{"id":4807,"date":"2024-08-09T12:05:56","date_gmt":"2024-08-09T17:05:56","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/media-and-victims-find-common-ground-against-hackers"},"modified":"2024-08-09T12:05:56","modified_gmt":"2024-08-09T17:05:56","slug":"media-victims-find-common-ground-against-hackers","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/09\/media-victims-find-common-ground-against-hackers\/","title":{"rendered":"Media &amp; Victims Find Common Ground Against Hackers"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt0f8a3831c5ec4df5\/66b62027b9f55c172efc4054\/Hackers_changed_the_media-4.jpeg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">BLACK HAT USA &#8211; Las Vegas \u2013 Wednesday, Aug. 9 \u2013 <\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When threat actors breach an organization and steal data, perhaps the worst thing imaginable to victims is the extortion attempts they face from the criminals behind the breach. These days, there is an added threat that hackers like to hang over their victims&#8217; heads: going to the press.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In a Black Hat panel titled <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.blackhat.com\/us-24\/briefings\/schedule\/index.html#how-hackers-changed-the-media-and-the-media-changed-hackers-40943\" rel=\"noopener\">&#8220;How Hackers Changed the Media (and the Media Changed the Hackers),&#8221;<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;Lorenzo Franceschi-Bicchierai, senior writer and editor of cybersecurity at TechCrunch;&nbsp;Robert McMillan, reporter at The Wall Street Journal; and Sadia Mirza, partner at Troutman Pepper, joined Sherri Davidoff, CEO of LMG Security, to discuss the new ways hackers are trying to gain the attention of journalists and shape the narrative of the media when a breach occurs.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Building a Brand\">Building a Brand<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security incidents typically begin with a criminal group of hackers stealing data from an organization and demanding payment. Whether it be $500,000 or millions of dollars, if a criminal entity is virtually unknown, it\u2019s likely they know few will take them seriously.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The group&#8217;s desire to build a name and reputation for themselves prompts what McMillan describes as the professionalization of these criminal groups, where they attempt to gain credibility \u2014 and get victims to fear or respect them. These groups are eager for media attention and will use the threat of going to the press against victims to urge them pay up. They often reach out to journalists themselves or to pages on media websites after a breach occurs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">But just because a hacker reaches out to the media about a breach doesn&#8217;t mean a journalist is immediately inclined to write about it.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Sometimes they reach out and they are not telling the whole truth, or sometimes they\u2019re making it up,&#8221; said&nbsp;Franceschi-Bicchierai, who noted that while his publication aims to write several stories each week, if an incident is not 100% verifiable, it is fine to skip it or wait until more is known. He emphasized how important it is for journalists to verify claims that are being made \u2014 one source, especially one as dubious as a criminal hacker, does not make a story worth pursuing.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Only One Part of the Story\">Only One Part of the Story<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s&nbsp;not just journalists who take what a hacker says with a grain of salt. Troutman Pepper&#8217;s Mirza noted that a threat to go to the media is just one more factor to consider when advising clients who have been breached.&nbsp;The fact that these hackers want to maintain their brand is another factor to consider.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;An organization would be more inclined to pay a threat actor group that has a reputation to uphold its commitment,&#8221; Mirza said. Ultimately, however, the goals of the media and incident and investigation teams are very different.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We&#8217;re not trying to break a story,&#8221; she said. &#8220;We are trying to get our arms around the full scope of what\u2019s happened so that we can provide organized information about the response.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Finding a Middle Ground\">Finding a Middle Ground<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There are stark differences when media and investigators approach a breach from disparate standpoints. On one end, investigation teams on behalf of their compromised client are tight-lipped, taking time to figure out exactly what has happened. On the other end, journalists feel governed by their commitment to tell the truth and inform the public about what is happening as accurately as possible. All the while, hackers are trying to gain something from each side: getting media attention and extorting victims.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">How can both be appeased, while also not falling into the trap that hackers have laid out?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It first starts with understanding what an incident response process looks like, said Mirza.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;A forensic investigation could take weeks,&#8221; she said. Victims are not comfortable sharing information as soon as the press may want them to because they don\u2019t have all the information they need or want. Sometimes there are hiccups along the road in response and in figuring out what next steps to take; whether it be negotiating a number for the payment, deciding to pay, figuring out how many people have been impacted, or what information has been stolen.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">McMillan said this is why clarity and communication from victims is essential.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;You could communicate that,&#8221; he said. &#8220;We can understand complicated things. You don&#8217;t just have to have a [ransom] number, but you want to engage and explain where you are and why things may be a certain way.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/media-and-victims-find-common-ground-against-hackers\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>BLACK HAT USA &#8211; Las Vegas \u2013 Wednesday, Aug. 9<\/p>\n","protected":false},"author":12,"featured_media":4808,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4807","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/media-victims-find-common-ground-against-hackers-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4807","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4807"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4807\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4808"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}