Tech

Data Is More Exposed to Digital Ransom Than Ever

Image via Flickr/CC

In October, hackers unleashed CryptoLocker, a piece of malware that raids the hard drives of computers running Microsoft Windows, encrypts any personal data, and holds it for ransom. To retrieve the purloined data, victims are forced to pay ransom money in Bitcoins. And, last week, the hacker team Inj3ct0r targeted the MacRumors forums, advising forum owners to pay for a security patch in yet another type of digital currency.

Though neither of these hacks are especially epic—users must foolishly download CryptoLocker through email, while MacRumors forums aren’t exactly vaults of vital data—they do suggest a future in which personal data is increasingly held for ransom. With people living their lives more and more online in the form of images, browsing history, social media sharing, cloud storage, etc., the specter of personal data hostage-taking seems a very real one.

Videos by VICE

And so this type of threat shouldn’t be limited to downloadable ransomware viruses, but extended to malicious hackers stealing data in a variety of other ways. Nor is this simply the prospect of personal computers being hacked, but of information raids on very specific servers storing personal data.

A team of hackers hoping to make a little cash could, for example, exploit a dating site’s servers, threatening to reveal users’ sexual proclivities until a ransom is paid. Or imagine hackers staging a raid on medical facility servers, where they could obtain personal medical records and do with it what they wish.

In fact, something like this happened in July 2012 to the Surgeons of Lake County, a small medical practice located in Libertyville, a northern Illinois suburb. As revealed by the healthcare provider’s doctors, hackers accessed electronic medical records and emails, encrypted the data, and asked for digital ransom in exchange for the password to the stolen cache. It only reinforces the truth that companies dealing with sensitive personal information need exceptionally strong security.

The reality here is that the amount of data we put out into the digital ether is tremendous and ever-growing. To malicious hackers it is a virtual treasure trove—an ocean of potential booty. And with use of anonymous digital currencies and the Dark Web on the rise, getting paid could potentially become easier and even less risky for the motivated malicious hacker.

Add to this another reality laid bare by Edward Snowden’s NSA leaks and growth in private sector surveillance: data mining’s astonishing efficiency means that not only do ethically-challenged governments have access to user data, but so do malicious hackers. The question then becomes, if we are so appalled at our data exposure to governments and corporations, then why aren’t we as worried about malicious hackers who could hold our data hostage? The Electronic Frontier Foundation, for instance, has been arguing for months now that the NSA’s weakening of the internet is exposing us all to malicious hacking.

Until the NSA’s recklessness on this front is addressed (in any substantive fashion), what can be done to protect our data? First of all, change logins and passwords often. It goes without saying that users should not store critical data on their computer’s hard drive; but, some people are just that stupid. Back up vital data on multiple external hard drives and thumb drives. (Note: CryptoLocker’s ransomware can encrypt files from external hard drives and even Dropbox and Google Drive, so be aware of that.) Updating anti-virus software is common sense, but still worth mentioning, as is being aware of the latest security vulnerabilities.

Internet users should also be discriminating when it comes to who and what they are sharing. If a person has any doubts about who could possibly see their sensitive information, then they shouldn’t send a message containing this data. Such caution is not paranoia but smart internet usage. Also, delete inbox messages that may have sensitive information exchanges in them. Ask the recipient to do the same.

More people should also consider using PGP (Pretty Good Privacy) for email communications. PGP requires the email sender and recipient to encrypt their communications, which they can access (decrypt) through their private keys. Mozilla’s Thunderbird, which is easy to set up, allows its email users to send and receive encrypted messages.

These pro-active data security measures are easily available to the individual, but how should we feel when it comes to the companies and organizations to whom we entrust our sensitive data? Facebook and Twitter can both be hacked, as can email clients, though they work feverishly to patch any security flaws. Again, perhaps the best thing to do is be discriminating in what we share, but also be sure that the entities storing our data are secure and use strong encryption.

Short of all of this, make greater use of that antiquated form of communication favored by spies and underworld criminals: face-to-face information exchange. Hackers won’t ever exploit that system.

Thank for your puchase!
You have successfully purchased.