{"id":10229,"date":"2022-05-05T05:00:43","date_gmt":"2022-05-05T09:00:43","guid":{"rendered":"https:\/\/jolt.richmond.edu\/?p=10229"},"modified":"2022-04-10T17:03:00","modified_gmt":"2022-04-10T21:03:00","slug":"regulating-ransomware-under-united-states-law","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2022\/05\/05\/regulating-ransomware-under-united-states-law\/","title":{"rendered":"Regulating Ransomware Under United States Law"},"content":{"rendered":"<p>By Liz Jacobs<\/p>\n<p>&nbsp;<\/p>\n<p>Ransomware is a type of malicious software cybercriminals use to block you from accessing your own data.<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a> Ransomware remains a global cybersecurity threat, as it is a unique kind of attack because it is the one cybercrime that has a high direct return of investment associated with it, by holding the victims&#8217; ransom for financial payment.<a href=\"#_ftn2\" name=\"_ftnref2\">[2]<\/a> On a global scale, cybercriminals will continue to focus their efforts on this revenue-generating stream.<a href=\"#_ftn3\" name=\"_ftnref3\">[3]<\/a>\u00a0There is no industry that is exempt from the ransomware threat,<a href=\"#_ftn4\" name=\"_ftnref4\">[4]<\/a>\u00a0and it requires constant focus, assessment, and review to ensure that critical information assets remain safeguarded and protected against it.<a href=\"#_ftn5\" name=\"_ftnref5\">[5]<\/a><\/p>\n<p>Ransomware involves digital extortionists encrypting the files on your system and adding extensions to the attacked data and holding it \u201chostage\u201d until the demanded ransom is paid.<a href=\"#_ftn6\" name=\"_ftnref6\">[6]<\/a>\u00a0Ransomware enters your network in a variety of ways, the most popular is a download via a spam email attachment.<a href=\"#_ftn7\" name=\"_ftnref7\">[7]<\/a> The download then launches the ransomware program that attacks your system.<a href=\"#_ftn8\" name=\"_ftnref8\">[8]<\/a><\/p>\n<p>Ransomware can occur in both a large scheme and a smaller scale. It can occur to individuals, small businesses, large businesses, and even the government. There are two types of ransomware, crypto and locker.<a href=\"#_ftn9\" name=\"_ftnref9\">[9]<\/a> Crypton Ransomware targets the data and file systems on the device versus the device itself, so the computer is functional except for the ability to access the encrypted files.<a href=\"#_ftn10\" name=\"_ftnref10\">[10]<\/a> Locker ransomware prevents the victim from using the system by locking components or all of the system.<a href=\"#_ftn11\" name=\"_ftnref11\">[11]<\/a><\/p>\n<p>Biden has referenced ransomware to \u201cfit comfortably within a legal framework,\u201d the United States should expressly endorse three interdependent legal positions; to wit, that: \u201c1) Sovereignty is a rule of international law; 2) States must exercise due diligence to terminate hostile cyber operations from their territory; and 3) States may engage in collective countermeasures.\u201d\u00a0<a href=\"#_ftn12\" name=\"_ftnref12\">[12]<\/a><\/p>\n<p>The United States faces persistent and increasingly sophisticated malicious cyber campaigns that threaten the public sector, the private sector, and ultimately the American people\u2019s security and privacy. There are many different arguments on how to address this nationwide problem. For one, the government and private sector work together to help decrease ransomware attacks by using preventative measures and reporting attacks.<a href=\"#_ftn13\" name=\"_ftnref13\">[13]<\/a> This ultimately comes in shape by requiring the private sector to work with the government in reporting ransomware attacks. Biden has signed an executive order meant to strengthen the federal government\u2019s cybersecurity standards for software and technology services it uses, which a senior administration official described as a fundamental shift in the federal government\u2019s approach to cybersecurity incidents away from spot responses and toward trying to prevent them from happening in the first place.<a href=\"#_ftn14\" name=\"_ftnref14\">[14]<\/a><\/p>\n<p>Others argue that the government cannot and should not regulate the private sector to prevent these actions. This argument believes that the government should regulate their own technology and let private businesses control their own. Ultimately, \u200bthe growth of unregulated cryptocurrency, one official said, is \u201cwhat\u2019s driven the growth of ransomware.\u201d<a href=\"#_ftn15\" name=\"_ftnref15\">[15]<\/a><\/p>\n<p>As mentioned, ransomware is a type of malicious software cybercriminals use to block you from accessing your own data.<a href=\"#_ftn16\" name=\"_ftnref16\">[16]<\/a> Ransomware effects vary depending upon who the victim of the attack is. As a country, we are reliant on technology, so any sort of ransomware attack can make us extremely vulnerable to other sorts of attacks. Overall, the increase in ransomware has been a concern for the United States government and lawmakers. The impact of such legislation and choice of governmental involvement will ultimately affect the country\u2019s safety from such attacks.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> <em>How Ransomware Works<\/em>, Unitrends, https:\/\/www.unitrends.com\/solutions\/ransomware-education#:~:text=Ransomware%20Definition,from%20accessing%20your%20own%20data.&amp;text=During%20this%20time%2C%20the%20cybercriminals,use%20of%20backups%20for%20recovery.<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> Alicia Hope, <em>A Suspected Ransomware Cyber Attack Shuts Down World\u2019s Fifth Largest Beermaker Molson Coors<\/em>, CPO Magazine (Mar. 19, 2021), https:\/\/www.cpomagazine.com\/cyber-security\/a-suspected-ransomware-cyber-attack-shuts-down-worlds-fifth-largest-beermaker-molson-coors\/.<\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[3]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> <em>Ransomware: The Trust Cost to Business<\/em>, Cybereason, https:\/\/www.cybereason.com\/hubfs\/dam\/collateral\/ebooks\/Cybereason_Ransomware_Research_2021.pdf.<\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> Alicia Townsend, <em>Watch Out! Cyber Criminals Are Coming<\/em>, Onelogin (Jan. 5, 2022), https:\/\/www.onelogin.com\/blog\/cybercriminals-coming.<\/p>\n<p><a href=\"#_ftnref6\" name=\"_ftn6\">[6]<\/a> <em>How Ransomware Works<\/em>, <em>supra<\/em> note 1.<\/p>\n<p><a href=\"#_ftnref7\" name=\"_ftn7\">[7]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref8\" name=\"_ftn8\">[8]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref9\" name=\"_ftn9\">[9]<\/a> <em>Ransomware Attacks and Types \u2013 How Encryption Trojans Differ<\/em>, Kaspersky, https:\/\/www.kaspersky.com\/resource-center\/threats\/ransomware-attacks-and-types.<\/p>\n<p><a href=\"#_ftnref10\" name=\"_ftn10\">[10]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref11\" name=\"_ftn11\">[11]<\/a> <em>Id.<\/em><\/p>\n<p><a href=\"#_ftnref12\" name=\"_ftn12\">[12]<\/a> Gary Corn, <em>International Law\u2019s Role in Combating Ransomware<\/em>, Just Security (Aug. 23, 2021), https:\/\/www.justsecurity.org\/77845\/international-laws-role-in-combating-ransomware\/.<\/p>\n<p><a href=\"#_ftnref13\" name=\"_ftn13\">[13]<\/a> <em>Press Release, Treasury Takes Robust Actions to Counter Ransomware<\/em>, U.S. Dep\u2019t of the Treasury (Sept. 21, 2021), https:\/\/home.treasury.gov\/news\/press-releases\/jy0364.<\/p>\n<p><a href=\"#_ftnref14\" name=\"_ftn14\">[14]<\/a> Maria Henriquez, <em>President Biden Signs Executive Order to Strengthen U.S. Cybersecurity Defenses<\/em>, Security Magazine (May 13, 2021), https:\/\/www.securitymagazine.com\/articles\/95197-president-biden-signs-executive-order-to-strengthen-us-cybersecurity-defenses.<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[15]<\/a> Ellen Nakashima, Hamza Shaban &amp; Rachel Lerman, <em>The Biden Administration Seeks to Rally Allies and the Private Sector Against the Ransomware Threat<\/em>, Wash. Post (June 4, 2021, 2:24 PM), https:\/\/www.washingtonpost.com\/business\/2021\/06\/04\/white-house-fbi-ransomware-attacks\/.<\/p>\n<p><a href=\"#_ftnref16\" name=\"_ftn16\">[16]<\/a> <em>How Ransomware Works<\/em>, <em>supra<\/em> note 1.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-10232\" src=\"https:\/\/jolt.richmond.edu\/files\/2022\/05\/Capture.png\" alt=\"\" width=\"588\" height=\"376\" \/><\/p>\n<p>Image source: https:\/\/krebsonsecurity.com\/category\/ransomware\/<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Liz Jacobs &nbsp; Ransomware is a type of malicious software cybercriminals use to block you from accessing your own data.[1] Ransomware remains a global cybersecurity threat, as it is a unique kind of attack because it is the one cybercrime that has a high direct return of investment associated with it, by holding the [&hellip;]<\/p>\n","protected":false},"author":5136,"featured_media":10230,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366],"tags":[],"class_list":["post-10229","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-post"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/blog.richmond.edu\/jolt\/files\/2022\/04\/ransomware.png","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-2EZ","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/10229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/5136"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=10229"}],"version-history":[{"count":2,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/10229\/revisions"}],"predecessor-version":[{"id":10233,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/10229\/revisions\/10233"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media\/10230"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=10229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=10229"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=10229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}