TechCrunch News 01月14日
UK plans to ban public sector organizations from paying ransomware hackers
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

英国政府正考虑禁止公共部门和关键基础设施组织支付赎金,以打击网络犯罪。提案中,地方议会、学校和NHS信托等公共机构将被禁止向勒索软件黑客付款,此举旨在切断网络犯罪分子的资金来源。此前,英国公共部门遭受多次网络攻击,其中NHS病理实验室供应商Synnovis的网络攻击导致大量患者数据泄露,并造成医疗服务中断。新提案还将禁止能源和通信等关键基础设施组织支付赎金,并要求未被禁的受害者向政府报告事件。政府还将有权阻止向受制裁实体支付赎金。英国政府希望通过这些措施应对勒索软件威胁,并切断犯罪网络的资金链。

🚫 英国政府拟议禁止公共部门,如地方议会、学校和NHS信托等,向勒索软件黑客支付赎金,旨在直接打击网络犯罪的商业模式。

🚨 关键基础设施组织,包括能源和通信行业的企业,也将被禁止支付赎金,以减少其对网络攻击的脆弱性。

📢 英国还计划建立强制性的勒索软件事件报告制度,要求未被禁止的受害者向政府报告网络攻击事件。

🔒 政府将有权阻止向受制裁实体支付赎金,以防止资金流向可能威胁国家安全的组织。

🇷🇺 英国政府指出,许多网络攻击事件与俄罗斯有关联的犯罪团伙有关,这些团伙对英国的关键基础设施构成直接威胁。

U.K. public sector and critical infrastructure organizations could be banned from making ransom payments under new proposals from the U.K. government. 

The U.K.’s Home Office launched a consultation on Tuesday that proposes a “targeted ban” on ransomware payments. Under the proposal, public sector bodies — including local councils, schools, and NHS trusts — would be banned from making payments to ransomware hackers, which the government says would “strike at the heart of the cybercriminal business model.” 

This government proposal comes after a wave of cyberattacks targeting the U.K. public sector. The NHS last year declared a “critical” incident following a cyberattack on pathology lab provider Synnovis, which led to a massive data breach of sensitive patient data and months of disruption, including canceled operations and the diversion of emergency patients. According to new data seen by Bloomberg, the cyberattack on Synnovis resulted in harm to dozens of patients, leading to long-term or permanent damage to their health in at least two cases. 

The newly outlined U.K. government proposals would also make it a criminal offense for critical infrastructure organizations, such as businesses in the energy and communications sectors, to make ransom payments in the event of a ransomware attack. U.K. government departments are already banned from paying ransomware gangs. 

The U.K. proposals also detail a new mandatory reporting regime for ransomware incidents, which would require that cyberattack victims who are not covered by the ban report the incident to the government. Another proposal suggests a program aimed at preventing the payment of ransoms to sanctioned entities, which the government will have the power to block. 

Security minister Dan Jarvis said: “With an estimated $1 billion flowing to ransomware criminals globally in 2023, it is vital we act to protect national security as a key foundation upon which this government’s Plan for Change is built.

“These proposals help us meet the scale of the ransomware threat, hitting these criminal networks in their wallets and cutting off the key financial pipeline they rely upon to operate,” said Jarvis.

According to data shared by the Home Office on Tuesday, the U.K.’s National Cyber Security Center managed 430 cyber incidents over the year ending August 2024, including 13 “nationally significant” ransomware incidents. These were carried out “largely by Russia-affiliated criminal gangs,” the Home Office said, which continue to pose an “immediate and disruptive threat” to the U.K.’s critical national infrastructure. 

The U.K.’s National Crime Agency took action against one of these gangs in October 2024, unmasking an alleged affiliate of the prolific Russia-linked LockBit ransomware group. LockBit was linked to an earlier cyberattack on NHS IT vendor Advanced.

The U.K. did not say if it plans to bring the measure before lawmakers in Parliament. The Home Office’s consultation is set to end in April 2025.

In the United States, the federal government has long urged against paying ransom demands but has stopped short of imposing an outright national ban on ransom payments. However, in October 2023, a U.S.-led alliance of more than 40 countries vowed as governments not to pay ransoms to cybercriminals in a bid to starve the hackers from their source of income.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

勒索软件 网络安全 英国政府 公共部门 关键基础设施
相关文章