.

  • Written by Roberto Musotto, Research Fellow in Cyber Security and Law, Edith Cowan University
Ransomware attacks are becoming increasingly complex, as hackers find creative ways to beat ordinary systems of defence. christiaancolen/flickr, CC BY

In recent weeks, Johannesburg’s computer network was held for ransom by a hacker group called Shadow Kill Hackers. This was the second time in three months a ransomware attack has hit South Africa’s largest city. This time, however, hackers didn’t pose the usual threat.

Rather than denying the city access to its data, the standard blackmail in a ransomware attack, they threatened to publish it online. This style of attack, known as leakware, allows hackers to target more victims in a single attack – in this case the city’s citizens.


Read more: What is ransomware and how to protect your precious files from it


The latest Johannesburg attack was the second leakware attack of this type ever recorded, and a similar attack could hit Australia soon. And although our current cyberattack defences are more advanced than many countries, we could be taken by surprise because of the unique way leakware operates.

A new plan of attack

During the Johannesburg attack, city employees received a computer message saying hackers had “compromised all passwords and sensitive data such as finance and personal population information”. In exchange for not uploading the stolen data online, destroying it and revealing how they executed the breach, the hackers demanded four bitcoins (worth about A$52,663) - “a small amount of money” for a vast city council, they said.

The hacker group operated a Twitter account, on which they posted a photo showing the directories they had access to. ShadowKillGroup/twitter

In this case, access to data was not denied. But the threat of releasing data online can put enormous pressure on authorities to comply, or they risk releasing citizens’ sensitive information, and in doing so, betraying their trust.

The city of Johannesburg decided not to pay the ransom and to restore systems on its own. Yet we don’t know whether the data has been released online or not. The attack suggests cybercriminals will continue to experiment and innovate in a bid to defeat current prevention and defence measures against leakware attacks.

This login screen message was displayed on computers in Johannesburg following the attack. pule_madumo/twitter

Another notable leakware attack happened a decade ago against the US state of Virginia. Hackers stole prescription drug information from the state and tried obtaining a ransom by threatening to either release it online, or sell it to the highest bidder.

When to trust the word of a cybercriminal?

Ransomware attack victims face two options: pay, or don’t pay. If they choose the latter, they need to try other methods to recover the data being kept from them.

If a ransom is paid, criminals will often decrypt the data as promised. They do this to encourage compliance in future victims. That said, paying a ransom doesn’t guarantee the release or decryption of data.

The type of attack experienced in Johannesburg poses a new incentive for criminals. Once the attackers have stolen the data, and have been paid the ransom, the data still has extractive value to them. This gives them duelling incentives about whether to publish the data or not, as publishing it would mean they could continue to extort value from the city by targeting citizens directly.


Read more: Ransomware attacks on cities are rising – authorities must stop paying out


In cases where victims decide not to pay, the solution so far has been to have strong, separate and updated data backups, or use one of the passkeys available online. Passkeys are decryption tools that help regain access to files once they’ve been held at ransom, by applying a repository of keys to unlock the most common types of ransomware.

But these solutions don’t address the negative outcomes of leakware attacks, because the “hostage” data is not meant to be released to the victim, but to the public. In this way, criminals manage to innovate their way out of being defeated by backups and decryption keys.

The traditional ransomware attack

Historically, ransomware attacks denied users access to their data, systems or services by locking them out of their computers, files or servers. This is done through obtaining passwords and login details and changing them fraudulently through the process of phishing.

It can also be done by encrypting the data and converting it to a format that makes it inaccessible to the original user. In such cases, criminals contact the victim and pressure them into paying a ransom in exchange for their data. The criminal’s success depends on both the value the data holds for the victim, and the victim’s inability to retrieve the data from elsewhere.

Some cybercriminal groups have even developed complex online “customer support” assistance channels, to help victims buy cryptocurrency or otherwise assist in the process of paying ransoms.

Trouble close to home

Facing the risk of losing sensitive information, companies and governments often pay ransoms. This is especially true in Australia. Last year, 81% of Australian companies that experienced a cyberattack were held at ransom, and 51% of these paid.

Generally, paying tends to increase the likelihood of future attacks, extending vulnerability to more targets. This is why ransomware is a rising global threat.


Read more: When it comes to ransomware, it's sometimes best to pay up


In the first quarter of 2019, ransomware attacks went up by 118%. They also became more targeted towards governments, and the healthcare and legal sectors. Attacks on these sectors are now more lucrative than ever.

The threat of leakware attacks is increasing. And as they become more advanced, Australian city councils and organisations should adapt their defences to brace for a new wave of sophisticated onslaught.

As history has taught us, it’s better to be safe than sorry.

Roberto Musotto received funding from H2020. He is affiliated with the Cyber Security Research Cooperative Centre (CSCRC).

Brian Nussbaum is an assistant professor at the College of Emergency Preparedness, Homeland Security and Cybersecurity (CEHC) at the University at Albany, a cybersecurity fellow with the think tank New America, and an affiliate scholar with the Center for Internet and Society (CIS) at Stanford Law School.

Authors: Roberto Musotto, Research Fellow in Cyber Security and Law, Edith Cowan University

Read more http://theconversation.com/hackers-are-now-targeting-councils-and-governments-threatening-to-leak-citizen-data-126190

5 Things to Keep in Mind When Renting Skip Bins

Renting a skip bin is an easy way to ensure that all your rubbish is collected and sorted properly, especially in situations where you might not be able to rely on local rubbish collection services ...

News Company - avatar News Company

Job losses expected as NZ's broadcasting sector faces biggest overhaul in a decade

New Zealand's commercial broadcasters are in trouble and the government is considering a complete restructure of public broadcasting. from www.shutterstock.com, CC BY-NDNew Zealand’s broadcastin...

Merja Myllylahti, Co-Director JMAD research center, Auckland University of Technology - avatar Merja Myllylahti, Co-Director JMAD research center, Auckland University of Technology

Can Indigenous Australians be deported as 'aliens'? A High Court decision will show us the strength of modern colonial power

Federal Immigration Minister David Coleman has cancelled the visas of two overseas born Indigenous men with a criminal past. They are, Coleman says, aliens with no automatic right to live in Australia...

Dominic O'Sullivan, Adjunct Professor, Faculty of Health and Environmental Sciences, Auckland University of Technology and Associate Professor of Political Science, Charles Sturt University - avatar Dominic O'Sullivan, Adjunct Professor, Faculty of Health and Environmental Sciences, Auckland University of Technology and Associate Professor of Political Science, Charles Sturt University

'One of the most poignant opera scenes I have ever experienced': Pinchgut’s Farnace

This new production of Farnace overwhelms with delight. Brett Boardman/Pinchgut OperaReview: Farnace, composed by Vivaldi, Pinchgut Opera When a performance of Farnace was cancelled at the theatre o...

Daniela Kaleva, Associate Head Research and Scholarship, Australian Institute of Music - avatar Daniela Kaleva, Associate Head Research and Scholarship, Australian Institute of Music

Politics with Michelle Grattan: Andrew Hastie on foreign influence, security and veteran mental health

Chinese government influence and interference has been a contentious issue in Australia politics in the past year. Weighing up concerns about foreign money in state and federal campaigns, candidates...

Michelle Grattan, Professorial Fellow, University of Canberra - avatar Michelle Grattan, Professorial Fellow, University of Canberra

Litigation is the real reason financial reports are becoming harder to read

Westpac can expect a bumper turnout of shareholders at its annual general meeting in Sydney on Thursday, many of them angry at its alleged role in facilitating child exploitation in the Philippines, i...

Mark Humphery-Jenner, Associate Professor of Finance, UNSW - avatar Mark Humphery-Jenner, Associate Professor of Finance, UNSW

'How do I clean my penis?'

Wes Mountain/The Conversation, CC BY-ND Growing up, no one ever gave me the rundown on how or what I should do to keep my penis clean […] I’ve never read any reliable answer beyond washi...

David King, Senior Lecturer, The University of Queensland - avatar David King, Senior Lecturer, The University of Queensland

Voters send sharp message to politicians about trust: ANU Australian Election Study

Following the 2019 federal election, only 59% of voters said they were satisfied with the way democracy was working. AAP/Mick TsikasThe Australian National University’s election study has unders...

Michelle Grattan, Professorial Fellow, University of Canberra - avatar Michelle Grattan, Professorial Fellow, University of Canberra

Finally, your electricity bill looks set to fall. Here's how much you could save

The renewables revolution is starting to pay off: our electricity bills are set to fall. AAP/Julian SmithHousehold electricity bills in Australia have increased sharply in the past decade. But new off...

Tim Nelson, Associate Professor of Economics, Griffith University - avatar Tim Nelson, Associate Professor of Economics, Griffith University

Estonia didn't deliver its PISA results on the cheap, and neither will Australia

Estonia spends less per student than Australia, but its average wages are lower too. Ruslan Valeev/UnsplashEducation news in Australia last week was dominated by Australia’s worst ever showing i...

Peter Goss, School Education Program Director, Grattan Institute - avatar Peter Goss, School Education Program Director, Grattan Institute

What is sodium lauryl sulfate and is it safe to use?

SLS is a known irritant to human skin. But if it's only in contact with your skin for a short time, it's probably OK. from www.shutterstock.comIf you’ve ever Googled the causes of a skin compla...

Yousuf Mohammed, Dermatology researcher, The University of Queensland - avatar Yousuf Mohammed, Dermatology researcher, The University of Queensland

Science needs true diversity to succeed -- and Australian astronomy shows how we can get it

Australian astronomy punches well above its weight, in terms of the research it leads and the facilities it houses. We have made remarkable discoveries in the past year alone. Our scientists have re...

Lisa Kewley, Director, ARC Centre for Excellence in All-Sky Astrophysics in 3D, Australian National University - avatar Lisa Kewley, Director, ARC Centre for Excellence in All-Sky Astrophysics in 3D, Australian National University

50 years on from the Melbourne Transportation Plan, what can we learn from its legacy?

The Melbourne Transportation Plan included every freeway and major arterial road built in the city since 1969. Shuang Li/ShutterstockThis is the first article in a series to mark the 50th anniversary ...

Liam Davies, PhD Candidate, Centre for Urban Research, RMIT University - avatar Liam Davies, PhD Candidate, Centre for Urban Research, RMIT University

State Library Victoria proves libraries aren't just about books: they're about community

Not the hushed or book-filled library experience you might expect. Patrick Rodriguez/SLVPublic libraries embody the values of democracy by offering free access to knowledge. But the role of contempora...

Sarah Backhouse, Research Fellow, Learning Environments Applied Research Network (LEaRN), University of Melbourne - avatar Sarah Backhouse, Research Fellow, Learning Environments Applied Research Network (LEaRN), University of Melbourne

Evangelical churches believe men should control women. That's why they breed domestic violence

Evangelical church teachings create fertile ground for domestic violence, its justification and its concealment. ShutterstockThis article is the first in a series exploring gender and Christianity. J...

Vicki Lowik, PhD candidate, CQUniversity Australia - avatar Vicki Lowik, PhD candidate, CQUniversity Australia

Why Vieques Puerto Rico Should Be on Your Bucket List

When visiting remote islands, most people would say that you only need to stay a couple of days there. But when you decide to visit Vieques, Puerto Rico, you can strike that idea out of your mind...

News Company - avatar News Company

Albanese accuses Facebook of shrugging off fakery

Anthony Albanese has also criticised the government for attacking freedom of the press and the right to protest. AAP/Mick TsikasOpposition leader Anthony Albanese is sharply critical of Facebook for f...

Michelle Grattan, Professorial Fellow, University of Canberra - avatar Michelle Grattan, Professorial Fellow, University of Canberra

Latest Wednesday Lotto Results

Wednesday Lotto draw 3917 Lucky numbers for this draw were 43 followed by 25. The rest of the winning numbers are 44, 33, 7 and lastly 15. So, one even and five odd numbers are in the lucky num...

Viw Magazine - avatar Viw Magazine

Chinese students top the PISA rankings, but some Shanghai parents are turning away from the school system

China is fast becoming a middle-class nation. Ewan Yap/UnsplashAustralian 15 year olds were around three and a half years behind their counterparts in China in maths, according to the OECD’s lat...

Hannah Soong, Senior Lecturer in Teacher Education Practice, School of Education, University of South Australia - avatar Hannah Soong, Senior Lecturer in Teacher Education Practice, School of Education, University of South Australia

Sick and Tired of Your Dead End Job? Try Teaching!

Tired of the same old grind at the office? Want an opportunity to impact lives both in your community and around the world? Do you love to travel and have new experiences? Teaching English is the perfect job for you! All you need is a willingness to ...

News Company - avatar News Company

The Impact of an Aging Population in Australia

There’s an issue on the horizon that Australia needs to prepare for. The portion of elderly citizens that make up the country’s overall population is increasing, and we might not have the infrastructure in place to support this. Australians h...

News Company - avatar News Company

LifeStyle

Latest Wednesday Lotto Results

Wednesday Lotto draw 3917 Lucky numbers for this draw were 43 followed by 25. The rest of the...

Ways Love and Relationships Benefit Body and Mind

Being in a happy relationship is great. You always have someone to greet you when you come home ...

The Importance of Smiling: How You Can Smile More

Happiness is something we all strive for and is often just out of reach. Of course, it’s impos...

5 Things to Do On Your Wedding Morning

After months of meticulous planning, wedding mornings usually find the bride excited but stressed ...