Victims Call Hackers’ Bluff as Ransomware Deadline Nears
With the clock ticking on whether a global hacking attack would wipe out his data, Bolton Jiang had no intention of paying a 21st-century ransom.
Since a week ago, when the global malware attack hit people, companies and institutions in dozens of countries around the world, Mr. Jiang has been busily fixing and replacing computers at the electronics company where he works in Shanghai before the deadline kicks in. Paying is a bother, he said — and there was no guarantee he would get his data back.
“Even if you do pay, you won’t necessarily be able to open the files that are hit by the virus,” he said. “There is no solution to it.”
Tens of thousands of computer users around the world faced the same dilemma on Friday, their last chance to pay the anonymous hackers behind the ransomware attack known as WannaCry that struck last week. The attack exposed the widespread vulnerability of computers and offered a peek at how a new type of crime could be committed on a global scale.
As part of the hacking, attackers demanded that individuals pay a fee to regain control of their machines, or face losing their data.
The latest ransomware attack was particularly virulent, experts warned, because it had been based on stolen software from the National Security Agency. Law enforcement agencies in the United States and elsewhere have been hunting for the culprits, with attention now focusing on hackers linked to North Korea.
Despite a week of widespread disruption, the total paid in ransom so far looks relatively modest. An online tracking system early on Friday showed that the amount sent in the electronic currency Bitcoin to accounts listed by the attackers had begun to plateau on Wednesday, and by early Friday had reached about $90,000. Early estimates of what the virus could ultimately earn ranged into the tens of millions or even hundreds of millions of dollars. Victims have seven days to pay from when their computers were originally infected with the malware, so the deadline will vary from case to case.
A number of people and companies have struck a defiant tone. The Japanese conglomerate Hitachi, which had been identified in the news media as a victim, declined to confirm those reports on Friday but said that it had no intention of paying a ransom and that it aimed to be fully secure against future attacks by Monday.
Nissan Motor, another Japanese industrial giant, also said it would not pay a ransom. Its British facility was affected when the attack first rippled through the internet a week ago, but it said it had not lost data.
Owners of the more than 200,000 computers across the globe that have been hit by the malware face similar decisions. Those affected, including hospitals, government offices and universities, have lost access to important files such as business information, term papers and even medical records that could involve matters of life or death.
Yet cybersecurity experts have generally advised those affected not to pay.
“It costs the perpetrators peanuts to carry out an attack like this,” said Rafael Sanchez, international breach response manager at Beazley, an insurer in London that has handled thousands of ransomware attacks for corporate clients. “And any ransom will only likely lead to more attacks,” he added.
While some who paid regained access to their files, according to the Finnish cybersecurity firm F-Secure, security analysts caution that there is no guarantee all WannaCry victims will get their files back. The fact that the attackers listed only three addresses as payment destinations means it would be difficult to determine which victims had paid, and therefore whose files to decrypt.
“It looks like the attackers had no intent in decrypting anything,” said Tom Robinson, co-founder of Elliptic, a company in London that tracks online financial transactions involving virtual currencies that helps organizations respond to digital attacks.
As victims faced an agonizing choice on Friday over whether to pay or perhaps to lose their data, cybersecurity experts said that they had developed a potential way to decrypt individual machines without having to hand over the ransom. The technique, however, depended on how long infected computers had been hijacked by the online attackers, and required a high level of technical expertise.
According to law enforcement agencies, paying could leave victims vulnerable to being targeted again, and also presents a technical challenge for the many people affected who have never used Bitcoin before.
Many are not familiar with the electronic currency, which does not answer to any of the world’s central banks. Many national governments and institutions also have rules about not paying ransoms.
In Britain, whose National Health Service was one of the largest organizations affected by the ransomware attack, some medical institutions across England and Scotland were still struggling to get back on their feet after last Friday’s attack.
Barts Health, one of the country’s largest hospital groups, said that it had been forced to cancel 20 percent of outpatient appointments, as well as to cut back on nonemergency surgeries.
In Berhampur, a city of about 380,000 on India’s eastern coast, two computers at the Berhampur City Hospital were hit by the WannaCry malware. Dr. Saroj Mishra, assistant health officer for the surrounding district of Ganjam, said that most of the data had been recovered — and that health officials had no intention of paying the hackers.
“We don’t have the permission to pay the hackers,” Dr. Mishra said. He added, “there is no question of compromising. It is a matter of investigation.”
In other places, those affected simply cannot afford to pay.
In China, where pirated software is believed to have contributed to the ransomware’s spread, about 4,000 of the 40,000 institutions affected are educational establishments. On Chinese social media, many students reported being locked out of final term papers.
“The hacker asked for $300 to $600,” said Zhu Huanjie, a college student in Hangzhou. “Average students can’t afford that.”
The identity of the perpetrators remains unclear. Some initial signs point to hackers that cybersecurity specialists previously linked to North Korea, but the experts warn that the evidence is far from conclusive.
Some attacks could also come from copycats, experts say, muddying attempts to catch those behind the initial cyberattack.
Xu Hengyu, information technology manager of a Shanghai entertainment company, Renxing Pictures, said the firm had intended to send more than $720 to hackers threatening to delete two months’ worth of data. But when Mr. Xu tried to negotiate the price down, he said the hackers responded in Chinese and told him he could wire the money to a Chinese bank account in China’s currency, the renminbi, rather than in Bitcoin. Mr. Xu said he was unsure whether the hackers were the same as those behind the WannaCry attack.
“We thought about reporting to the police, but we haven’t so far,” he said. “We thought if this problem could be solved by the direct payment, we’d rather stay that way and not go to the police, as the police must already have many cases.”
He added, “We still prioritize data recovery over everything else.”