{"id":6444,"date":"2023-10-02T17:19:37","date_gmt":"2023-10-02T22:19:37","guid":{"rendered":"https:\/ransomware-to-pay-or-not-to-pay\/"},"modified":"2024-10-17T17:47:47","modified_gmt":"2024-10-17T22:47:47","slug":"ransomware-to-pay-or-not-to-pay","status":"publish","type":"post","link":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/","title":{"rendered":"Ransomware &#8211; to pay or not to pay?"},"content":{"rendered":"<p><span data-contrast=\"auto\">Ransomware is currently one of the most frequent and, above all, one of the most impactful threats for companies around the world, including Mexico.<br \/>\nIt affects companies of all types and sizes.<br \/>\nAlthough there are many ransomware variants and gangs, including Lockbit, AKIRA, APLHV, Cl0p, etc., they all have a common characteristic: their business model is based on double extortion.<br \/>\n&#8220;If you don&#8217;t pay the amount we demand, you will not only lose access to your data and systems we have encrypted, but we will publish the data we have exfiltrated.&#8221;   <\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":1,\"335551620\":1,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<p><span data-contrast=\"auto\">Regardless of the level of cybersecurity maturity of the affected company, the question often arises: should we pay?<br \/>\nWhat are the implications or consequences of paying?<br \/>\nIs it certain that, by paying, I will recover the data?<br \/>\nIf I pay, how long will it take to be operational again?     <\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":1,\"335551620\":1,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<p><span data-contrast=\"auto\">While there is no definitive answer to these unknowns, our experience in dealing with multiple incident cases, as well as reports from many researchers who have dealt with this threat around the world, allows us to provide some insights to companies, and especially to decision makers, so that they can make an informed decision based on solid evidence and data.<\/span><span data-ccp-props=\"{\"134233117\":false,\"134233118\":false,\"201341983\":0,\"335551550\":1,\"335551620\":1,\"335559685\":0,\"335559737\":0,\"335559738\":0,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<p><span data-ccp-props=\"{\"201341983\":0,\"335551550\":2,\"335551620\":2,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<p><span data-contrast=\"auto\">\u00bf<\/span><b><span data-contrast=\"auto\">What are the implications\/consequences of negotiating?<\/span><\/b><br \/>\n<span data-ccp-props=\"{\"201341983\":0,\"335551550\":2,\"335551620\":2,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<ol>\n<li data-leveltext=\"%1)\" data-font=\"\" data-listid=\"2\" data-list-defn-props=\"{\"335552541\":0,\"335559684\":-1,\"335559685\":720,\"335559991\":360,\"469769242\":[65533,0],\"469777803\":\"left\",\"469777804\":\"%1)\",\"469777815\":\"hybridMultilevel\"}\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">It is important to understand that it is not possible to have any guarantee that the decryption tool provided by the criminals after payment will work correctly, as there could have been data corrupted during the process.<br \/>\nThis will only be checked after payment, so that money will have been lost. <\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":160,\"335559740\":259}\"> <\/span><\/li>\n<\/ol>\n<ol>\n<li data-leveltext=\"%1)\" data-font=\"\" data-listid=\"2\" data-list-defn-props=\"{\"335552541\":0,\"335559684\":-1,\"335559685\":720,\"335559991\":360,\"469769242\":[65533,0],\"469777803\":\"left\",\"469777804\":\"%1)\",\"469777815\":\"hybridMultilevel\"}\" aria-setsize=\"-1\" data-aria-posinset=\"2\" data-aria-level=\"1\"><span data-contrast=\"auto\">Recovery times, even for a fee, can be long, as decryption and restoration processes are lengthy and depend on multiple factors (file\/image sizes, reconfigurations, etc.).<\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":160,\"335559740\":259}\"> <\/span><\/li>\n<\/ol>\n<ol>\n<li data-leveltext=\"%1)\" data-font=\"\" data-listid=\"2\" data-list-defn-props=\"{\"335552541\":0,\"335559684\":-1,\"335559685\":720,\"335559991\":360,\"469769242\":[65533,0],\"469777803\":\"left\",\"469777804\":\"%1)\",\"469777815\":\"hybridMultilevel\"}\" aria-setsize=\"-1\" data-aria-posinset=\"3\" data-aria-level=\"1\"><span data-contrast=\"auto\">There is no guarantee that the criminals will delete the extracted files, so even if you pay, it is possible that this information could end up being used for malicious purposes, or even end up being partially or totally leaked by means other than the attacker&#8217;s blog, at some point in the future.<\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":160,\"335559740\":259}\"> <\/span><\/li>\n<\/ol>\n<ol>\n<li data-leveltext=\"%1)\" data-font=\"\" data-listid=\"2\" data-list-defn-props=\"{\"335552541\":0,\"335559684\":-1,\"335559685\":720,\"335559991\":360,\"469769242\":[65533,0],\"469777803\":\"left\",\"469777804\":\"%1)\",\"469777815\":\"hybridMultilevel\"}\" aria-setsize=\"-1\" data-aria-posinset=\"4\" data-aria-level=\"1\"><span data-contrast=\"auto\">By paying, it will indirectly encourage the advancement of cybercrime, demonstrating not only the effectiveness of ransomware from an economic perspective, but also providing criminals with resources to continue, strengthen and expand their criminal activities.<\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":160,\"335559740\":259}\"> <\/span><\/li>\n<\/ol>\n<ol>\n<li data-leveltext=\"%1)\" data-font=\"\" data-listid=\"2\" data-list-defn-props=\"{\"335552541\":0,\"335559684\":-1,\"335559685\":720,\"335559991\":360,\"469769242\":[65533,0],\"469777803\":\"left\",\"469777804\":\"%1)\",\"469777815\":\"hybridMultilevel\"}\" aria-setsize=\"-1\" data-aria-posinset=\"5\" data-aria-level=\"1\"><span data-contrast=\"auto\">It is possible that the attacker may continue to have control and\/or persistence over the networks and systems, either through knowledge of flaws, vulnerabilities or key information of systems or networks of the victim organization, or through artifacts, tools, backdoors and\/or other mechanisms that they may have implemented.<br \/>\nPayment does not guarantee that the attacker will eliminate these mechanisms. <\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":160,\"335559740\":259}\"> <\/span><\/li>\n<\/ol>\n<ol>\n<li data-leveltext=\"%1)\" data-font=\"\" data-listid=\"2\" data-list-defn-props=\"{\"335552541\":0,\"335559684\":-1,\"335559685\":720,\"335559991\":360,\"469769242\":[65533,0],\"469777803\":\"left\",\"469777804\":\"%1)\",\"469777815\":\"hybridMultilevel\"}\" aria-setsize=\"-1\" data-aria-posinset=\"6\" data-aria-level=\"1\"><span data-contrast=\"auto\">Depending on the type of organization and the type of information leaked (or potentially leaked), you should review with the legal teams the implications before government agencies, such as BMV (Mexican Stock Exchange), Law for the protection of personal data held by individuals, or any other applicable to your operation.<br \/>\nPayment does not exempt you from these obligations. <\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":160,\"335559740\":259}\"> <\/span><\/li>\n<\/ol>\n<p><span data-ccp-props=\"{\"201341983\":0,\"335551550\":2,\"335551620\":2,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<p><span data-contrast=\"auto\">\u00bf<\/span><b><span data-contrast=\"auto\">How long does it take companies to recover after attacks?<\/span><\/b><span data-ccp-props=\"{\"201341983\":0,\"335551550\":2,\"335551620\":2,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<p><span data-contrast=\"auto\">This question is even more difficult to answer, as it depends on many factors, ranging from the level of maturity of the companies in terms of disaster recovery policies and processes (resilient backup strategy for example), IT team capabilities (systems administration and management, systems architecture, virtualization scheme, etc.), and also depends on the type of business and the type of company.  <\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559731\":708,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<p><span data-contrast=\"auto\">Recovering the organization&#8217;s operations is key and can take anywhere from a couple of days to weeks (some studies have averaged 24 days).<\/span><span data-contrast=\"auto\">1<\/span><span data-contrast=\"auto\">), but in many cases the process can take months.<br \/>\nStudies indicate that only 8% of organizations recover all of their data, after payment, and 29% recover half of their data, which takes several weeks or months to rebuild everything else.<br \/>\n24% take between 1 to 6 months, depending on the existence and availability of backups, and 84% of affected companies lost money\/received less revenue due to the attack.  <\/span><span data-contrast=\"auto\">2<\/span><span data-contrast=\"auto\">3<\/span><span data-contrast=\"auto\">. <\/span> <span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559731\":708,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<p><span data-contrast=\"auto\">As a reference, according to recent studies, organizations that have paid the ransom generally end up having a higher cost than those that do not.<br \/>\nThose that have paid, have incurred an average cost of 5.06 million USD in direct and indirect costs, during and after the attack, to which, in addition, must be added the cost of the ransom itself, which can be variable depending on the type of ransomware (from ~100,000USD to a few million USD).<br \/>\nIn those cases where the organization has not paid and has decided to recover with its own means and\/or from suppliers, the average cost is 5.17 million USD.  <\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559731\":708,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<p><span data-contrast=\"auto\">It should also be taken into account that, although the recovery time of computer systems may be relatively short, the time to recover business functionalities, the recovery of the image and trust of customers, the economic or legal consequences, could be much longer.<\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559731\":708,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<p><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n<p><span data-contrast=\"auto\">In conclusion, while the decision whether or not to pay a ransomware ransom is ultimately a very personal one for each organization and its senior management, and depends on many factors, not only technical but also business.<br \/>\nStill, the knowledge we have accumulated from hundreds of attacks over the past few years should help victims to make an informed decision for minimal impact. <\/span><span data-ccp-props=\"{\"201341983\":0,\"335551550\":6,\"335551620\":6,\"335559739\":160,\"335559740\":259}\"> <\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ransomware is currently one of the most frequent and, above all, one of the most impactful threats for companies around the world, including Mexico. It affects companies of all types and sizes. Although there are many ransomware variants and gangs, including Lockbit, AKIRA, APLHV, Cl0p, etc., they all have a common characteristic: their business model [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":6257,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[48],"tags":[],"class_list":["post-6444","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Ransomware is currently one of the most frequent and, above all, one of the most impactful threats for companies around the world, including Mexico. It affects companies of all types and sizes. Although there are many ransomware variants and gangs, including Lockbit, AKIRA, APLHV, Cl0p, etc., they all have a common characteristic: their business model\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Raul B. Netto\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Ransomware \u2013 to pay or not to pay? - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"Ransomware is currently one of the most frequent and, above all, one of the most impactful threats for companies around the world, including Mexico. It affects companies of all types and sizes. Although there are many ransomware variants and gangs, including Lockbit, AKIRA, APLHV, Cl0p, etc., they all have a common characteristic: their business model\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2023\/12\/e83d2271-52df-4878-98a8-31c356792b1c.jpeg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2023\/12\/e83d2271-52df-4878-98a8-31c356792b1c.jpeg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-10-02T22:19:37+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-10-17T22:47:47+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Ransomware \u2013 to pay or not to pay? - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Ransomware is currently one of the most frequent and, above all, one of the most impactful threats for companies around the world, including Mexico. It affects companies of all types and sizes. Although there are many ransomware variants and gangs, including Lockbit, AKIRA, APLHV, Cl0p, etc., they all have a common characteristic: their business model\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2023\/12\/e83d2271-52df-4878-98a8-31c356792b1c.jpeg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#blogposting\",\"name\":\"Ransomware \\u2013 to pay or not to pay? - Beacon Lab\",\"headline\":\"Ransomware &#8211; to pay or not to pay?\",\"author\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/raul-benitez\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/e83d2271-52df-4878-98a8-31c356792b1c.jpeg\",\"width\":1024,\"height\":1024},\"datePublished\":\"2023-10-02T17:19:37-06:00\",\"dateModified\":\"2024-10-17T17:47:47-06:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#webpage\"},\"articleSection\":\"Uncategorized\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"position\":2,\"name\":\"Uncategorized\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#listItem\",\"name\":\"Ransomware &#8211; to pay or not to pay?\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#listItem\",\"position\":3,\"name\":\"Ransomware &#8211; to pay or not to pay?\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/raul-benitez\\\/#author\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/raul-benitez\\\/\",\"name\":\"Raul B. Netto\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bccecadf0d687d48d3ba43e84b46c2fe6e62eba36dd58b702fdb0feed7fdcfa5?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Raul B. Netto\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/\",\"name\":\"Ransomware \\u2013 to pay or not to pay? - Beacon Lab\",\"description\":\"Ransomware is currently one of the most frequent and, above all, one of the most impactful threats for companies around the world, including Mexico. It affects companies of all types and sizes. Although there are many ransomware variants and gangs, including Lockbit, AKIRA, APLHV, Cl0p, etc., they all have a common characteristic: their business model\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/raul-benitez\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/author\\\/raul-benitez\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/e83d2271-52df-4878-98a8-31c356792b1c.jpeg\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#mainImage\",\"width\":1024,\"height\":1024},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/ransomware-to-pay-or-not-to-pay\\\/#mainImage\"},\"datePublished\":\"2023-10-02T17:19:37-06:00\",\"dateModified\":\"2024-10-17T17:47:47-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Ransomware \u2013 to pay or not to pay? - Beacon Lab","description":"Ransomware is currently one of the most frequent and, above all, one of the most impactful threats for companies around the world, including Mexico. It affects companies of all types and sizes. Although there are many ransomware variants and gangs, including Lockbit, AKIRA, APLHV, Cl0p, etc., they all have a common characteristic: their business model","canonical_url":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#blogposting","name":"Ransomware \u2013 to pay or not to pay? - Beacon Lab","headline":"Ransomware &#8211; to pay or not to pay?","author":{"@id":"https:\/\/beaconlab.us\/en\/author\/raul-benitez\/#author"},"publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2023\/12\/e83d2271-52df-4878-98a8-31c356792b1c.jpeg","width":1024,"height":1024},"datePublished":"2023-10-02T17:19:37-06:00","dateModified":"2024-10-17T17:47:47-06:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#webpage"},"isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#webpage"},"articleSection":"Uncategorized"},{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","name":"Uncategorized"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","position":2,"name":"Uncategorized","item":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#listItem","name":"Ransomware &#8211; to pay or not to pay?"},"previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#listItem","position":3,"name":"Ransomware &#8211; to pay or not to pay?","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/#listItem","name":"Uncategorized"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"Person","@id":"https:\/\/beaconlab.us\/en\/author\/raul-benitez\/#author","url":"https:\/\/beaconlab.us\/en\/author\/raul-benitez\/","name":"Raul B. Netto","image":{"@type":"ImageObject","@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/bccecadf0d687d48d3ba43e84b46c2fe6e62eba36dd58b702fdb0feed7fdcfa5?s=96&d=mm&r=g","width":96,"height":96,"caption":"Raul B. Netto"}},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#webpage","url":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/","name":"Ransomware \u2013 to pay or not to pay? - Beacon Lab","description":"Ransomware is currently one of the most frequent and, above all, one of the most impactful threats for companies around the world, including Mexico. It affects companies of all types and sizes. Although there are many ransomware variants and gangs, including Lockbit, AKIRA, APLHV, Cl0p, etc., they all have a common characteristic: their business model","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#breadcrumblist"},"author":{"@id":"https:\/\/beaconlab.us\/en\/author\/raul-benitez\/#author"},"creator":{"@id":"https:\/\/beaconlab.us\/en\/author\/raul-benitez\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2023\/12\/e83d2271-52df-4878-98a8-31c356792b1c.jpeg","@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#mainImage","width":1024,"height":1024},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/#mainImage"},"datePublished":"2023-10-02T17:19:37-06:00","dateModified":"2024-10-17T17:47:47-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Ransomware \u2013 to pay or not to pay? - Beacon Lab","og:description":"Ransomware is currently one of the most frequent and, above all, one of the most impactful threats for companies around the world, including Mexico. It affects companies of all types and sizes. Although there are many ransomware variants and gangs, including Lockbit, AKIRA, APLHV, Cl0p, etc., they all have a common characteristic: their business model","og:url":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2023\/12\/e83d2271-52df-4878-98a8-31c356792b1c.jpeg","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2023\/12\/e83d2271-52df-4878-98a8-31c356792b1c.jpeg","og:image:width":1024,"og:image:height":1024,"article:published_time":"2023-10-02T22:19:37+00:00","article:modified_time":"2024-10-17T22:47:47+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Ransomware \u2013 to pay or not to pay? - Beacon Lab","twitter:description":"Ransomware is currently one of the most frequent and, above all, one of the most impactful threats for companies around the world, including Mexico. It affects companies of all types and sizes. Although there are many ransomware variants and gangs, including Lockbit, AKIRA, APLHV, Cl0p, etc., they all have a common characteristic: their business model","twitter:creator":"@BeaconLabMX","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2023\/12\/e83d2271-52df-4878-98a8-31c356792b1c.jpeg"},"aioseo_meta_data":{"post_id":"6444","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2024-10-11 18:20:50","updated":"2025-09-24 05:38:20","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/category\/uncategorized\/\" title=\"Uncategorized\">Uncategorized<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tRansomware \u2013 to pay or not to pay?\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Uncategorized","link":"https:\/\/beaconlab.us\/en\/category\/uncategorized\/"},{"label":"Ransomware &#8211; to pay or not to pay?","link":"https:\/\/beaconlab.us\/en\/ransomware-to-pay-or-not-to-pay\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/6444","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/comments?post=6444"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/6444\/revisions"}],"predecessor-version":[{"id":6829,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/posts\/6444\/revisions\/6829"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/6257"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=6444"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/categories?post=6444"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/tags?post=6444"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}