Viw Magazine

Men's Weekly

.

  • Written by Roberto Musotto, Research Fellow in Cyber Security and Law, Edith Cowan University
Ransomware attacks are becoming increasingly complex, as hackers find creative ways to beat ordinary systems of defence. christiaancolen/flickr, CC BY

In recent weeks, Johannesburg’s computer network was held for ransom by a hacker group called Shadow Kill Hackers. This was the second time in three months a ransomware attack has hit South Africa’s largest city. This time, however, hackers didn’t pose the usual threat.

Rather than denying the city access to its data, the standard blackmail in a ransomware attack, they threatened to publish it online. This style of attack, known as leakware, allows hackers to target more victims in a single attack – in this case the city’s citizens.


Read more: What is ransomware and how to protect your precious files from it


The latest Johannesburg attack was the second leakware attack of this type ever recorded, and a similar attack could hit Australia soon. And although our current cyberattack defences are more advanced than many countries, we could be taken by surprise because of the unique way leakware operates.

A new plan of attack

During the Johannesburg attack, city employees received a computer message saying hackers had “compromised all passwords and sensitive data such as finance and personal population information”. In exchange for not uploading the stolen data online, destroying it and revealing how they executed the breach, the hackers demanded four bitcoins (worth about A$52,663) - “a small amount of money” for a vast city council, they said.

The hacker group operated a Twitter account, on which they posted a photo showing the directories they had access to. ShadowKillGroup/twitter

In this case, access to data was not denied. But the threat of releasing data online can put enormous pressure on authorities to comply, or they risk releasing citizens’ sensitive information, and in doing so, betraying their trust.

The city of Johannesburg decided not to pay the ransom and to restore systems on its own. Yet we don’t know whether the data has been released online or not. The attack suggests cybercriminals will continue to experiment and innovate in a bid to defeat current prevention and defence measures against leakware attacks.

This login screen message was displayed on computers in Johannesburg following the attack. pule_madumo/twitter

Another notable leakware attack happened a decade ago against the US state of Virginia. Hackers stole prescription drug information from the state and tried obtaining a ransom by threatening to either release it online, or sell it to the highest bidder.

When to trust the word of a cybercriminal?

Ransomware attack victims face two options: pay, or don’t pay. If they choose the latter, they need to try other methods to recover the data being kept from them.

If a ransom is paid, criminals will often decrypt the data as promised. They do this to encourage compliance in future victims. That said, paying a ransom doesn’t guarantee the release or decryption of data.

The type of attack experienced in Johannesburg poses a new incentive for criminals. Once the attackers have stolen the data, and have been paid the ransom, the data still has extractive value to them. This gives them duelling incentives about whether to publish the data or not, as publishing it would mean they could continue to extort value from the city by targeting citizens directly.


Read more: Ransomware attacks on cities are rising – authorities must stop paying out


In cases where victims decide not to pay, the solution so far has been to have strong, separate and updated data backups, or use one of the passkeys available online. Passkeys are decryption tools that help regain access to files once they’ve been held at ransom, by applying a repository of keys to unlock the most common types of ransomware.

But these solutions don’t address the negative outcomes of leakware attacks, because the “hostage” data is not meant to be released to the victim, but to the public. In this way, criminals manage to innovate their way out of being defeated by backups and decryption keys.

The traditional ransomware attack

Historically, ransomware attacks denied users access to their data, systems or services by locking them out of their computers, files or servers. This is done through obtaining passwords and login details and changing them fraudulently through the process of phishing.

It can also be done by encrypting the data and converting it to a format that makes it inaccessible to the original user. In such cases, criminals contact the victim and pressure them into paying a ransom in exchange for their data. The criminal’s success depends on both the value the data holds for the victim, and the victim’s inability to retrieve the data from elsewhere.

Some cybercriminal groups have even developed complex online “customer support” assistance channels, to help victims buy cryptocurrency or otherwise assist in the process of paying ransoms.

Trouble close to home

Facing the risk of losing sensitive information, companies and governments often pay ransoms. This is especially true in Australia. Last year, 81% of Australian companies that experienced a cyberattack were held at ransom, and 51% of these paid.

Generally, paying tends to increase the likelihood of future attacks, extending vulnerability to more targets. This is why ransomware is a rising global threat.


Read more: When it comes to ransomware, it's sometimes best to pay up


In the first quarter of 2019, ransomware attacks went up by 118%. They also became more targeted towards governments, and the healthcare and legal sectors. Attacks on these sectors are now more lucrative than ever.

The threat of leakware attacks is increasing. And as they become more advanced, Australian city councils and organisations should adapt their defences to brace for a new wave of sophisticated onslaught.

As history has taught us, it’s better to be safe than sorry.

Roberto Musotto received funding from H2020. He is affiliated with the Cyber Security Research Cooperative Centre (CSCRC).

Brian Nussbaum is an assistant professor at the College of Emergency Preparedness, Homeland Security and Cybersecurity (CEHC) at the University at Albany, a cybersecurity fellow with the think tank New America, and an affiliate scholar with the Center for Internet and Society (CIS) at Stanford Law School.

Authors: Roberto Musotto, Research Fellow in Cyber Security and Law, Edith Cowan University

Read more http://theconversation.com/hackers-are-now-targeting-councils-and-governments-threatening-to-leak-citizen-data-126190

Restoring Rental Spaces To Perfection Before Moving Out

A stressful part when leaving a rented home is ensuring the space is spotless and ready for inspection. A professional's help becomes invalu...

Why More Aussies Are Choosing Pontoon Boats To Launch a Waterside Lifestyle

Soaking up the long, sunny days of summer is a classic Australian pastime, and there’s no better way to do it than aboard a boat. But wh...

Building Bespoke Spaces: Why a Custom-Driven Approach Truly Matters

When it comes to creating a home that’s a perfect fit for your lifestyle, a Fiteni Homes-style approach offers unmatched flexibility and...

Refining Facial Contours with Modern Surgical Techniques on the Gold Coast

When we think of rejuvenation and restoring youthful contours, a targeted solution such as a face lift can be transformational. For those ...

Term Deposits Australia: A Complete Guide to Fixed-Rate Savings

For Australians seeking a safe, predictable way to grow their savings, term deposits australia options provide an attractive solution. Off...

Emergency Gate Repairs in Melbourne: Keeping Your Property Secure and Functional

A malfunctioning gate can be more than an inconvenience — it can compromise your property’s security, accessibility, and safety. Acros...

Chatswood Tutoring: Empowering Students to Achieve Academic Excellence

Education is more competitive today than ever before, and students face constant pressure to perform well across multiple subjects and exa...

Top Tips When Searching for Caravans for Sale in Perth

Western Australia is built for road trips. With its sweeping coastline, desert tracks and endless sunshine, there’s no better way to exp...

From Gaps to Glamour: Exploring Dental Bridge and Cosmetic Dentist Brisbane Options

A healthy, complete smile has the power to boost confidence, improve speech, and enhance overall oral function. However, the unexpected lo...

Achieving Your Healthiest, Straightest Smile in Blackburn

Your life can be genuinely transformed by a confident, healthy smile that enhances your overall well-being and self-esteem. Blackburn dent...

Hobart Smile Secrets: Achieving Perfection with All-on-4 and Porcelain Veneers

Hobart smiles, rebuilt and refined Hobart’s waterfront, sandstone facades, and the sweep of kunanyi, Mount Wellington, set a high bar f...

How an EV Charger Installation Cost Calculator Helps Australians Budget Accurately

As electric vehicles become more common across Australia, many new EV owners face the same question: how much will it cost to install a home...

How Do I Choose the Right Pool Size and Design for My Backyard?

Choosing the right pool size and design is one of the most exciting steps in creating your dream outdoor space. Whether you’re planning a ...

Maximising Space with Innovative Storage Solutions for Urban Cyclists

Urban cyclists often face the challenge of limited storage space in their homes. Efficient storage solutions are crucial for maintaining a c...

How to Choose the Best Coffee Beans for Your Home

Coffee is more than just a morning ritual, it’s comfort, energy, and joy in a cup. Whether you enjoy a bold espresso or a smooth latte, th...

Running with Wide Feet? A Guide to 4E Running Shoes and Injury Prevention

Running stands out as a beloved fitness pursuit in Australia. From the scenic coastal routes of Sydney to the lush parklands of Adelaide and...

Intellectual Property Mistakes Businesses Make

Protecting intellectual property (IP) is essential for any business, yet many companies overlook key steps that safeguard their ideas and ...

Security Fencing: Strength, Style, and Safety for Every Property

When it comes to protecting your property, nothing provides peace of mind quite like high-quality security fencing. Whether you’re safeg...

FRP Storage Tanks: Strong, Reliable, and Built to Last for Modern Industries

💧 Discover why FRP storage tanks are the smart choice for industries! From strength and corrosion resistance to easy maintenance and long...

How to Build a Simple Summer Wardrobe That Works Anywhere

Image source: Dekota SwimI swear — I packed for three days in Byron and ended up wearing the same outfit on repeat. A linen shirt, my Broo...

hacklink hack forum hacklink film izle hacklink หวยออนไลน์mavibetสล็อตเว็บตรงgamdom girişpadişahbetMostbetbetofficemavibetpin updizipalholiganbet girişpradabetcocktail glassestipobetpusulabetcasibompusulabetjojobet girişbetofficetipobet girişpusulabetpusulabetpusulabetholiganbet色情 film izlejojobetnakitbahisJojobet 1106pusulabet girişpusulabet girişmatbetYakabet1xbet girişjojobetGrandpashabetgobahisorisbetbetofficemeritkingjojobet girişgiftcardmall/mygiftultrabet girişmatbetzbahis türkiyebets10kingbettingjustintvcasibomkingroyalbetcioiptvcasibomcasibomJojobetmeritkingmeritkingnitrobahisFast Payout Casinoscasibomdeneme bonusumadridbetyakabetcasibom girişcasibombetciobetcioultrabetSekabetCasibomkingroyalsekabetDinamobetrinabetVdcasinobetpuanMarsbahisatlasbetultrabet girişprimebahismeritkingprimebahismeritking girişholiganbetultrabetultrabetultrabetcasibombetkolikgalabetSahabetcasibomcasibompusulabetorisbettipobet girişcolor pickermatbet girişpusulabet girişbetsmove girişbetsmove girişbetsmove girişholiganbet girişgalabet girişคลิปโป๊Casibomcasibomvaycasinodeneme bonusu veren siteleronwinonwinizmir escorttimebetkonya escorthttps://bogaria-atelier.com/grandbettingtimebetgrandbettingbetofficetimebetultrabetbets10kavbet girişmarsbahisroyal reelsnorabahistipobet güncel girişKayseri Escortjojobet girişJojobetbetasushayalbahishayalbahisbettiltcasibomHoliganbetaviator gamecasibomtimebettimebettimebetbahislionistanbul escort telegrambetparkcasibompantheraproject.netcasibomcrown155 casinohb88aussuper96 loginpusulabetmeritbetbetasusholiganbetcasibom한국야동pusulabetหวยออนไลน์padişahbetbetparkgiftcardmall/mygift주소모음 주소모아spin2u loginneoaus96 casino loginHoliganbetStreameastholiganbetpadişahbetbetasuscasibombets10ff29 casinoStreameastholiganbetstakemate77best e-wallet pokies 2025malware downloadтоп 10 казинорейтинг лучших казиноjojobet 1106bets10aresbetmatbetmostbetsiteold.unicorsalud.edu.coJojobet 1106mostbetmeritcasinomatbetgrandpashabetjojobet giriş hacklink hack forum hacklink film izle hacklink หวยออนไลน์mavibetสล็อตเว็บตรงgamdom girişpadişahbetMostbetbetofficemavibetpin updizipalholiganbet girişpradabetcocktail glassestipobetpusulabetcasibompusulabetjojobet girişbetofficetipobet girişpusulabetpusulabetholiganbet色情 film izlejojobetnakitbahisJojobet 1106pusulabet girişpusulabet girişmatbetYakabet1xbet girişjojobetGrandpashabetgobahisorisbetbetofficemeritkingjojobet girişgiftcardmall/mygiftultrabet girişmatbetzbahis türkiyebets10kingbettingjustintvcasibomkingroyalbetcioiptvcasibomcasibomJojobetmeritkingmeritkingFast Payout Casinoscasibomdeneme bonusumadridbetyakabetcasibom girişcasibombetciobetcioultrabetSekabetCasibomkingroyalsekabetDinamobetrinabetVdcasinobetpuanMarsbahisatlasbetultrabet girişprimebahismeritkingprimebahismeritking girişholiganbetultrabetultrabetultrabetcasibombetkolikgalabetSahabetcasibomcasibompusulabetorisbettipobet girişcolor pickermatbet girişpusulabet girişbetsmove girişbetsmove girişbetsmove girişholiganbet girişgalabet girişคลิปโป๊Casibomcasibomvaycasinodeneme bonusu veren siteleronwinonwinizmir escorttimebetkonya escorthttps://bogaria-atelier.com/grandbettingtimebetgrandbettingbetofficetimebetultrabetbets10kavbet girişroyal reelsnorabahistipobet güncel girişKayseri Escortjojobet girişJojobetbetasushayalbahishayalbahisbettiltcasibomHoliganbetaviator gametimebettimebettimebetbahislionistanbul escort telegrambetparkcasibompantheraproject.netcasibomcrown155 casinohb88aussuper96 loginpusulabetmeritbetbetasusholiganbetcasibom한국야동หวยออนไลน์padişahbetbetpark주소모음 주소모아spin2u loginneoaus96 casino loginHoliganbetStreameastholiganbetpadişahbetbetasuscasibombets10ff29 casinoStreameastholiganbetstakemate77best e-wallet pokies 2025топ 10 казинорейтинг лучших казиноbets10aresbetmatbetmostbetmostbetmeritcasinomatbetgrandpashabetjojobet giriş