BitDepthFeatured

Ransomware report reveals Caricom-wide attacks

3 Mins read

Above: Illustration by swevil/123RF.com

BitDepth#1448 for March 04, 2024

The Ransomware Roundhouse, a report on the state of ransomware in 2023 was launched last week with a webinar discussing the findings and their implications.

The authors, Alex Samm of Tier 10 Technology and Shiva Parasram of the Computer Forensics and Security Institute, acknowledge that their findings are incomplete, based as they are on announcements by ransomware collectives of successful exfiltrations of company data from businesses.

The report lists 32 known breaches among Caricom nations. TT is second in a tie with the Dominican Republic with four known breaches and behind Dominica and Puerto Rico who led with six known breaches each.

The Caricom nations confirmed to have been hit by successful ransomware breaches were Antigua and Barbuda, The Bahamas, Barbados, Belize, Dominica, Grenada, Guyana, Haiti, Jamaica and Trinidad and Tobago.

Among the affected entities are insurance companies, logistics and supply businesses, retail and medical companies and a higher education institution.

The report redacts specific details about the companies or institutions affected, but lists the ransomware collectives responsible for the 2023 attacks.

The 8Base, Lockbit3, RansomEXX, Royal and Hive ransomware groups targeted TT and only Royal is currently listed as inactive.

These are all international criminal businesses, the authors warn, who do not discriminate based on company size, business sector or location.

“In 2023 we learned that no one was safe in the Caribbean region,” Parasram and Samm write.

“The sector, size of the organisation, technologies implemented, impact on the global stage, geo-political affiliations or even the GDP were of no matter. Threat actors were interested only in profits and chose their targets based on who was likely to suffer great losses (or fines where applicable), should they refuse to pay them.”

The authors also expressed concern that the list of 32 regional breaches is probably inaccurate, since it does not list ransomware attacks that ended in payment of the routinely exorbitant demands.

Groups such as LockBit3 list over 1,000 victims on their official dark web leak site for 2023, indicating that ransomware groups have become far more aggressive than seen in previous years and companies and organisations alike are in fact paying the ransoms.”

That conjecture is supported by the increase in ransoms paid in 2023, usually in some form of cryptocurrency.

“According to researchers at Chainalysis.com, the amount paid in ransoms for 2023 amounted to a staggering US$1.1 billion. This figure is almost double the amount paid in 2022 which totalled US$560 million.”

It’s notable that the breaches reported in Trinidad and Tobago were largely found on the dark web after ransoms were not paid and stolen data was released to the public.

The local fuzziness around ransomware is only made worse by the national disinclination to be open about these incidents.

In January, Minister of National Security Fitzgerald Hinds told a workshop hosted by his ministry, Caricom IMPACS and the EU that between 2019 and 2023, the TT Cyber Security Incident Response Team had recorded 205 successful cyberattacks with 52 of them occurring in 2023 alone.

There was no clarity about what the TTCSIRT logged as a successful cyberattack.
Were these attacks that were successful at penetrating a company’s digital security measures?

Were they cybersecurity attacks resulting in the infection of a secured computer system? Attacks that resulted in a data breach of sensitive data?

Attacks that breached secured systems, infiltrated them and suffered exfiltrated data and subsequent ransomware demands?

I ask this, because TechNewsTT, like many websites, is under almost continuous daily probing by dictionary password attacks, code injection intrusions and DDOS attempts.

Once a week, I need to specifically block an IP address for sustained and unrelenting efforts (200 or more attempts in less than an hour) to breach the website’s security systems.

Every attack is unnerving, but there is a steadily escalating scale of severity that this country is not capable – even in the face of widespread public concern – of assessing and tabulating in any meaningful way.

The TTCSIRT generally does not respond to requests for information from this columnist and when a response is given, its brevity approaches haiku.

It’s possible that the TTCSIRT is only reflecting what it is given, which is precious little from companies affected by cyberattacks.

Ransomware groups are unconstrained by geography, bureaucracy and certainly not by pride. They are also largely unconcerned about law enforcement.

Within days of a collective effort by international law enforcement agencies to shut down the darkweb presence of LockBit3, the ransomware group was back at a new onionsite link and posting fresh data, including a dump it alleged was exfiltrated from the FBI.

Local victims have overwhelmingly chosen to be respond to these incidents with a digital omerta until confronted with undeniable evidence of the breaches.

That’s a nonstop ride to where we are now. Nowhere.

What keeps regional cybersecurity experts awake at night

What keeps regional cybersecurity experts awake at night

Whether the attack comes from a successful external attempt, exploiting a vulnerability or from inside, perhaps a disgruntled employee, an exploit needs just one vulnerability.
Read More
Where hackers begin

Where hackers begin

Digital nation strategies have been released by 170 countries and regions and more than 60 countries have elevated AI in their national strategy.
Read More
Blue skies for microblogging?

Blue skies for microblogging?

Bluesky hit its current high of 23 million users faster than expected, but it’s way behind X.
Read More
The apps that thrive in Apple’s ecosystem

The apps that thrive in Apple’s ecosystem

By Apple's own yardstick an app that shares usable data across three devices is acceptable one that synchronises with four is a winner.
Read More
America’s open mic moment

America’s open mic moment

What made online pundits so effective in the US election?
Read More
The press and the president-elect

The press and the president-elect

Beyond the president-elect's often-expressed intent to retaliate against journalists he believes are unfairly attacking him is the agenda of Project 2025.
Read More
All washed up

All washed up

Dirt on its own will simply shake out of fabric. What keeps it in place is oil and grease, readily generated by human skin.
Read More
The state of Caribbean digital transformation

The state of Caribbean digital transformation

Despite 87 per cent believing that digital will disrupt their industry, 87 per cent acknowledged that they don't have the right leaders
Read More
The WordPress War

The WordPress War

WPEngine and the websites of its customers were blocked from the WordPress log-in system theme and plug-in updates and other background processes that enable a Wordpress website.
Read More
A budget of concrete and asphalt

A budget of concrete and asphalt

Four years after Hassel Bacchus took up the pioneering role of Digital Transformation Minister, the 2025 budget could not identify any completed transformation project that's positively affected citizens.
Read More
Arima’s first step toward becoming a smart city

Arima’s first step toward becoming a smart city

The public WiFi was officially activated on September 28 at the hospital, and it's fast. A local ping registered 250 megabits of download speed and 126 for upload.
Read More
Now hear this!

Now hear this!

Budget headsets will effectively dampen ambient sounds, but tend to be an all or nothing solution.
Read More
A taxing time for all

A taxing time for all

Tax collection began using the least customer-friendly interface imaginable, lines outside a government building.
Read More
Mobile devices, a war of increments

Mobile devices, a war of increments

Mixing and matching the two rival ecosystems is essentially impossible, so it's the utility of the products combined that makes the biggest difference.
Read More
Why cash is king in Trinidad and Tobago

Why cash is king in Trinidad and Tobago

In 2017, 16 per cent of users owned a credit card, a figure that dropped to 15 per cent by 2023.
Read More
I shopped at Temu!

I shopped at Temu!

Temu is great fun to explore and offers many bargains but product quality can be wildly variable.
Read More
What’s needed to make e-Governance happen?

What’s needed to make e-Governance happen?

“If we look at successful governments that have achieved a certain level in of success in these programs, some things stand out."
Read More
Changing the education conversation

Changing the education conversation

There are local schools that aspire to continuous improvement and others that struggle to make it through a working day without bloodshed.
Read More
Practical steps to reducing cybersecurity risks

Practical steps to reducing cybersecurity risks

The process, to be effective, must be ongoing and managed to ensure that vendors meet required standards.
Read More
The consequences of careless code

The consequences of careless code

The cruel reality of Crowdstrike is that it wasn't a cybersecurity attack. It was a quality of service lapse and the incident puts IT professionals in an odd space.
Read More
What keeps regional cybersecurity experts awake at night What keeps regional cybersecurity experts awake...
Where hackers begin Where hackers begin
Blue skies for microblogging? Blue skies for microblogging?
The apps that thrive in Apple’s ecosystem The apps that thrive in Apple’s...
America’s open mic moment America’s open mic moment
The press and the president-elect The press and the president-elect
All washed up All washed up
The state of Caribbean digital transformation The state of Caribbean digital transformation
The WordPress War The WordPress War
A budget of concrete and asphalt A budget of concrete and asphalt
Arima’s first step toward becoming a smart city Arima’s first step toward becoming a...
Now hear this! Now hear this!
A taxing time for all A taxing time for all
Mobile devices, a war of increments Mobile devices, a war of increments
Why cash is king in Trinidad and Tobago Why cash is king in Trinidad...
I shopped at Temu! I shopped at Temu!
What’s needed to make e-Governance happen? What’s needed to make e-Governance happen?
Changing the education conversation Changing the education conversation
Practical steps to reducing cybersecurity risks Practical steps to reducing cybersecurity risks
The consequences of careless code The consequences of careless code

🤞 Get connected!

A once weekly email notification of new stories on TechNewsTT. Just that. No spam.

Possible UI Glitch. Click top right corner to dismiss 👉

Get Connected!

A once weekly email notification of new stories on TechNewsTT.

Just that. No spam.

Related posts
BitDepthFeatured

What keeps regional cybersecurity experts awake at night

4 Mins read
Whether the attack comes from a successful external attempt, exploiting a vulnerability or from inside, perhaps a disgruntled employee, an exploit needs just one vulnerability.
BitDepthFeatured

Where hackers begin

3 Mins read
Digital nation strategies have been released by 170 countries and regions and more than 60 countries have elevated AI in their national strategy.
Press Releases

Samsung extends Knox security to its home appliances

2 Mins read
Knox Matrix is a security solution that comprehensively protects connected devices and networks using private blockchain technology.
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

1 Comment
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
trackback
9 months ago

[…] Caribbean – The Ransomware Roundhouse, a report on the state of ransomware in 2023 was launched last week with a webinar discussing the findings and their implications… more […]

×
FeaturedOpinion

What the blockchain tells us about the big business of ransomware

1
0
Share your perspective in the comments!x
()
x