FBI asks private sector for advice on ransomware attacks
The “Ransomware Summit” opens lines of communication between corporate and government
Over 100 public-sector ransomware attacks were reported in the US in 2019, roughly double the amount in 2018. The actual number of attacks, however, is likely much larger; many are never reported to federal law enforcement.
Jackson County, Georgia paid $400,000 in March to retrieve the county's data from the hackers that stole it, rather than rebuild its networks altogether. The city of Riviera Beach, Florida, paid $600,000 in a similar case in June. These are just two of the many poorly-secured local governments, businesses, and schools that have been forced to hand over millions of dollars to hackers who can buy ransomware as a service kits for cheap on the dark web.
In an effort to respond to the problem, the FBI quietly invited corporate ransomware experts to a two-day, closed-door conference in September. It was an unprecedented admission by the federal agency that it must rely on the private sector for more data to better investigate ransomware cases.
FBI cyber division section chief Herb Stapleton said the goal of this "Ransomware Summit" was for corporate executives to "help us fill in some of the gaps in the intel" on ransomware threats: "There are probably thousands of attacks every year that aren't reported to the FBI."
The most popular ransomware strains targeting UK businesses Ransomware attacks on UK businesses soar 195% 40% of cybersecurity professionals think paying ransomware demands should be illegal
One executive estimated that the companies in attendance represented more than half of key responders to enterprise ransomware attacks. Among them were representatives from tech giant IBM and law firm Kroll, sharing their knowledge from tracking attackers to helping victims recover. Additionally, cyber insurance companies and a cryptocurrency-tracing Silicon Valley startup claimed seats at the table.
Many details from the summit fall under the "TLP Amber" designation, which prohibits attendees from sharing sensitive information. However, Stapleton told CyberScoop that the FBI requested executives to anonymise victim data and share it with federal officials to "round out" the bureau's picture of the threat.
According to Stapleton, executives asked for a list of the types of information they could provide the FBI to assist in future investigations. In exchange, the bureau updated them on the current climate of ransomware threats.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Some of these private-sector entities have a lot broader reach than the FBI does," Stapleton admitted. "They have clients who are already concerned with these types of things and there's an opportunity [via the conference] for a unified message about instituting proper back-up protocols for your data."
One attendee, Coveware CEO Bill Siegel, praised the conference for fostering cooperation between federal and private ransomware specialists. Such discussions, he said, can "greatly augment investigations [and] recovery".
Stapleton agreed that the forum will lay the foundation for more thorough discourse between federal officials and the private sector on how to respond to future ransomware threats.
- 
Cisco wants to take AI closer to the edgeNews The new “integrated computing platform” from Cisco aims to support AI workloads at the edge
 - 
Software developer salaries are surging in the UK as AI skills gaps drives demandNews Stack Overflow says positive growth in developer salaries shows the community is thriving
 
- 
Volkswagen confirms security ‘incident’ amid ransomware breach claimsNews Volkswagen has confirmed a security "incident" has occurred, but insists no IT systems have been compromised.
 - 
The number of ransomware groups rockets as new, smaller players emergeNews The good news is that the number of victims remains steady
 - 
Teens arrested over nursery chain Kido hacknews The ransom attack caused widespread shock when the hackers published children's personal data
 - 
NCA confirms arrest after airport cyber disruptionNews Disruption is easing across Europe following the ransomware incident
 - 
Cyber professionals are losing sleep over late night attacksNews Hackers are biding their time and launching attacks when businesses can’t respond
 - 
Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million rewardNews The US Department of Justice is offering a reward of up to $10 million for information leading to the arrest of Volodymyr Viktorovych Tymoshchuk, an alleged ransomware criminal.
 - 
Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attackNews The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector
 - 
Ransomware attack on IT supplier disrupts hundreds of Swedish municipalitiesNews The attack on IT systems supplier Miljödata has impacted public sector services across the country