
Executive Summary
Ransomware has become a rampant problem within the United States, especially since the beginning of the COVID-19 pandemic. These perpetrators are often protected by foreign governments, which creates difficulties in attempting to prosecute those who are responsible for these crimes. These attacks have become increasingly costly, raising moral and legal questions about how to address this issue. Congress has the opportunity to help state, local, and tribal governments by passing legislation that will improve the skills of their employees and make it more difficult for ransomware gangs to be paid in the first place.
Background
Ransomware is a type of malicious software, or malware, that infects a computer and encrypts the files so that the owner cannot access them. Ransomware typically requires human interaction to allow an executable file into the network. Once in the network, the file executes, encrypts the data, and adds an extension to all files which makes them inaccessible. It is possible for “drive-by” attacks to occur without human interaction, but this is much less common. To decrypt the files and regain access, the attacker will demand a ransom from the victim. If the ransom is not paid, the victim risks having their data deleted. There is a variation, which is included under the banner of ransomware, called doxware. Doxware threatens to release data from a victim’s hard drive. However, it is much more difficult for hackers to find this information which has caused encryption ransomware to be the dominant form.
One reason that ransomware has become much more prevalent is the use of Ransomware as a Service (RaaS). Ransomware is difficult to create and keep up to date, meaning very few people can create the software necessary to implement these attacks. However, it is much easier to use this software once it has been created. RaaS is the response to this reality where “affiliates” rent the use of a ransomware strain in exchange for a percentage of the payout to the original creators. The cybersecurity firm Group-IB analyzed ransomware attacks throughout 2020 and found that two-thirds of these were perpetrated using the RaaS model.[i]
The major perpetrator of ransomware attacks are ransomware gangs located either in the former Soviet Union or associated with the Russian government. Recorded Future, a security firm based outside of Boston, tracks about 25 ransomware groups. Approximately 15 groups, including the five largest, are believed to be based in Russia or elsewhere in the former Soviet Union.[ii] Ransomware is so prevalent in Russia and other former Soviet states because of the excellent STEM programs in universities which came about during the Cold War. After the collapse of the Soviet Union, the new Russian economy could not utilize the technically skilled workers. Despite some improvement in the Russian tech sector, there remains a lack of legitimate jobs, combined with the low salaries for the jobs available, which has led many to work in the shadow economy.
The Russian government’s involvement with cybercriminals has become an increasingly large issue in recent years with more groups moving into fields such as ransomware. The level of involvement varies from direct government employment of criminals to simply ignoring criminal activity. It is a well-known rule that the Russian government only prosecutes hacking groups based outside of Russia or those that attack Russian or allied targets. This turning of a blind eye is the primary means of Russian government support, but there has been anecdotal evidence that formal cooperation between the Federal Security Service (FSB) and these groups has occurred, such as the Russian citizens who hacked Yahoo in 2014.[iii]
It is important to recognize that Russia is not the only country which hosts ransomware gangs. Gangs in countries such as China, Iran, and North Korea have undertaken attacks against the United States in the past. However, no other country has as many gangs as Russia does, and those groups have not caused as much damage.
Ransomware attacks have become much more common and ransom costs have increased in recent years. In 2020 alone, almost $350 million in ransoms were paid[iv] with the average ransomware payment more than doubling from $115,123 in 2019 to $312,493 in 2020.[v] The highest ransom demand on record came in 2021 at $50 million. Ransomware as an industry is extremely top-heavy in terms of how money is distributed, meaning that a small number of groups gain most of the benefits from the entire industry. 199 deposit addresses receive 80% of all funds sent by ransomware addresses in 2020 and an even smaller group of 25 addresses accounts for 46%.[vi] It is projected that in 2021 a ransomware attack could or will occur every 11 seconds and the total economic damage from ransomware attacks would amount to $20 billion.[vii]
The total economic damage projected for 2021 is a much larger sum than the total ransoms paid in 2020. This is because many associated costs are not the ransom. There are major costs that can come about both during and after a ransomware attack. During an attack, the primary cost aside from a ransom is the downtime of services. Companies cannot undertake business until either their networks have been restored from a backup or the ransom has been paid and the verified key arrives. Additionally, sensitive data may be released. This can impact the reputation of a company or provide market secrets they had possessed. Potential clients may also hesitate to work with a victim of a ransomware attack because they do not want their data to be put at risk. Additional costs during the attack are fees for ransom negotiators, a continually growing market, and lawyers brought in to prevent liability. After the attack, there are three additional sets of potential costs: Upgrading technology and systems, litigation settlements, and regulatory fines. Upgrading technology occurs in almost every situation because victims want to patch flaws that were exploited. Litigation settlements and regulatory fines depend on the specific attack. If private information was leaked or if the victim was not practicing adequate safety measures, they may be open to charges being brought against them.
Current Issues
The major current question on this topic is whether or not states should permit ransom payments. Many scholars focus on a legal argument for banning ransom payments. This argument is based upon previously existing laws such as the Foreign Corrupt Practices Act’s anti-bribery provision and the Computer Fraud and Abuse Act’s ban on “payments stemming from threats to damage a government or bank computer, or a computer used in, or affecting, interstate or foreign commerce.”[viii]
However, there is an important argument to consider for risks of prohibiting ransoms. Ransomware gangs have already shown that they will attack both critical infrastructure which is operated by both public and private organizations. If ransoms were entirely banned, an attack on critical infrastructure would be crippling until the organization could regain control of their systems and restore them from backed up data. It would prohibit the ability of said infrastructure to easily reopen and could cause more harm to American citizens than paying the ransom would. These considerations have raised an important set of questions about the vulnerability of infrastructure sectors. There are 16 designated critical infrastructure sectors in the United States and few of them have mandatory cyber requirements.[ix] Additionally, these sectors are managed by a variety of departments, many of whom do not have the experience or the resources that is possessed by either private cybersecurity professionals or federal cybersecurity employees to devote to these threats. There have been many discussions about legislation to ban ransom payments, but no bills which would do so are currently moving through Congress or any state legislatures.
The biggest challenge in combating ransomware is the ever-evolving threat and its new strains. Ransomware gangs move quickly and release new forms of malicious code soon after one is taken down. Additionally, institutions, companies, and individuals need to successfully defend every time while hackers only need to succeed once. These issues are an ever-occurring issue with issues in this realm and must be addressed.
The primary reason that previous attempts to combat ransomware have failed is that, historically, there has not been an emphasis on public education of ransomware. The first documented ransomware virus is from 1989 when the PC Cyborg virus was distributed to AIDS researchers via floppy disk.[x] Since then, the United States has been extremely effective in working with international actors and the private sector to take down ransomware strains such as Gameover ZeuS. However, these have all been responses with minimal proactive measures.
Recommendations
Congress can make a substantial impact on the issue of ransomware. The easiest recommendation which they could implement would be passing H.R.3138, the State and Local Cybersecurity Improvement Act. This bill has passed in the House of Representatives but remains in the Senate Committee on Homeland Security and Governmental Affairs. This bill would assist state, local, and tribal governments in improving their cybersecurity planning and the skills of their workers. Ransomware has become the issue it is today because of Bitcoin and other cryptocurrency. Because of this, it is necessary to increase regulation of these currencies and their exchanges. Banks are required under the Bank Secrecy Act (BSA) to comply with rules which combat money laundering. To create an equal standing for cryptocurrency, Congress could pass new legislation which would do the same for Bitcoin and other forms of anonymous online payments. While there is risk in prohibiting the payment of ransoms, it is better than continuing the status quo of allowing organizations to pay ransoms without accountability and thus not needing to improve their defenses to prevent intrusions from occurring in the future. Ransom prices will soon become too high to pay if they continue to increase at their current rate. Congress should establish a standard, as is suggested by Marañon and Wittes, for a general ban with a case-by-case reviewal option for exemption.[xi] Finally, all ransomware attacks should be required to be reported to CISA and attacks against publicly traded companies should be required to be reported to the SEC. It is not only necessary to better understand the full scope of the ransomware problem, but any such intrusion is vital information for investors and government auditors. This issue has gained the attention of policymakers in recent months. Since July, three separate bills have been introduced in Congress to mandate reporting of companies impacted by ransomware attacks. [xii]
The primary limitation on this issue is its rapid evolution and the protection of groups within Russia. They will always be able to change their methods of attack more quickly and effectively than institutions will be able to defend against them. This is compounded by the fact that training employees on how to create and implement cybersecurity strategies will lag and any institution is only as secure as its least secure point of contact. An additional limit comes in terms of the banning of ransoms. Not all ransoms can be banned, or gangs will target critical infrastructure that would cost human lives to change the policy or have someone break it in despite the laws. There will need to be sectors, such as healthcare, which are permitted to pay these ransoms even though it may cause increased attacks against them.
Future policy could make substantial gains in preventing ransomware from becoming an issue by removing the incentives and payment methodology that is currently most used. These policies would focus on the regulation of cryptocurrency and how to provide incentives for hackers to find non-criminal employment. In terms of regulating cryptocurrencies, it will be difficult to find the appropriate line between maintaining anonymity of users and combatting its use for ransomware. Finally, as mentioned above, many hackers have fallen into their jobs because they are highly educated and do not have options for legitimate employment in their field. Policies which can help to provide incentives to take up legitimate jobs, such as funding for job training or foreign direct investment in technical sectors, could help to bring those hackers that would be amenable to leaving away from illicit employment.
[i] Tim Maurer, “Why the Russian Government Turns a Blind Eye to Cybercriminals,” Carnegie Endowment for International Peace, February 2, 2018, https://carnegieendowment.org/2018/02/02/why-russian-government-turns-blind-eye-to-cybercriminals-pub-75499.
[ii] Andrew Kramer, Michael Schwirtz, and Anton Troianovski, “’They Hit You Hard’: How DarkSide Became Powerhouse of Ransomware Attacks,” Business Standard, May 30, 2021, https://www.business-standard.com/article/international/cybergangs-become-ransomware-gang-poses-threat-to-companies-people-in-us-121053000136_1.html.
[iii] Tim Maurer, “Why the Russian Government Turns a Blind Eye to Cybercriminals”.
[iv] Samantha Schwartz, “Cryptocurrency Fuels Ransomware Payments. Without Regulation, It Could Get Worse,” Cybersecurity Dive, May 7, 2021, https://www.cybersecuritydive.com/news/ransomware-bitcoin-cryptocurrency-regulation/599766/.
[v] Jenny Jun, “The Political Economy of Ransomware,” War on the Rocks, June 2, 2021, https://warontherocks.com/2021/06/the-political-economy-of-ransomware/.
[vi] “Ransomware Skyrocketed in 2020, But There May Be Fewer Culprits Than You Think,” Chainalysis Insights, January 26, 2021, https://blog.chainalysis.com/reports/ransomware-ecosystem-crypto-crime-2021.
[vii] Jun, “The Political Economy of Ransomware”.
[viii] Marañon, Alvaro, and Benjamin Wittes. “Ransomware Payments and the Law.” Lawfare, Brookings Institute, 23 Aug. 2021, www.lawfareblog.com/ransomware-payments-and-law.
[ix] Tim Maurer, “Why the Russian Government Turns a Blind Eye to Cybercriminals”.
[x] “AIDS Trojan: PC Cyborg: Original Ransomware,” KnowBe4, August 30, 2021. https://www.knowbe4.com/aids-trojan
[xi] Marañon Wittes, “Ransomware Payments and the Law.”
[xii] Jenny Jun and Nadiya Kostyuk, “The Pros and Cons of Mandating Reporting from Ransomware Victims,” Lawfare, November 1, 2021, https://www.lawfareblog.com/pros-and-cons-mandating-reporting-ransomware-victims.


Leave a Reply