probably a dozen times) I’ve shepherded future clients who have called me for assistance, because all their customer information, vendor data, and billing was locked, and they didn’t have backups. if you’re fucked, you chalk it up to a business expense whether or not you get your data back. you pay the ranson, and you pray. then when you get access to your data again, you lock it down. always. everytime.
I mean news like this is the best way to stop people paying, I hope every business that doesn’t pay sends the hackers this article and says this is why
Never pay ransomware. Just write the data off. Learn how to take decent backups
Not ransomware but just ransom to data exfil by a vulnerable API. But paying is still a dumb idea.
deleted by creator
"Hi, I just sent the ransom payment to the Bitcoin address you provided.
"Now you’ll unlock my data, right?
“… right?”
has worked 100% percent of the time (probably a dozen times) I’ve shepherded future clients who have called me for assistance, because all their customer information, vendor data, and billing was locked, and they didn’t have backups. if you’re fucked, you chalk it up to a business expense whether or not you get your data back. you pay the ranson, and you pray. then when you get access to your data again, you lock it down. always. everytime.
Sure. Make it profitable to the hackers to keep doing it.
If the alternative is “likely go out of business”, then yeah…
They already made it profitable for the hackers by not backing their data up properly, this is just that bill coming due.
I mean news like this is the best way to stop people paying, I hope every business that doesn’t pay sends the hackers this article and says this is why
deleted by creator
How is someone getting control of their data by paying a ransom?
The opposing actor still has your data, so it doesn’t really matter how much you pay, you’ll never be able to mitigate that security issue, surely?
deleted by creator
i didn’t read the article, for stolen data, you’re hosed. deleted.