It's a hot topic, the old "pay or don't pay" for hackers not to leak your data. Since recording this a few days ago, we've had Grafana go with the "no pay" approach, and I've seen a raft of commentary around other companies reaching "agreements", which is a much politer way of saying "we paid extortionists a ransom". I'm concerned about the normalisation of ransom payments, and using language that deflects from the criminal nature of it is a big part of that. Instructure's exact words were that they "reached an agreement with the unauthorised actor involved", which really waters down the severity of the whole thing. It looks like, for the time being, "pay or leak" is the new norm... along with nonsensical statements like "the data was returned to us" 🤷♂️
Weekly update- Homepage
- International
- Weekly Update 504
Related
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbo...
45 minutes ago
0
Fake IRS letters target cryptocurrency holders
10 hours ago
2
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
12 hours ago
4
Claims in the Storm
14 hours ago
7
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
22 hours ago
6
New Tool Traces AI Videos Back to Their Source
22 hours ago
6
Is There Really a Fix for CISO Fatigue?
1 day ago
8

_Ivelin_Radkov_Alamy.png?width=720&quality=80&disable=upscale)








