Given credit card data and account information has long been dirt-cheap to buy on the dark web, ransomware stepped in years ago as the preferred means of monetizing a hacker’s handiwork.  Combining the best of social engineering, e.g., well-crafted spear phishing using publicly available information, including emails of licensed professionals, with botnets usually tasked with promulgating spam, criminals have been able to easily re-purpose the latest exploits and social engineering techniques for ransomware.

For years now, ransomware scams have successfully targeted professionals.  For example, the Florida Bar many years ago warned its members of phishing exploits using various subject lines, including “Florida Bar Complaint – Attorney Consumer Assistance Program”.   One such email scam using “Lawyers and judges may now communicate through the portal” in the subject line relied on information found in a Florida bar article and preyed on many lawyers’ natural tendency to help by asking recipients to “test the portal and give feedback.”

As with many business owners, these scams succeed because professionals are pressed for time, have computers systems that do not automatically filter executable content or are themselves lacking in adequate training. Indeed, even if there is adequate training and sophisticated IT personnel running a firm’s network, no law firm is likely immune to hacking incidents, including the venerable Cadwalader Wickersham & Taft and other large blue chip firms such as Cravath Swaine & Moore LLP and Weil Gotshal & Manges LLP.

Since 2018, 138 law firms have publicly confirmed ransomware attacks on their systems, impacting at least 2.9 million records.  Last year saw the highest number of attacks (45) and records affected (1.6 million) so far.  This should come as no surprise given that the ABA has been warning lawyers for years regarding data security.

Accounting firms have also long fell prey to ransomware.   In fact, ransomware is especially successful with accounting firms given accountants hold critical financial data of clients that is often deadline-focused. Given the significant penalties assessed against clients for untimely filings good cybersecurity hygiene can sometimes be inadvertently disregarded for purposes of expediency.

These threats have become more pronounced over the years given criminals realize the benefit of redirecting resources to ransomware aimed at professionals such as lawyers and accountants. A consultant who assists accounting firms guard against ransomware attacks long ago warned accountants of the polymorphic Virlock that spawns unique versions after every use so antivirus programs cannot recognize it as well as TeslaCrypt that uses file names associated with well-known online games found on a child’s computer – which can spread to other computers attached to a home network, including an office PC.

As set forth in a decade-old CERT notice, destructive and lucrative ransomware variants include: Xorist, CryptorBit, CryptoLocker, CryptoDefense, and Cryptowall. All these exploits encrypt files on the local computer, shared network files, and removable media – the same techniques still used today.  Even though the private decryption keys for CryptoLocker, Xorist, CryptoDefense have long become available – rendering these exploits defensible, ransomware variants with no available decryption keys continue to launch on a routine basis.

To its credit, the FBI has addressed ransomware exploits for some time now – likely given it was inadvertently a participant in one such exploit. In 2012, the FBI was spoofed in a Reveton ransomware attack activated when a user visited a compromised website. Once infected, the victim’s computer immediately locks, and the monitor displays a screen stating there has been a violation of federal law. The bogus message goes on to say that the user’s Internet address was identified by the FBI as having been associated with child pornography sites or other illegal online activity. To unlock their machines, users are required to pay a fine using the MoneyPak prepaid money card service.

According to an April 29, 2016 FBI Bulletin, the FBI projected that ransomware attacks would grow a great deal in the years to come. To that end, the FBI suggested that the key areas to focus on with ransomware are prevention, business continuity, and remediation. Given that ransomware social engineering techniques have rapidly evolved, business recovery and continuity become even more crucial. More to the point, as recognized by the FBI: “There’s no one method or tool that will completely protect you or your organization from a ransomware attack.”

Instead, the FBI suggests firms focus on a variety of prevention efforts – in terms of awareness training for employees and technical prevention controls, as well as the creation of a solid business continuity plan in the event of a ransomware attack.  And, after a ransomware attack is suspected, victims should immediately contact the local FBI field office and report the incident to the Bureau’s Internet Crime Complaint Center.  These are good tips that most firms should follow.

If a firm wants to immediately enact a more proactive approach, however, there are certainly additional very basic policies and procedures that can be put in place right now to help avoid a ransomware exploit:

  • Block executable files (such as “.exe” files) and compressed archives (such as zip files) containing executable files before they reach a user’s inbox.
  • Block the use of thumb drives.
  • Specifically mitigate against social engineering exploits by providing employee online training that is continuous and targeted with services such as KnowBe4.
  • Keep operating systems, browsers and browser plug-ins fully updated.
  • Program hard drives on your computer network to prevent any unidentified user from modifying files.
  • Make sure there is a patch management plan in place.
  • Regularly back up data with media not connected to the Internet.

As for the most basic of “basic training”, some local law firm administrators were told years ago sound advice that never gets old: “Be smart. Be aware. Don’t open or click on anything that looks suspicious. They won’t come in if you don’t open the door.” In other words, never click on a link, file or image from an untested source or unknown URL. The extra seconds it takes to confirm the actual sender of an email message or owner of a website is well worth the time.

Given that business continuity best practices must mesh with IT security best practices, backups should be stored outside the network. And, if you are forced to restore from a backup it is never wise to restore your data over existing production data. Consulting with a disaster recovery specialist before disaster strikes probably is a good idea.

Again, because this serious threat of ransomware is not going away anytime soon, small and mid-sized business owners are reminded to at least do the basics – train staff regarding email and social media policies, implement minimum IT security protocols, regularly backup data, plan for disaster, and regularly test your plans.