{"id":6548,"date":"2017-05-13T23:44:51","date_gmt":"2017-05-14T03:44:51","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=6548"},"modified":"2019-03-08T19:52:08","modified_gmt":"2019-03-09T00:52:08","slug":"volume23_annualsurvey_sherer","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2017\/05\/13\/volume23_annualsurvey_sherer\/","title":{"rendered":"Ransomware \u2013 Practical and Legal Considerations for Confronting the New Economic Engine of the Dark Web"},"content":{"rendered":"<p style=\"text-align: left;\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-347\" src=\"https:\/\/blog.richmond.edu\/jolt\/files\/2012\/11\/pdf_icon.png\" alt=\"Download PDF\" width=\"50\" height=\"50\" \/><a href=\"https:\/\/blog.richmond.edu\/jolt\/files\/2017\/05\/Sherer-Final-clean-.pdf\">Sherer Publication Version PDF<\/a><\/p>\n<p style=\"text-align: center;\">Cite as: James A. Sherer, Melinda L. McLellan, Emily R. Fedeles, and Nichole L. Sterling,\u00a0<em>Ransomware \u2013 Practical and Legal Considerations for Confronting the New Economic Engine of the Dark Web<\/em>,\u00a023 Rich. J.L. &amp; Tech. Ann. Survey (2017), http:\/\/jolt.richmond.edu\/2017\/04\/30\/volume23_annualsurvey_sherer\/.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\">By: James A. Sherer,* Melinda L. McLellan,** Emily R. Fedeles,*** and Nichole L. Sterling****<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p style=\"text-align: center;\"><strong>I. \u00a0 \u00a0Introduction<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Ransomware is malicious software that encrypts data on a device or a system, then bars access to, or recovery of, that data until the owner has paid a ransom.<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a> This type of threat has existed in some shape or form since at least 1989,<a href=\"#_ftn2\" name=\"_ftnref2\">[2]<\/a> but over the past two years the frequency and scope of attacks have increased to alarming levels. In response, the U.S. Federal Trade Commission (FTC) identified Ransomware as \u201cone of the most serious online threats facing people and businesses\u201d in 2016 as well as \u201cthe most profitable form of malware criminals use,\u201d<a href=\"#_ftn3\" name=\"_ftnref3\">[3]<\/a> and the FBI developed a special working group dedicated to fighting it.<a href=\"#_ftn4\" name=\"_ftnref4\">[4]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[2]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Considering that Ransomware emerged \u201cat the dawn of the Internet revolution,\u201d<a href=\"#_ftn5\" name=\"_ftnref5\">[5]<\/a> even before the development of formalized Internet law and policy, attorneys have now had a bit of time to become familiar with its operation and effects and to contemplate reasonable and legitimate responses to Ransomware attacks. Despite the intervening decades, and although Ransomware as a process and business are (somewhat) better understood, the legal implications of Ransomware attacks are still up for debate, and there is no simple answer to the question of how Ransomware victims can, or should, deal with an attack.<\/p>\n<p>&nbsp;<\/p>\n<p>[3]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 This digital menace poses constantly evolving threats, which adds to the challenges victims confront when attempting to implement current guidance and benchmarked response efforts to Ransomware. These challenges are not only rooted in functionality and potential damage, but also due to the emergence of a viable business model facilitating Ransomware\u2019s exponential growth as a tool for criminals. We will explore these challenges by providing an overview of Ransomware\u2019s development and spread and then examining the current, albeit unsettled, legal landscape surrounding Ransomware attacks and victim responses, to consider what the future might hold for regulation in this space.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>II. \u00a0 \u00a0A History of Ransomware<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[4]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 As noted above, Ransomware has been around in one form or another for at least ten years,<a href=\"#_ftn6\" name=\"_ftnref6\">[6]<\/a> and as early as 1989 in the U.S.<a href=\"#_ftn7\" name=\"_ftnref7\">[7]<\/a> and Europe.<a href=\"#_ftn8\" name=\"_ftnref8\">[8]<\/a> The first recorded example was biologist Joseph Popp\u2019s \u201cAIDS Trojan\u201d: Popp developed the virus and \u201cpassed 20,000 infected floppy disks out at the 1989 World Health Organization\u2019s AIDS conference.\u201d<a href=\"#_ftn9\" name=\"_ftnref9\">[9]<\/a> Ransomware subsequently faded as a notable security concern for more than a decade before making another brief appearance in 2005.<a href=\"#_ftn10\" name=\"_ftnref10\">[10]<\/a> Then, in the wake of an economic recession, Ransomware came back with a vengeance, making a dramatic entrance as it \u201cresurged in 2013;\u201d<a href=\"#_ftn11\" name=\"_ftnref11\">[11]<\/a> it has continued to flourish ever since. Interestingly, Ransomware\u2019s recent reemergence may be explained, in part, by the success of other hacking efforts. The historical model for the most obvious cybercrimes had been stealing and selling data (usually credit card numbers), but this fraud became so prevalent that the going rate for stolen payment card information has dropped precipitously over the past five years.<a href=\"#_ftn12\" name=\"_ftnref12\">[12]<\/a> In response, \u201c[t]o keep cybercrime profitable, criminals needed to find a new cohort of potential buyers, and they did: all of us.\u201d<a href=\"#_ftn13\" name=\"_ftnref13\">[13]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[5]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Although experts rightly emphasize the significant problem Ransomware presents today, the risks have not always been so grave in the hostage-software industry. As Doug Pollack noted, \u201cironically, until [the 2005 resurgence], most [Ransomware] was fake. Fraudulent spyware removal tools and performance optimizers scared users into paying to fix problems that didn\u2019t really exist.\u201d<a href=\"#_ftn14\" name=\"_ftnref14\">[14]<\/a> Regardless, most present-day (and, likely, future) Ransomware <em>is<\/em> serious business, both in the effects it has on victims and in the underground infrastructure that buttresses Ransomware\u2019s propagation. Moreover, the scourge of Ransomware is growing steadily, with some researchers noting 500% yearly increases.<a href=\"#_ftn15\" name=\"_ftnref15\">[15]<\/a> Other experts focus on the exponential reach of Ransomware, noting that it \u201cinfects one computer but\u2026often spreads across network drives to infect other computers as well.\u201d<a href=\"#_ftn16\" name=\"_ftnref16\">[16]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[6]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 In the face of an inarguably immense and expanding problem, an understanding of the relevant legal issues is crucial for practitioners who will encounter Ransomware and its effects. That said, evaluating the applicable legal framework requires knowledge of Ransomware\u2019s mechanics, which may vary widely by the type, source, and purpose of the Ransomware\u2014not to mention the specific effects it may have on a given organization.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>III. \u00a0 \u00a0Ransomware as a Process<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[7]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Malware is malicious software, but that category \u201cencompasses a wide range of program types including viruses, worms, logic bombs, Trojan horses, keyloggers, zombie programs, and backdoors.\u201d<a href=\"#_ftn17\" name=\"_ftnref17\">[17]<\/a> One subcategory of Malware is \u201cScareware,\u201d or Malware that \u201ctakes advantage of people\u2019s fear of revealing their private information, losing their critical data, or facing irreversible hardware damage.\u201d<a href=\"#_ftn18\" name=\"_ftnref18\">[18]<\/a> Ransomware is a subset of Scareware; specifically a \u201ccategory of malicious software which, when run, disables the functionality of a computer in some way,\u201d<a href=\"#_ftn19\" name=\"_ftnref19\">[19]<\/a> making it essentially \u201ca digital version of hostage taking.\u201d<a href=\"#_ftn20\" name=\"_ftnref20\">[20]<\/a> Ransomware is also classified as a type of viral software, which is software that may be grouped into separate \u201cfamilies\u201d and differentiated by whether it presents only the superficial trappings of a threat or poses an actual problem.<a href=\"#_ftn21\" name=\"_ftnref21\">[21]<\/a> We may divide the types of Ransomware that pose an actual threat into two main groups: \u201cone-off\u201d variants used in an ad-hoc fashion, and software that serves as an extension of the broader criminal infrastructure into which victims pay their ransom.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 60px;\"><strong>A. \u00a0 \u00a0Locker Ransomware<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[8]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Beginning with the functional mechanics of the software, Ransomware attacks can be segregated by form. Early variants<a href=\"#_ftn22\" name=\"_ftnref22\">[22]<\/a> were primarily <em>Locker<\/em> Ransomware, and were identified as such (e.g., WinLocker, which would lock up a user\u2019s screen, and Master Boot Record, which would interrupt a user\u2019s normal operating system).<a href=\"#_ftn23\" name=\"_ftnref23\">[23]<\/a> The Locker approach \u201crestricts user access to infected systems by locking up the interface or computing resources within the system,\u201d<a href=\"#_ftn24\" name=\"_ftnref24\">[24]<\/a> thereby blocking off access to the computer or denying access to files.<a href=\"#_ftn25\" name=\"_ftnref25\">[25]<\/a> Locker Ransomware may display \u201ca message that demands payment to restore functionality,\u201d<a href=\"#_ftn26\" name=\"_ftnref26\">[26]<\/a> such that it appears similar to the other Ransomware variants discussed below, but operates quite differently.<\/p>\n<p>&nbsp;<\/p>\n<p>[9]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 If the victim\u2019s operating system is imagined as a storage unit, where the worth of the operating system lies in the items contained within the unit, Locker Ransomware operates by effectively changing the lock on the door, or, in some cases, changing the mechanism by which the lock engages. The items within the storage unit remain untouched, and the victim is asked to pay to have the door unlocked (or to have the locking mechanism restored to its original form), but victims in such Locker Ransomware cases have other options for regaining access. For example, they can try to bypass the door by (metaphorically) drilling out the lock, taking the door off its hinges, or just removing the walls from around the unit\u2019s contents.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 60px;\"><strong>B. \u00a0 \u00a0Crypto Ransomware<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[10]\u00a0\u00a0\u00a0\u00a0 Cryptographic approaches to Ransomware operate differently, though the initial message\u2014pay us or you cannot access your data\u2014looks the same at first blush. Rather than focusing solely on the lock, however, these variants<a href=\"#_ftn27\" name=\"_ftnref27\">[27]<\/a> employ a Crypto Ransomware or CryptoLocker approach.<a href=\"#_ftn28\" name=\"_ftnref28\">[28]<\/a> Here, the Ransomware \u201cencrypts files on the target system so that the computer is still usable, but users can\u2019t access their data.\u201d<a href=\"#_ftn29\" name=\"_ftnref29\">[29]<\/a> This type of Ransomware typically \u201cuses RSA 2048 encryption to encrypt files,\u201d making \u201ccracking the lock\u201d to avoid paying ransom an impossibility; for an average desktop computer, this approach would take \u201caround 6.4 quadrillion years.\u201d<a href=\"#_ftn30\" name=\"_ftnref30\">[30]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[11]\u00a0\u00a0\u00a0\u00a0 Continuing with the storage unit metaphor, a Crypto Ransomware approach may or may not tamper with the lock on the front door. Instead, Crypto Ransomware sizes up each item within the unit, systematically determining the relative value of the files to the user. These may include, for example, unstructured data comprised of user photos, Word documents, Excel files, or PDFs. Once those files are identified by extension, the program goes to work, encrypting each file and rendering it unusable pending payment of the ransom\u2014unless, as we discuss below, (1) the user can find a workaround solution online; or (2) the ransom <em>is<\/em> paid but no key is provided.<\/p>\n<p>&nbsp;<\/p>\n<p>[12]\u00a0\u00a0\u00a0\u00a0 When it comes to Crypto Ransomware, there is no option to drill out the lock, take the door off the hinges, or tear down the wall; each file is locked up separately and indefinitely.<a href=\"#_ftn31\" name=\"_ftnref31\">[31]<\/a> Accordingly, this type of Ransomware poses a very different kind of threat and, as such, is handled quite differently by experienced security professionals tasked with solving the problem.<\/p>\n<p>&nbsp;<\/p>\n<p>[13]\u00a0\u00a0\u00a0\u00a0 Crypto Ransomware doesn\u2019t stop there. Certain variants add insult to injury, as some may, \u201cwhile encrypting files, search[] and steal[] [B]itcoins from the user.\u201d<a href=\"#_ftn32\" name=\"_ftnref32\">[32]<\/a> Others, called \u201cDoxware,\u201d may focus on areas normally associated with user privacy such as conversations, photos, and other sensitive files; and threaten to release them publicly unless the ransom is paid.<a href=\"#_ftn33\" name=\"_ftnref33\">[33]<\/a> Still another form of Crypto Ransomware, Shadowlock, \u201cforces users to complete consumer surveys of products and services as the ransom payment.\u201d<a href=\"#_ftn34\" name=\"_ftnref34\">[34]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[14]\u00a0\u00a0\u00a0\u00a0 Although Ransomware\u2019s efficacy has improved over the decades since its introduction, many earlier forms are still in use.<a href=\"#_ftn35\" name=\"_ftnref35\">[35]<\/a> This may be due in part to its inherent longevity, as one key element of older Ransomware\u2019s functionality is the malicious way in which its self-propagating features make it incredibly difficult to eliminate. Some legacy Ransomware variations are no longer in circulation, but certain \u201c[m]alware that was released years\u2014in some cases, decades\u2014ago is still alive and well today,\u201d<a href=\"#_ftn36\" name=\"_ftnref36\">[36]<\/a> making awareness of modern Ransomware\u2019s progenitors required knowledge for practitioners active in this space.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 60px;\"><strong>C. \u00a0 \u00a0Ransomware Delivery<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[15]\u00a0\u00a0\u00a0\u00a0 Despite the automated nature of Ransomware\u2019s self-propagation, the spread of most Ransomware is still a personal process that relies on human error.<a href=\"#_ftn37\" name=\"_ftnref37\">[37]<\/a> The FBI notes specifically that \u201cRansomware is frequently delivered through spear phishing emails\u201d to end users.<a href=\"#_ftn38\" name=\"_ftnref38\">[38]<\/a> Other common methods of installing Ransomware are \u201cexploit kits,\u201d<a href=\"#_ftn39\" name=\"_ftnref39\">[39]<\/a> \u201cWeb exploits and drive-by downloads,\u201d<a href=\"#_ftn40\" name=\"_ftnref40\">[40]<\/a> \u201cinfected removable drives, infected software installers,\u201d<a href=\"#_ftn41\" name=\"_ftnref41\">[41]<\/a> and \u201cmass phishing campaigns.\u201d<a href=\"#_ftn42\" name=\"_ftnref42\">[42]<\/a> In a \u201cmass phishing campaign,\u201d<a href=\"#_ftn43\" name=\"_ftnref43\">[43]<\/a> malware is \u201cinstalled on a user\u2019s computer without their knowledge when that user browses to a compromised website,\u201d<a href=\"#_ftn44\" name=\"_ftnref44\">[44]<\/a> and is using \u201coutdated browsers, browser plugins, and other software.\u201d<a href=\"#_ftn45\" name=\"_ftnref45\">[45]<\/a> These techniques may be referred to as \u201cmalvertising\u201d where \u201c[c]ybercriminals leverage compromised advertising networks to serve malicious advertisements on legitimate websites which subsequently infect the visitors&#8230;[later] redirecting the user to an Exploit Kit (EK) landing page.\u201d<a href=\"#_ftn46\" name=\"_ftnref46\">[46]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[16]\u00a0\u00a0\u00a0\u00a0 In addition to leveraging self-propagation, Ransomware schemes also may rely on the \u201cspray and pray\u201d technique, or sending out massive quantities of malware-infected emails in hopes of hitting \u201cas many individual targets\u2026as quickly as possible\u201d by virtue of sheer volume.<a href=\"#_ftn47\" name=\"_ftnref47\">[47]<\/a> Still other types of Ransomware have begun to deploy an even more personal approach, tailoring messages to appear as genuine as possible; often through social engineering research used to gain knowledge of a company\u2019s operational structure, invoicing and remittance practices, and even individuals\u2019 writing styles.<a href=\"#_ftn48\" name=\"_ftnref48\">[48]<\/a> Increasingly, \u201ce-mails are highly targeted to both the organization and individual, making scrutiny of the document and sender important to prevent exploitation.\u201d<a href=\"#_ftn49\" name=\"_ftnref49\">[49]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 60px;\"><strong>D. \u00a0 \u00a0Personality and Psychology<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[17]\u00a0\u00a0\u00a0\u00a0 The customization of these programs is reflected in a variety of features that are now common to Ransomware schemes. For example, certain programs display multiple language options so \u201clanguage is not a barrier to payment, [allowing] the user [to] access ransom instructions in English, French, German, Russian, Italian, Spanish, Portuguese, Japanese, Chinese and Arabic\u201d<a href=\"#_ftn50\" name=\"_ftnref50\">[50]<\/a> and making sure that the Ransomware \u201cexperience\u201d is appropriately localized for the victim.<a href=\"#_ftn51\" name=\"_ftnref51\">[51]<\/a> Once the Ransomware is downloaded, it disables the victim\u2019s machine \u201cby disallowing execution of various programs,\u201d demanding ransom, and even \u201cusing local police images\u201d \u2013the program geo-locates the user\u2019s internet protocol address and associates that address with location-specific law enforcement decals and insignia deployed from a central command-and-control server.<a href=\"#_ftn52\" name=\"_ftnref52\">[52]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[18]\u00a0\u00a0\u00a0\u00a0 In connection with this locality-based personalization, Ransomware may use psychological tactics to induce guilt or shame in individual victims.<a href=\"#_ftn53\" name=\"_ftnref53\">[53]<\/a> For example, ransom notes may include salacious details to frighten users, sometimes claiming that the victim has violated federal statutes and\/or threatening imprisonment for alleged visits to websites \u201ccontaining pornography, child pornography, zoophilia and child abuse.\u201d<a href=\"#_ftn54\" name=\"_ftnref54\">[54]<\/a> These ransom notes are then spread throughout the computer\u2019s operating system, often propagating hundreds of copies on a given computer to ensure the user\u2019s attention is drawn to the threat.<a href=\"#_ftn55\" name=\"_ftnref55\">[55]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[19]\u00a0\u00a0\u00a0\u00a0 Alternatively, \u201csome versions of Ransomware are now designed to seek out the files on a victim\u2019s computer that are most likely to be precious, such as a large number of old photographs, for example, tax filings, or financial worksheets.\u201d<a href=\"#_ftn56\" name=\"_ftnref56\">[56]<\/a> Other variants \u201cjust delete[] files instead of encrypting them.\u201d<a href=\"#_ftn57\" name=\"_ftnref57\">[57]<\/a> Finally, some \u201cvariants display a countdown timer to the victim, threatening to delete the key\/decryption tool if payment is not received before the timer reaches zero or, in other cases, increase the price of the ransom.\u201d<a href=\"#_ftn58\" name=\"_ftnref58\">[58]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[20]\u00a0\u00a0\u00a0\u00a0 Even setting aside the nuances of these personal approaches, it is nearly impossible for security experts to keep pace with Ransomware advances generally, as \u201chackers are releasing over 100,000 new [R]ansomware variants daily,\u201d<a href=\"#_ftn59\" name=\"_ftnref59\">[59]<\/a> and \u201c\u2018evil genius\u2019 [R]ansomware ideas are \u2018coming out on a regular basis.\u2019\u201d<a href=\"#_ftn60\" name=\"_ftnref60\">[60]<\/a> Perhaps even more challenging for law enforcement and security specialists, the level of technological expertise required to engineer a Ransomware attack has decreased significantly; at this point, deploying Ransomware is \u201crelatively low budget, low stakes, and [doesn\u2019t] require much skill to pull off.\u201d<a href=\"#_ftn61\" name=\"_ftnref61\">[61]<\/a> Indeed, in one instance, a recent drop in price to US$39 for Ransomware software concerned experts who believed \u201cthe low price coupled with its potency could trigger a wave of new infections.\u201d<a href=\"#_ftn62\" name=\"_ftnref62\">[62]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[21]\u00a0\u00a0\u00a0\u00a0 Evolving with the times, recent Ransomware variants have focused on smartphones and other connected devices, including those that are a part of the \u201cInternet of Things.\u201d<a href=\"#_ftn63\" name=\"_ftnref63\">[63]<\/a> The first instances of \u201cmobile-focused Ransomware came out in 2013,\u201d<a href=\"#_ftn64\" name=\"_ftnref64\">[64]<\/a> buoyed in part \u201cby the practice of users downloading pirated apps from unsanctioned app stores.\u201d<a href=\"#_ftn65\" name=\"_ftnref65\">[65]<\/a> As noted by another commentator, \u201c[R]ansomware criminals can achieve some profit from targeting any system: mobile devices, personal computers, industrial control systems, refrigerators, portable hard drives, etc. The majority of these devices are not secured in the slightest against a [R]ansomware threat.\u201d<a href=\"#_ftn66\" name=\"_ftnref66\">[66]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>IV. \u00a0 \u00a0The Business of Ransomware<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 30px;\">You always wanted a Ransomware but never wanted two pay Hundreds of dollars for it? This list is for you!?? Stampado is a cheap and easy-to-manage ransomware, developed by me and my team. It\u2019s meant two be really easy-to-use. You\u2019ll not need a host. All you will need is an email account.<a href=\"#_ftn67\" name=\"_ftnref67\">[67]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[22]\u00a0\u00a0\u00a0\u00a0 The mentality behind Ransomware seems to have deep-rooted cultural underpinnings, likened by some authors to medieval roadways that became host \u201cto travelling footpads referred to as highwaymen.\u201d<a href=\"#_ftn68\" name=\"_ftnref68\">[68]<\/a> Methodologically, the purveyors of Ransomware bear little resemblance to hackers \u201cwho attempt to exfiltrate or manipulate data where it is stored, processed, or in transmission;\u201d instead, \u201cransomware criminals only attempt to prevent access to the data.\u201d<a href=\"#_ftn69\" name=\"_ftnref69\">[69]<\/a> In short, Ransomware aims to disrupt.<\/p>\n<p>&nbsp;<\/p>\n<p>[23]\u00a0\u00a0\u00a0\u00a0 Ransomware differs from many other types of hacking on a number of levels. It has been called a \u201cbusiness model\u201d<a href=\"#_ftn70\" name=\"_ftnref70\">[70]<\/a> that has \u201cquickly risen to dominance\u201d<a href=\"#_ftn71\" name=\"_ftnref71\">[71]<\/a> within the \u201ccybercriminal market in the past few years\u201d<a href=\"#_ftn72\" name=\"_ftnref72\">[72]<\/a> and has \u201cemerged as one of the most serious online threats facing businesses.\u201d<a href=\"#_ftn73\" name=\"_ftnref73\">[73]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[24]\u00a0\u00a0\u00a0\u00a0 Often, a Ransomware attempt betrays the fact that its author \u201clack[s] the technical complexity to perform successful attacks;\u201d<a href=\"#_ftn74\" name=\"_ftnref74\">[74]<\/a> some versions have been described as lacking technical savvy, and others as \u201cnot very well developed\u201d beginner-level efforts.<a href=\"#_ftn75\" name=\"_ftnref75\">[75]<\/a> Perhaps because of a general lack of know-how, and Ransomware\u2019s reputation as offering \u201ceasier money than hacking into personal information to use for identity theft,\u201d<a href=\"#_ftn76\" name=\"_ftnref76\">[76]<\/a> a cottage industry has mushroomed. Certain criminals \u201cnow have the resources to hire professional developers to build increasingly sophisticated malware\u201d on their behalf.<a href=\"#_ftn77\" name=\"_ftnref77\">[77]<\/a> Providers, \u201cusually based in Russia, Ukraine, Eastern Europe and China, have begun licensing what\u2019s known as \u2018exploit kits\u2019\u2014all-inclusive Ransomware apps\u2014to individual hackers for a couple hundred dollars a week,\u201d<a href=\"#_ftn78\" name=\"_ftnref78\">[78]<\/a> or even \u201c[US]$50 for a set period time of use,\u201d<a href=\"#_ftn79\" name=\"_ftnref79\">[79]<\/a> frequently taking a \u201ccut of the profits from payouts.\u201d<a href=\"#_ftn80\" name=\"_ftnref80\">[80]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[25]\u00a0\u00a0\u00a0\u00a0 Known as \u201cRansomware-as-a-service\u201d (or RaaS), there are now \u201cproducts, such as CerberRing, which provide[] less-tech savvy criminals a corridor into cybercrime, and yield[] criminal affiliates (often tasked with distributing the [R]ansomware) a healthy portion of the profits.\u201d<a href=\"#_ftn81\" name=\"_ftnref81\">[81]<\/a> Interestingly enough, because Ransomware is such big business, some Ransomware enterprises actually offer \u201ccustomer service which victims can contact to negotiate\u201d<a href=\"#_ftn82\" name=\"_ftnref82\">[82]<\/a> and similar structures that make both launching the attacks, and paying the ransoms, easier.<a href=\"#_ftn83\" name=\"_ftnref83\">[83]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[26]\u00a0\u00a0\u00a0\u00a0 Some commentators note that there is \u201csome honour among thieves,\u201d where \u201chackers almost always honour their word and provide the encryption key to those who make timely online payments.\u201d<a href=\"#_ftn84\" name=\"_ftnref84\">[84]<\/a> Others disagree, noting that a decision to pay does not consistently restore functionality, and \u201c[t]he only reliable way to restore functionality is to remove the malware.\u201d<a href=\"#_ftn85\" name=\"_ftnref85\">[85]<\/a> For many this is truly unfortunate, as \u201c[t]he costs of downtime often exceed the cost of ransom.\u201d<a href=\"#_ftn86\" name=\"_ftnref86\">[86]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[27]\u00a0\u00a0\u00a0\u00a0 Ransomware infrastructure has \u201cbegun to mimic the way modern software is developed: there are criminal engineers and manufacturers, retailers, and \u2018consumers\u2019\u2014[those] hackers on the lookout for the newest, most effective product.\u201d<a href=\"#_ftn87\" name=\"_ftnref87\">[87]<\/a> In some cases, when a ransom is paid functionality may be restored but in an inconsistent manner (e.g., accounting data may be returned, but mapped drive data is not); in at least one of those cases, the victim determined that the \u201chelp\u201d offered by the Ransomware attacker could instead lead to the loss of more data.<a href=\"#_ftn88\" name=\"_ftnref88\">[88]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[28]\u00a0\u00a0\u00a0\u00a0 Ransomware may be preferred by criminals because it cuts out the middle-man. <a href=\"#_ftn89\" name=\"_ftnref89\">[89]<\/a> It bypasses many of the annoyances associated with hacking to steal data that then must be monetized. Where \u201cintellectual property, or other sensitive information that is stolen outright&#8230;.is often \u2018fenced\u2019 on the Dark Web, then the buyer has to turn it into a false identity that can be used to fraudulently obtain goods or services.\u201d<a href=\"#_ftn90\" name=\"_ftnref90\">[90]<\/a> In contrast, Ransomware has victims who \u201cpay the criminal directly, the payment happens within hours or days in untraceable currency, and there is no chain of custody to point to the criminals because the data stays on the victim\u2019s system the whole time.\u201d<a href=\"#_ftn91\" name=\"_ftnref91\">[91]<\/a> Indeed, deploying Ransomware is especially convenient for criminals, as its operation \u201coften means dealing not with a small group of fellow criminals, but instead with a much larger population of lay users who are unlikely to disappear behind bars.\u201d<a href=\"#_ftn92\" name=\"_ftnref92\">[92]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>V. \u00a0 \u00a0Ransomware\u2019s Direct Impact<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[29]\u00a0\u00a0\u00a0\u00a0 In some cases, specific industries have been singled out as popular targets. For instance, at the time of writing, \u201c[R]ansomware is the dominant current information security threat to health care providers.\u201d<a href=\"#_ftn93\" name=\"_ftnref93\">[93]<\/a> Ransomware may target \u201cvictims like healthcare providers whose complex independent networks and critical need for real-time information can make reliance on backups difficult and potentially life-threatening.\u201d<a href=\"#_ftn94\" name=\"_ftnref94\">[94]<\/a> These types of targets (\u201chospitals in particular\u201d but also \u201cother firms heavily dependent on computers\u201d<a href=\"#_ftn95\" name=\"_ftnref95\">[95]<\/a>) tend to focus on paying off the attacker to make the problem go away, whereas other types of companies may be amenable to \u201cresisting the attack and rebuilding entire systems.\u201d<a href=\"#_ftn96\" name=\"_ftnref96\">[96]<\/a> If the demands are not met, in the most extreme examples, a victim might be \u201cforced back into the 1980s: digital typewriters, notebooks, fax machines, post-it notes, paper checks and the like.\u201d<a href=\"#_ftn97\" name=\"_ftnref97\">[97]<\/a> In the face of these challenges, many organizations and individuals simply pay. Some do so without fanfare, and experts claim it \u201cwould shock you [] how many companies have quietly gone ahead and paid for information to be returned.\u201d<a href=\"#_ftn98\" name=\"_ftnref98\">[98]<\/a> Others, like PayPal, have made public the fact that they will pay for stolen data to protect their customers.<a href=\"#_ftn99\" name=\"_ftnref99\">[99]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[30]\u00a0\u00a0\u00a0\u00a0 One commentator noted that attorneys increasingly are \u201ctargets of [R]ansomware;\u201d in the past several years, a number of \u201clarge and small law firms in the United States and Canada have had their office computer systems compromised by [R]ansomware.\u201d<a href=\"#_ftn100\" name=\"_ftnref100\">[100]<\/a> Some professionals \u201csuspect that paying gets you listed on the Dark Web as an easy target, setting you up for more attacks.\u201d<a href=\"#_ftn101\" name=\"_ftnref101\">[101]<\/a> At least in some cases, the FBI appears to agree.<a href=\"#_ftn102\" name=\"_ftnref102\">[102]<\/a> Ransomware\u2019s effects are not just monetary, as the loss of the files themselves (or the cost of ransom) may be eclipsed by the loss of \u201cclient trust, relationships, and reputation.\u201d<a href=\"#_ftn103\" name=\"_ftnref103\">[103]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>VI. \u00a0 \u00a0Ransomware\u2019s Indirect Impact<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[31]\u00a0\u00a0\u00a0\u00a0 One commentator notes that Ransomware is an exception (and perhaps portends a wave of such exceptions) to the traditional \u201cdata security breach\u201d concept with which we have all become familiar.<a href=\"#_ftn104\" name=\"_ftnref104\">[104]<\/a> Whereas a traditional \u201cbreach\u201d typically entails the acquisition of data, Ransomware allows wrongdoers to control, damage, and interrupt systems; deny access to data; and destroy or otherwise harm the data\u2019s integrity\u2014all <em>without<\/em> actual acquisition of the data.<a href=\"#_ftn105\" name=\"_ftnref105\">[105]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[32]\u00a0\u00a0\u00a0\u00a0 Although some contend that \u201cno information is actually stolen during a [R]ansomware attack,\u201d<a href=\"#_ftn106\" name=\"_ftnref106\">[106]<\/a> others argue that falling victim to Ransomware \u201ccould also be considered a data breach, even though the data never leaves the victim\u2019s systems.\u201d<a href=\"#_ftn107\" name=\"_ftnref107\">[107]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[33]\u00a0\u00a0\u00a0\u00a0 The issue of whether Ransomware constitutes a breach was raised at the 2016 Healthcare Compliance Association conference.<a href=\"#_ftn108\" name=\"_ftnref108\">[108]<\/a> There, Iliana Peters of the Department of Health and Human Services\u2019 (HHS) Office for Civil Rights (OCR) \u201cpointed out that HIPAA regulations define a data breach as \u2018impermissible acquisition, access, use or disclosure of PHI [protected health information](paper or electronic) which compromises the security or privacy of the PHI.\u2019\u201d<a href=\"#_ftn109\" name=\"_ftnref109\">[109]<\/a> Additional HIPAA guidance from the OCR also notes that some Ransomware may \u201cexfiltrate\u201d the data,<a href=\"#_ftn110\" name=\"_ftnref110\">[110]<\/a> which further complicates a simple explanation for the mechanics of a Ransomware attack. The OCR also noted that \u201c[h]ospitals and other healthcare providers hit by [R]ansomware attacks should notify affected individuals, the federal government and perhaps the news media unless there is a \u2018low probability\u2019 any personal health information was disclosed.\u201d<a href=\"#_ftn111\" name=\"_ftnref111\">[111]<\/a> That \u201cguidance makes clear that a [R]ansomware attack usually results in a \u2018breach\u2019 of healthcare information under the HIPAA Breach Notification Rule,\u201d noted OCR\u2019s Executive Director, Jocelyn Samuels.<a href=\"#_ftn112\" name=\"_ftnref112\">[112]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[34]\u00a0\u00a0\u00a0\u00a0 In contrast, some argue that data breach notification statutes were implemented with a focus on informing citizens that their personal information may have been compromised, offering \u201cvaluable warnings to assist victims in protecting themselves\u201d and otherwise corralling information that has been set loose in the outside world.<a href=\"#_ftn113\" name=\"_ftnref113\">[113]<\/a> The July 2016 HHS guidance also indicates that the question of \u201cwhether notification is required comes down to a \u2018fact-specific determination.\u2019\u201d<a href=\"#_ftn114\" name=\"_ftnref114\">[114]<\/a> In some cases, a forensic investigation may provide evidence to support a company\u2019s conclusion that a ransomware attack did not expose any personal information, even if the incident resulted in a system shutdown or other functional difficulties. Many healthcare entities have reached this same conclusion under HIPAA.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>VII. \u00a0 \u00a0Response to Ransomware<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[35]\u00a0\u00a0\u00a0\u00a0 Although the following discussion examines conventional best practice approaches for dealing with Ransomware, but the preceding section should signal that there is no one-size-fits-all solution. As with many computer infections, a typical initial response to Ransomware may be to restart the computer in \u201csafe mode\u201d in an effort to disable a number of programs that might be causing issues.<a href=\"#_ftn115\" name=\"_ftnref115\">[115]<\/a> In the case of Ransomware, however, this approach may backfire, allowing the malicious software to flourish by un-loading antivirus programs that otherwise may have stopped it.<a href=\"#_ftn116\" name=\"_ftnref116\">[116]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[36]\u00a0\u00a0\u00a0\u00a0 The next step in the response protocol is for victims to identify which \u201cstrain\u201d of Ransomware they are dealing with, and then determine whether an \u201capplicable decryption method\u201d may be readily available to help unlock or decrypt files.<a href=\"#_ftn117\" name=\"_ftnref117\">[117]<\/a> Whether this approach will be successful depends on the sophistication of the Ransomware. Certain generic, readily available strains that are still freely disseminated among would-be hackers may be defeated with relative ease, and the fact that a given strain of Ransomware is still in circulation is not proof of its viability or effectiveness.<a href=\"#_ftn118\" name=\"_ftnref118\">[118]<\/a> To give one example, \u201cthe makers of Jigsaw ransomware have continued their assault against victims despite the fact its encryption scheme has been defeated by security researchers.\u201d<a href=\"#_ftn119\" name=\"_ftnref119\">[119]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[37]\u00a0\u00a0\u00a0\u00a0 If these initial efforts are unsuccessful, certain victims may be inclined to pay the ransom. Experts may caution against paying the ransom prematurely, but for many, a relatively paltry Ransomware demands (demands often range from US$200 to US$2,000) may be seen as \u201cnuisance fee\u201d more than anything else.<a href=\"#_ftn120\" name=\"_ftnref120\">[120]<\/a> The \u201cTo Pay or Not to Pay\u201d<a href=\"#_ftn121\" name=\"_ftnref121\">[121]<\/a> characterization of a standard response to Ransomware is apt, though this decision-making process may mean waiting to decide until after an initial deadline is extended.<a href=\"#_ftn122\" name=\"_ftnref122\">[122]<\/a> Waiting may result in a doubling of the ransom<a href=\"#_ftn123\" name=\"_ftnref123\">[123]<\/a> or even an exponential increase\u2014up to US$20,000 in some instances.<a href=\"#_ftn124\" name=\"_ftnref124\">[124]<\/a> And in some cases there really is no choice. As noted in a recent report, \u201c[f]or variants of [R]ansomware that rely on types of strong asymmetric encryption that remain relatively unbreakable without the decryption key, victim response is sharply limited to pay[ing] the ransom or los[ing] the data. No security vendor or law enforcement authority can help victims recover from these attacks.\u201d<a href=\"#_ftn125\" name=\"_ftnref125\">[125]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[38]\u00a0\u00a0\u00a0\u00a0 Paying a ransom may, therefore, make logical sense, given that \u201cRansomware attacks, especially those against individual users, only demand a few hundred dollars at most from the victim\u201d and \u201c[f]rom law enforcement\u2019s perspective, a home burglary results in greater loss than a singular [R]ansomware attack.\u201d<a href=\"#_ftn126\" name=\"_ftnref126\">[126]<\/a> At least one commentator noted cynically that, because \u201c[s]ecurity has always been a business decision, [s]ome companies would rather pay a lower fee for ransom than pay for the cost of having a robust security stance.\u201d<a href=\"#_ftn127\" name=\"_ftnref127\">[127]<\/a> Others note that \u201cto save money, some organizations don\u2019t include all their important files in their backups, or don\u2019t run their backups often enough.\u201d<a href=\"#_ftn128\" name=\"_ftnref128\">[128]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[39]\u00a0\u00a0\u00a0\u00a0 However, notwithstanding the low dollar value of most demands, taken in the aggregate, these attacks cost real money. \u201c[L]osses for victims from a single strain of the CryptoWall malware were close to $18 million,\u201d<a href=\"#_ftn129\" name=\"_ftnref129\">[129]<\/a> and another Ransomware attacker earned roughly $1 million.<a href=\"#_ftn130\" name=\"_ftnref130\">[130]<\/a> Given that \u201cnearly 30 percent of CryptoLocker and CryptoWall victims pay the ransom,\u201d<a href=\"#_ftn131\" name=\"_ftnref131\">[131]<\/a> there remains the concern that \u201chackers [will] continue to ask for higher and higher ransoms.\u201d<a href=\"#_ftn132\" name=\"_ftnref132\">[132]<\/a> Early payment schemes involved payment through \u201can SMS text message or regular call to a premium rate number\u201d where such charges could be \u201cas high as $460.\u201d<a href=\"#_ftn133\" name=\"_ftnref133\">[133]<\/a> A second iteration of payment schemes moved to prepaid electronic payment systems such as Paysafecard, Ukash, and Moneypak, where Ransomware victims are required to purchase special PIN numbers.<a href=\"#_ftn134\" name=\"_ftnref134\">[134]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[40]\u00a0\u00a0\u00a0\u00a0 Regardless of whether it makes business sense for victims to pay a victim to pay a given ransom, victims must also consider whether they <em>may<\/em> pay. Unhelpfully, regulatory authorities have expressed varying opinions on that point and have not provided definitive guidance as to whether victims should pay. The FTC notes that \u201c[l]aw enforcement doesn\u2019t recommend paying the ransom\u201d while warning that \u201cit\u2019s up to you to determine whether the risks and costs of paying are worth the possibility of getting your files back.\u201d<a href=\"#_ftn135\" name=\"_ftnref135\">[135]<\/a> In contrast, Joseph Bonavolonta, the head of the FBI\u2019s Cyberand Counterintelligence Program in 2015, stated that the FBI \u201coften advise[s] people just to pay the ransom.\u201d<a href=\"#_ftn136\" name=\"_ftnref136\">[136]<\/a> Rick Kam, president of ID Experts, also opined that \u201cit is often easier just to pay the ransom than to do without the data.\u201d<a href=\"#_ftn137\" name=\"_ftnref137\">[137]<\/a> Anecdotally, the authors have heard a wide range of opinions with respect to whether paying the ransom is a sound approach. Indeed, given the exploding number of attacks and diversity of outcomes, it is increasingly challenging to offer affected companies or individuals clear recommendations on how to assess the likelihood of success when it comes to answering a Ransomware demand.<\/p>\n<p>&nbsp;<\/p>\n<p>[41]\u00a0\u00a0\u00a0\u00a0 In short, law enforcement guidance may boil down to a \u201c[l]ook, we can\u2019t help you,\u201d<a href=\"#_ftn138\" name=\"_ftnref138\">[138]<\/a> response, even if some agencies indicate that \u201c[m]ost\u2026including law enforcement don\u2019t condone paying the ransom,\u201d<a href=\"#_ftn139\" name=\"_ftnref139\">[139]<\/a>and \u201c[m]ost security vendors advise the public (who are not yet victims) to never pay the ransom and to focus on mitigation efforts instead.\u201d<a href=\"#_ftn140\" name=\"_ftnref140\">[140]<\/a> The FBI, however, appears to be seeking \u201cpublic-private partnerships,\u201d as the Bureau utilizes notifications it receives regarding Ransomware and other threats in an overall effort to build up more comprehensive forms of defense and prevention.<a href=\"#_ftn141\" name=\"_ftnref141\">[141]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>VIII. \u00a0 \u00a0Practical and Legal Considerations<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[42]\u00a0\u00a0\u00a0\u00a0 In almost all cases, Ransomware ransom demands must be paid in a digital currency such as Bitcoin.<a href=\"#_ftn142\" name=\"_ftnref142\">[142]<\/a> Bitcoin emerged in 2009<a href=\"#_ftn143\" name=\"_ftnref143\">[143]<\/a> and has had unpredictable and profound effects, particularly with respect to the underground economy.<a href=\"#_ftn144\" name=\"_ftnref144\">[144]<\/a> For many victims, receipt of a Bitcoin ransom demand is the first time they are exposed to the term, and very few have the necessary resources available to pay such a demand in a timely manner. Others who are aware of the threat\u2014or who have a need for Bitcoin as a payment method for unrelated reasons\u2014may \u201cstockpile [B]itcoins in order to pay off cyber criminals who threaten to bring down their critical IT systems.\u201d<a href=\"#_ftn145\" name=\"_ftnref145\">[145]<\/a> To provide one public example, Hollywood Presbyterian Medical Center recently paid $17,000 in Bitcoin in response to a ransom demand.<a href=\"#_ftn146\" name=\"_ftnref146\">[146]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[43]\u00a0\u00a0\u00a0\u00a0 Unfortunately, making a Bitcoin payment is not a straightforward prospect for most organizations. The process is rife with potential legal and practical problems, because the company will likely \u201cneed to buy Bitcoins from an online exchange. The exchange will require you to supply a bank account or debit card number to fund the transaction, which creates an immediate risk because Bitcoin exchanges are notorious for being hacked.\u201d<a href=\"#_ftn147\" name=\"_ftnref147\">[147]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[44]\u00a0\u00a0\u00a0\u00a0 To add another layer of complexity, in its March 25, 2014 Virtual Currency Guide, the United States Internal Revenue Service declared that a virtual currency such as Bitcoin is considered property, not currency, and thus its use is a taxable event.<a href=\"#_ftn148\" name=\"_ftnref148\">[148]<\/a> Further, \u201c[a] payment made using virtual currency is subject to information reporting to the same extent as any other payment made in property.\u201d<a href=\"#_ftn149\" name=\"_ftnref149\">[149]<\/a> \u201cThe basis of virtual currency\u2026is the fair market value of the virtual currency in U.S. dollars as of the date of receipt\u201d, which means that a taxpayer could end up with a taxable gain or loss, depending on the net outcome.<a href=\"#_ftn150\" name=\"_ftnref150\">[150]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[45]\u00a0\u00a0\u00a0\u00a0 Concurrently, Ransomware perpetrators who demand Bitcoin ransoms run the risk of also violating financial services laws and regulations prohibiting the operation of unlicensed banks\u2014or at least causing such violations.<a href=\"#_ftn151\" name=\"_ftnref151\">[151]<\/a> \u201c[T]he U.S. Attorney for the Southern District of New York issued a press release concerning [a] criminal prosecution against Anthony R. Murgio and Yuri Lebedev for running an unlicensed Bitcoin exchange used by victims of CryptoWall [R]ansomware to pay ransoms [to their attackers] via TOR (The Onion Router).\u201d<a href=\"#_ftn152\" name=\"_ftnref152\">[152]<\/a> The two men were accused of having operated Coin.mx, a Bitcoin exchange service, in violation of federal anti-money laundering laws and regulations and that, \u201cin doing so, they knowingly exchanged cash for people whom they believed may be engaging in criminal activity.\u201d<a href=\"#_ftn153\" name=\"_ftnref153\">[153]<\/a> It is alleged that, in total, \u201cbetween approximately October 2013 and January 2015, Coin.mx exchanged at least [US]$1.8 million for Bitcoins on behalf of tens of thousands of customers.\u201d<a href=\"#_ftn154\" name=\"_ftnref154\">[154]<\/a> In addition, during this time, Murgio allegedly \u201ctransferred hundreds of thousands of dollars to bank accounts in Cyprus, Hong Kong, and Eastern Europe, and received hundreds of thousands of dollars from bank accounts in Cyprus and the British Virgin Islands, in furtherance of the operations of his unlawful business.\u201d<a href=\"#_ftn155\" name=\"_ftnref155\">[155]<\/a> In doing so, the operators of Coin.mx were said to have \u201cknowingly enabled the criminals responsible for those attacks to receive the proceeds of their crimes\u201d thereby violating federal anti-money laundering laws, because they \u201cnever filed any suspicious activity reports regarding any of the transactions.\u201d<a href=\"#_ftn156\" name=\"_ftnref156\">[156]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[46]\u00a0\u00a0\u00a0\u00a0 As part of its efforts to combat global terrorism, the U.S. actively works to prevent terrorists from accessing and using its financial system.<a href=\"#_ftn157\" name=\"_ftnref157\">[157]<\/a> Payments to criminals using Ransomware to hold data hostage may run afoul of banking laws and policies as well as related statutes and regulations. Individuals and organizations choosing to make ransom payments to end Ransomware attacks could be subject to international sanctions programs administered in the U.S. by the Office of Foreign Assets Control (OFAC), though such enforcement has not yet been tested as of this writing. Under these sanctions programs, ransom payments to certain entities are illegal, as noted by Samuel Cutler:<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 30px;\">It\u2019s important to begin from the fact that ransom payments to [Foreign Terrorist Organizations] FTOs or Specially Designated Global Terrorists (\u201cSDGTs\u201d) identified by [OFAC] are illegal under U.S. law. Monetary contributions to FTOs are considered material support under 18 U.S.C. 2339B, while transfers to SDGTs are violations of economic sanctions imposed pursuant to the International Emergency Economic Powers Act (\u201cIEEPA\u201d).<\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 30px;\">Furthermore, as the Financial Action Task Force (\u201cFATF\u201d) notes in discussion of ransom payments to the Islamic State in Iraq and the Levant (\u201cISIL\u201d), \u201c[U.N. Security Council] Resolution 2161 applies to both direct payments and indirect payments through multiple intermediaries, of ransoms to groups or individuals on the Al-Qaida Sanctions List. These restrictions apply not only to the ultimate payer of the ransom, but also to the parties that may mediate such transfers, including insurance companies, consultancies, and any other financial facilitators.\u201d<a href=\"#_ftn158\" name=\"_ftnref158\">[158]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[47]\u00a0\u00a0\u00a0\u00a0 So far, the act of paying to remove Ransomware has not been prosecuted under 18 U.S.C. 2339B<a href=\"#_ftn159\" name=\"_ftnref159\">[159]<\/a> or IEEPA, but U.S. law enforcement officials encourage victims of Ransomware to report the attacks and are actively seeking to uncover the people behind these attacks. It remains to be seen whether a substantial Ransomware-related payment that was determined to have been made to a person or group on an OFAC list may result in legal action.<a href=\"#_ftn160\" name=\"_ftnref160\">[160]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[48]\u00a0\u00a0\u00a0\u00a0 In addition, an Executive Order issued in April 2015 \u201cexpand[s] the [existing] sanctions regime to block the property and interests of persons engaging in \u2018significant malicious cyber-enabled activities\u2019\u201d outside of the U.S. that constitute a significant threat to the country as &#8220;determined by the Secretary of the Treasury, in consultation with the Attorney General and the Secretary of State.&#8221;\u00a0<a href=\"#_ftn161\" name=\"_ftnref161\">[161]<\/a> Activities deemed significant \u201chave the purpose or effect of\u201d seriously harming or compromising critical infrastructure; disrupting the availability of computers and networks; and misappropriating funds, trade secrets, personal identifiers, or financial information.<a href=\"#_ftn162\" name=\"_ftnref162\">[162]<\/a> Moreover, \u201c[t]he blocking extends to assets of those who \u2018have materially assisted, sponsored, or provided financial, material, or technological support for, or goods or services in support of, any activity [proscribed by the order] or any person whose property and interests are blocked pursuant to this order,\u2019\u201d which could implicate individuals and institutions that choose to pay to remove Ransomware.<a href=\"#_ftn163\" name=\"_ftnref163\">[163]<\/a> Ransomware disrupts the availability of computers and networks, has the ability to compromise critical infrastructure, and may allow for the misappropriation of information; these and other risks are among the considerations presented in the Order.<a href=\"#_ftn164\" name=\"_ftnref164\">[164]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[49]\u00a0\u00a0\u00a0\u00a0 In addition, the U.S. government\u2019s hostage policy may be instructive in determining whether a Ransomware payment is likely to be prosecuted. The government itself will not pay ransoms to release human hostages, but the relevant policy explicitly states that families will not be prosecuted for paying ransoms in exchange for hostages, even if these payments are made to FTOs or other individuals or groups on the government\u2019s sanctions lists.<a href=\"#_ftn165\" name=\"_ftnref165\">[165]<\/a> Former President Obama noted that \u201cno family of an American hostage has ever been prosecuted for paying a ransom for the return of their loved ones.\u201d<a href=\"#_ftn166\" name=\"_ftnref166\">[166]<\/a> Whether that U.S. policy would extend to <em>photos<\/em> of an individual\u2019s loved ones held hostage by Ransomware is an entirely different question\u2014one that may well test the limits of the government\u2019s humanitarian leniency in this regard.<\/p>\n<p>&nbsp;<\/p>\n<p>[50]\u00a0\u00a0\u00a0\u00a0 Current U.S. hostage policy also offers no exemption from prosecution for organizations making or facilitating ransom payments.<a href=\"#_ftn167\" name=\"_ftnref167\">[167]<\/a> The FBI notes in its Ransomware guidance that \u201cby paying a ransom, an organization might inadvertently be funding other illicit activity associated with criminals.\u201d<a href=\"#_ftn168\" name=\"_ftnref168\">[168]<\/a> Moreover, intermediaries cannot be used to avoid OFAC sanctions, which include freezing assets, forfeiture of assets, preventing payment transfers, fines, and imprisonment.<a href=\"#_ftn169\" name=\"_ftnref169\">[169]<\/a> In Ransomware attacks, it may be impossible to ascertain who exactly is holding the data hostage, which in turn prevents the victim from determining in advance whether a ransom payment could result in sanctions for the organization.<\/p>\n<p>&nbsp;<\/p>\n<p>[51]\u00a0\u00a0\u00a0\u00a0 Ultimately, it seems unlikely that individuals will be penalized for making small payments to regain access to personal data affected by Ransomware; enforcement is challenging on a practical level, as the anonymity of virtual currencies makes it difficult\u2014if not impossible\u2014to know whether payments are going to individuals or groups on sanctions lists.<a href=\"#_ftn170\" name=\"_ftnref170\">[170]<\/a> Large organizations considering whether to pay higher amounts to meet demands from Ransomware attackers may face a more aggressive enforcement landscape. In some cases, organizations have engaged third parties to pay virtual currency ransom demands on their behalf. Ransomware payoffs and other hacking-related expenses may be funneled through intermediaries that \u201care often part of a larger contract for countersurveillance work, ensuring corporate accounting departments don\u2019t need to green-light individual black market buys.\u201d<a href=\"#_ftn171\" name=\"_ftnref171\">[171]<\/a> With respect to the concept of paying ransom generally, it is worth considering the court\u2019s ruling in <em>United States v. Kozeny<\/em>,<a href=\"#_ftn172\" name=\"_ftnref172\">[172]<\/a> in which the \u201cUnited States District Court for the Southern District of New York [found] that only extortion or duress under the threat of <em>imminent physical harm<\/em> would excuse[] the conduct\u201d (emphasis added).<a href=\"#_ftn173\" name=\"_ftnref173\">[173]<\/a> It is difficult to imagine extending that line of reasoning to include threats to important documents or photos, especially given that industry best practices for business continuity include maintaining robust backups that would protect against just this threat.<a href=\"#_ftn174\" name=\"_ftnref174\">[174]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[52]\u00a0\u00a0\u00a0\u00a0 As noted by some practitioners,<a href=\"#_ftn175\" name=\"_ftnref175\">[175]<\/a> counsel\u2019s advice on preventing and responding to Ransomware attacks may implicate Model Rule 1.1 \u2013 Competence, as amended by Comment 8, where \u201c\u2026a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology\u2026\u201d<a href=\"#_ftn176\" name=\"_ftnref176\">[176]<\/a> Although the recent explosion in Ransomware attacks is a relatively new phenomenon, there is no shortage of resources lawyers can use to become familiar with the threats posed by Ransomware and, consequently, to their clients\u2019 data. For example, the FBI has issued guidance that provides \u201ckey areas to focus on with Ransomware [such as] prevention, business continuity, and remediation.\u201d<a href=\"#_ftn177\" name=\"_ftnref177\">[177]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[53]\u00a0\u00a0\u00a0\u00a0 With respect to potential regulatory enforcement, the FTC has warned that \u201ca company\u2019s failure to update its systems and patch vulnerabilities known to be exploited by Ransomware could violate Section 5 of the FTC Act.\u201d<a href=\"#_ftn178\" name=\"_ftnref178\">[178]<\/a> In addition, the Gramm-Leach-Bliley Act (GLBA) includes requirements concerning the disclosure by financial institutions of fraudulent access to customer information.<a href=\"#_ftn179\" name=\"_ftnref179\">[179]<\/a> The GLBA Safeguards Rule may be used \u201cin conjunction with the FTC\u2019s Section 5 authority to bring actions against financial institutions that fail to properly protect consumer financial information.\u201d<a href=\"#_ftn180\" name=\"_ftnref180\">[180]<\/a> Covered Entities under HIPAA are themselves subject to the Security Rule which, among a myriad of requirements to safeguard patient data, obligates Covered Entities to implement a data backup plan.<a href=\"#_ftn181\" name=\"_ftnref181\">[181]<\/a> HIPAA compliance guides indicate that HIPAA security requirements extend to Ransomware, noting \u201c&#8230;the possibility of a [R]ansomware attack must now be covered in any risk assessment.\u201d<a href=\"#_ftn182\" name=\"_ftnref182\">[182]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[54]\u00a0\u00a0\u00a0\u00a0 Ransomware attacks also create eDiscovery conundrums. Ransomware as an application has been considered in a number of cases, including with respect to assessing a defendant\u2019s behavior to determine whether parole was violated,<a href=\"#_ftn183\" name=\"_ftnref183\">[183]<\/a> and in an arbitration regarding the ownership of a domain name.<a href=\"#_ftn184\" name=\"_ftnref184\">[184]<\/a> Given the potential for increasingly complex conflicts in this space, practitioners should consider the implications of Ransomware on eDiscovery across a variety of scenarios. These include situations in which Ransomware is the source of a given dispute, as well as when Ransomware becomes a complicating factor in the eDiscovery process.<a href=\"#_ftn185\" name=\"_ftnref185\">[185]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[55]\u00a0\u00a0\u00a0\u00a0 Although eDiscovery has not been directly addressed in published decisions that contain a Ransomware element, the duty to preserve remains inviolate.<a href=\"#_ftn186\" name=\"_ftnref186\">[186]<\/a> If a matter involves Ransomware, and whether that matter affects the data itself or has secondary implications with respect to the data\u2019s unavailability (such as when a hospital is attacked and patients are rerouted to other locations),<a href=\"#_ftn187\" name=\"_ftnref187\">[187]<\/a> eDiscovery considerations should be front-of-mind for practitioners. Not only will claims or defenses associated with the Ransomware attack necessarily implicate the technology used, the practices that may have enabled (or failed to prevent) the attack (e.g., the infection vector, the data affected, or the target\u2019s backup environment) all may be relevant to the case, thus subject to discovery and requiring preservation.<\/p>\n<p>&nbsp;<\/p>\n<p>[56]\u00a0\u00a0\u00a0\u00a0 Yet another potential risk concerns the possibility that Ransomware could negatively impact eDiscovery collection, preservation, and later discovery efforts. The data preserved by eDiscovery collections often includes highly refined sets of important, often \u201centirely new stores of extraordinarily sensitive information\u201d<a href=\"#_ftn188\" name=\"_ftnref188\">[188]<\/a> that are retained for legal hold purposes regardless of the company\u2019s standard data retention policies and information governance practices.<a href=\"#_ftn189\" name=\"_ftnref189\">[189]<\/a> As discussed above, law firms have become a lucrative target for criminals using Ransomware;<a href=\"#_ftn190\" name=\"_ftnref190\">[190]<\/a> among other valuable data sources, information preserved pursuant to litigation holds often is maintained by law firms that are representing multiple companies in a variety of matters. Law firms and other organizations\u2014including vendors that provide preservation-related services\u2014that have custody of these eDiscovery data sets should be cognizant of the risks created by atypical retention practices. These data sets are no less susceptible to Ransomware than their \u201cstandard\u201d counterparts\u2014and may even be more attractive targets, given the one-off nature of eDiscovery collections as well as the highly sensitive data they contain. Further, Ransomware may \u201cpreserve\u201d data in a sense, but the data cannot be made available for production or may not exist in a usable format, which can add to the eDiscovery conundrums noted above.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>IX. \u00a0 \u00a0Ransomware\u2019s Future<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p>[57]\u00a0\u00a0\u00a0\u00a0 Ransomware appears poised to evolve along the same lines as many other non-criminal programming efforts, increasingly adopting the aesthetic and practicality of popular software instances that rely on a modular design, allowing criminals to \u201cuse certain functions as-needed,\u201d and offering \u201cmuch better efficiency\u201d and the \u201cability to switch tactics as required in the event one method is discovered or is found to be ineffective.\u201d<a href=\"#_ftn191\" name=\"_ftnref191\">[191]<\/a> This approach would retain certain core elements associated with functional, successful Ransomware variants in play while remaining nimble enough to affect new Internet of Things and mobile device usage.<\/p>\n<p>&nbsp;<\/p>\n<p>[58]\u00a0\u00a0\u00a0\u00a0 For example, replacing the usual \u201ccommand and control\u201d center and related Deep- or Dark-Web business model, future Ransomware might \u201csimply transmit a beacon with a GUID (globally unique identifier) to a Command and Control domain, trying to reach this domain through common protocols\/services\u2026to transmit this data.\u201d<a href=\"#_ftn192\" name=\"_ftnref192\">[192]<\/a> That is, Ransomware applications will be streamlined to suit a market seeking self-service options, exchanging a bespoke process for one that is both easier to replicate on a mass scale and cheaper to produce and distribute.<a href=\"#_ftn193\" name=\"_ftnref193\">[193]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[59]\u00a0\u00a0\u00a0\u00a0 As noted above, the volume and scope of attacks has expanded as demographics and usage patterns have shifted more and more Ransomware activity onto mobile and Internet of Things devices.<a href=\"#_ftn194\" name=\"_ftnref194\">[194]<\/a> In addition, the software and strategy underlying Ransomware attacks has adapted to evade common protective measures; since good backups often are the best defense against serious damage in the event of an attack, newer Ransomware variations have been built to go after those backups as well, destroying \u201call Shadow Copy and restore point data on Windows systems.\u201d<a href=\"#_ftn195\" name=\"_ftnref195\">[195]<\/a> Ransomware is being developed to target not only a given piece of hardware, but also the device\u2019s local and virtual environment, in an attempt to outwit the efforts of potential victims by guessing at where they might back up their data and undermining those preventative or responsive measures. Future Ransomware may well exploit would-be victims\u2019 digital networking or social connections, using information gleaned from online posts to identify additional targets who may value the same types of data and thus be willing to pay the same types of ransoms to secure its release.<\/p>\n<p>&nbsp;<\/p>\n<p>[60]\u00a0\u00a0\u00a0\u00a0 Although individuals will no doubt continue to fall victim to Ransomware, the trend seems to be toward attacks carried out on a more ambitious scale. Criminals are said to be \u201cshying away from random attacks,\u201d shifting from a focus on individuals and \u201cexpanding [further] into the corporate world\u201d where victims are more likely to have the financial wherewithal to pay larger sums.<a href=\"#_ftn196\" name=\"_ftnref196\">[196]<\/a> In short, an \u201cindividual might be limited to a [US] $500 ransom, but how about a manufacturer or a hedge fund?\u201d<a href=\"#_ftn197\" name=\"_ftnref197\">[197]<\/a> Criminals can leverage knowledge gained through experience in the ransom marketplace to seek out specific opportunities, determining, for example, that an average person\u2019s photos are worth $X; an investment manager\u2019s emails and personal diary are worth $Y; and a hedge fund\u2019s proprietary formulas, representing \u201cneed-to-know\u201d intelligence that is jealously guarded, are worth $Z. Adept attackers have already demonstrated their ability to exploit victim psychology in the abstract; laser-like, focused shakedowns may be the next horizon for Ransomware attacks.<\/p>\n<p>&nbsp;<\/p>\n<p>[61]\u00a0\u00a0\u00a0\u00a0 In addition to diversified attack methodology, the potential <em>impacts<\/em> of Ransomware attacks are evolving. Beyond the hijacking or theft of stored financial records or customer files, targeting connected technology has the potential to wreak physical, \u201creal life\u201d havoc.<a href=\"#_ftn198\" name=\"_ftnref198\">[198]<\/a> In the case of the Hollywood Presbyterian Medical Center Ransomware attack, for example, in addition to \u201cforcing staff to go back to paper records and fax machines,\u201d the data loss may have impacted care as \u201cemergency patients were diverted to other hospitals.\u201d<a href=\"#_ftn199\" name=\"_ftnref199\">[199]<\/a> As we continue to rely more heavily on connected devices, it is not difficult to see how these types of disruptions could create serious problems across multiple industry sectors\u2014the incipient arrival of driverless cars, for example, represents a potentially vulnerable technology that could be exploited for profit by data hostage-takers. An instance of Ransomware may be localized, but its effects can extend much further afield. Cars without accessible data could be paralyzed, regardless of whether they are in motion at the time the attack begins. Picture the movie <em>Speed<\/em>, replacing Sandra Bullock at the helm of a passenger-laden bus with a driverless car heading toward a cliff, doomed to disaster unless a ransom is paid.<a href=\"#_ftn200\" name=\"_ftnref200\">[200]<\/a> Likewise, many hospital treatments rely on accurate patient data at critical moments. How much would an individual pay to ensure her blood type is communicated correctly or that his medical history warns doctors of possible drug interactions? If a patient were to die under such circumstances, how would a court assess liability for a failure either to prevent the Ransomware attack, or to pay the ransom promptly?<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\"><strong>X. \u00a0 \u00a0Conclusion<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p style=\"padding-left: 30px;\">\u201c[Ransomware] is a volume business. It\u2019s simple, relatively anonymous and fast. Some people will pay, some will not pay, so what. With a wide enough set of targets there is enough upside for these types of attacks to generate a steady revenue stream.\u201d<a href=\"#_ftn201\" name=\"_ftnref201\">[201]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[62]\u00a0\u00a0\u00a0\u00a0 Grey areas abound, but thoughtful preparation is the best defense; both to avoid a Ransomware attack in the first place, and to manage the issues that may arise when an attack occurs. Practitioners should not only be knowledgeable about Ransomware, which includes understanding Ransomware\u2019s operation, effects, and ramifications, but also vigilant in following the latest trends and tracking the ever-evolving threats. Ransomware is not going anywhere, and while the meteoric rise and spread of Ransomware has been startling as a singular issue, it also serves as a clear warning of things to come. There is still plenty of room for innovation and tremendous incentives for criminals to pursue these opportunities. In a marketplace flooded with stolen credit card numbers and digital credentials, selling ill-gotten personal information to identity thieves has become both more cumbersome and less lucrative than holding data hostage and demanding a ransom from its owner.<a href=\"#_ftn202\" name=\"_ftnref202\">[202]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>[63]\u00a0\u00a0\u00a0\u00a0 Given this environment, practitioners should take a proactive approach to understanding Ransomware, not only to counsel clients effectively, but also to safeguard their own sensitive data, both professional and personal. Such understanding demands a working knowledge of digital currencies and ransom payment options, although there is some debate as to whether employing intermediaries<a href=\"#_ftn203\" name=\"_ftnref203\">[203]<\/a> may help address that particular challenge.<a href=\"#_ftn204\" name=\"_ftnref204\">[204]<\/a> Regardless, the key will be education and vigilance to guide strategic responses to Ransomware incidents. In addition to taking steps to <em>prevent<\/em> Ransomware attacks, practitioners must prepare to <em>respond<\/em> as effectively and efficiently as possible to this ever-evolving threat.<a href=\"#_ftn205\" name=\"_ftnref205\">[205]<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\"><\/a>* James A. Sherer is a Partner in the New York office of Baker &amp; Hostetler LLP.<\/p>\n<p>** Melinda L. McLellan is a Partner in the New York office of Baker &amp; Hostetler LLP.<\/p>\n<p>*** Emily R. Fedeles is an Associate in the New York office of Baker &amp; Hostetler LLP.<\/p>\n<p>**** Nichole L. Sterling is an Associate in the New York office of Baker &amp; Hostetler LLP.<\/p>\n<p>&nbsp;<\/p>\n<p>[1] <em>See <\/em>Krzysztof Cabaj &amp; Wojciech Mazurczyk, <em>Using Software-Defined Networking for Ransomware Mitigation: the Case of CryptoWall<\/em>, 30 IEEE Network 14 (2016).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> <em>See <\/em>James Scott &amp; Drew Spaniel, The ICIT Ransomware Report: 2016 Will be the Year Ransomware Holds America Hostage 3\u20134 (2016).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[3]<\/a> Ben Rossen, <em>How to Defend Against Ransomware<\/em>, FTC (Nov. 10, 2016), https:\/\/www.consumer.ftc.gov\/blog\/how-defend-against-ransomware, https:\/\/perma.cc\/CJA5-BV2B.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> <em>See<\/em> Paul Merrion, <em>FBI Creates Task Force to Fight Ransomware Threat<\/em>, CQ Roll Call, Apr. 4, 2016, 2016 WL 2758516.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> Robert E. Litan, <em>Law and Policy in the Age of the Internet<\/em>, 50 Duke L.J. 1045, 1045 (2001).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref6\" name=\"_ftn6\">[6]<\/a> <em>See <\/em>Amin Kharraz et al., <em>Cutting the Gordian Knot: A Look Under the Hood of Ransomware Attacks<\/em>, <em>in <\/em>DIMVA 2015 Proceedings of the 12th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment 3 (Springer 2015).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref7\" name=\"_ftn7\">[7]<\/a> <em>See <\/em>James Scott &amp; Drew Spaniel, <em>supra <\/em>note 2, at 4.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref8\" name=\"_ftn8\">[8]<\/a> Nicole van der Meulen et al., European Parliament Policy Dep&#8217;t for Citizens&#8217; Rights &amp; Constitutional Affairs, Cybersecurity in the European Union and Beyond: Exploring the Threats and Policy Responses 35 (2015), http:\/\/www.europarl.europa.eu\/RegData\/etudes\/STUD\/2015\/536470\/IPOL_STU(2015)536470_EN.pdf, https:\/\/perma.cc\/6M58-B4TW.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref9\" name=\"_ftn9\">[9]<\/a> James Scott &amp; Drew Spaniel, <em>supra <\/em>note 2, at 6.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref10\" name=\"_ftn10\">[10]<\/a> <em>See id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref11\" name=\"_ftn11\">[11]<\/a> <em>See <\/em>van der Meulen, <em>supra<\/em> note 8, at 35.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref12\" name=\"_ftn12\">[12]<\/a> <em>See <\/em>Josephine Wolff, <em>The New Economics of Cybercrime<\/em>, The Atlantic (June 7, 2016), http:\/\/www.theatlantic.com\/business\/archive\/2016\/06\/ransomware-new-economics-cybercrime\/485888\/, https:\/\/perma.cc\/5L3U-47CT.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref13\" name=\"_ftn13\">[13]<\/a> <em>Id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref14\" name=\"_ftn14\">[14]<\/a> Doug Pollack, Ransomware 101: What to Do When Your Data is Held Hostage 7 (2016) (ebook), http:\/\/lpa.idexpertscorp.com\/acton\/attachment\/6200\/f-051f\/1\/-\/-\/-\/-\/IDE_eBook_Ransomware_082616_v1.pdf?cm_mmc=Act-On%20Software-_-email-_-ID%20Experts%20Download%20-%20Ransomware%20101%3A%20What%20to%20Do%20When%20Your%20Data%20is%20Held%20Hostage-_-Download%20Now&amp;sid=TV2:dA7ip6myT, https:\/\/perma.cc\/327S-TXFL.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[15]<\/a> <em>See <\/em>Kharraz, <em>supra<\/em> note 6, at 1, 4.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref16\" name=\"_ftn16\">[16]<\/a> <em>See <\/em>Azad Ali et al., <em>Recovering from the Nightmare of Ransomware \u2013 How Savvy Users Get Hit with Viruses and Malware: A Personal Case Study<\/em>, 17 Issues in Information Systems 58, 61 (2016).<\/p>\n<p><em>\u00a0<\/em><\/p>\n<p><a href=\"#_ftnref17\" name=\"_ftn17\">[17]<\/a> Robert J. Kroczynski, <em>Are the Current Computer Crime Laws Sufficient or Should the Writing of Virus Code Be Prohibited?<\/em>, 18 Fordham Intell. Prop. Media &amp; Ent. L.J. 817, 823 (2008).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref18\" name=\"_ftn18\">[18]<\/a> <em>See <\/em>Kharraz, <em>supra<\/em> note 6, at 1.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref19\" name=\"_ftn19\">[19]<\/a> Gavin O\u2019Gorman &amp; Geoff McDonald, <em>Ransomware: A Growing Menace<\/em>, Symantec Corp. (2012) at 2, http:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_response\/whitepapers\/ransomware-a-growing-menace.pdf, https:\/\/perma.cc\/F6UF-UDUL.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref20\" name=\"_ftn20\">[20]<\/a> Eric Jardine, <em>A Continuum of Internet-Based Crime: How the Effectiveness of Cybersecurity Policies Varies across Cybercrime Types<\/em>, ResearchGate, 10 (Jan. 2016), <em>reprinted<\/em> <em>in <\/em>Research Handbook on Digital Transformations 421 (F. Xavier Olleros &amp; Majinda Zhegu eds., 2016).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref21\" name=\"_ftn21\">[21]<\/a> <em>See <\/em>Kharraz, <em>supra<\/em> note 6, at 2.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref22\" name=\"_ftn22\">[22]<\/a> <em>See, e.g.<\/em>, William Largent, <em>Ransomware: Past, Present, and Future<\/em>, Talos Blog (Apr. 11, 2016, 9:01 AM), http:\/\/blog.talosintel.com\/2016\/04\/ransomware.html, https:\/\/perma.cc\/QU27-WDRK (last visited Feb. 6, 2017).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref23\" name=\"_ftn23\">[23]<\/a> <em>See <\/em>Ian T. Ramsey &amp; Edward A. Morse, Cyberspaxe Law Comm. Winter Working Grp., Ransoming Data: Technological and Legal Implications of Payments for Data Privacy 4\u20135 (Jan. 29-30, 2016) (unpublished manuscript) (on file with author), http:\/\/www.stites.com\/uploads\/learning-center\/Ramsey_Ransoming-data_Jan2016.pdf, https:\/\/perma.cc\/H4BZ-UHY3.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref24\" name=\"_ftn24\">[24]<\/a> Pollack, <em>supra <\/em>note 14, at 7.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref25\" name=\"_ftn25\">[25]<\/a> <em>See <\/em>Largent,<em> supra <\/em>note 22.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref26\" name=\"_ftn26\">[26]<\/a><em> See <\/em>O\u2019Gorman &amp; McDonald,\u00a0<em>supra <\/em>note 19, at 2.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref27\" name=\"_ftn27\">[27]<\/a> <em>See, e.g.<\/em>, Largent,<em> supra <\/em>note 22<em>.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref28\" name=\"_ftn28\">[28]<\/a> <em>See id<\/em>.<\/p>\n<p><em>\u00a0<\/em><\/p>\n<p><a href=\"#_ftnref29\" name=\"_ftn29\">[29]<\/a> Doug Pollack, <em>Trading in Fear: The Anatomy of Ransomware<\/em>, id experts (May 2, 2016), https:\/\/www2.idexpertscorp.com\/blog\/single\/trading-in-fear-the-anatomy-of-ransomware, https:\/\/perma.cc\/7VTU-5QAC.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref30\" name=\"_ftn30\">[30]<\/a> Adam Alessandrini, Ransomware Hostage Rescue Manual 2, (2015), http:\/\/resources.idgenterprise.com\/original\/AST-0147692_Ransomware-Hostage-Rescue-Manual.pdf, https:\/\/perma.cc\/9V7T-L4YA.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref31\" name=\"_ftn31\">[31]<\/a> Considerations associated with quantum computing and decryption are outside the purview of this paper.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref32\" name=\"_ftn32\">[32]<\/a> Ramsey &amp; Morse, <em>supra<\/em> note 23, at 5.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref33\" name=\"_ftn33\">[33]<\/a> Chris Ensey, <em>Ransomware Has Evolved, And Its Name Is Doxware<\/em>, DarkReading (Jan. 4, 2017, 07:30 AM) http:\/\/www.darkreading.com\/attacks-breaches\/ransomware-has-evolved-and-its-name-is-doxware\/a\/d-id\/1327767, https:\/\/perma.cc\/VGJ6-HUHD (noting also that this would be one way of getting back access to at least some of the hostage files).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref34\" name=\"_ftn34\">[34]<\/a> <em>Technical Intricacies of Ransomware and Safeguarding Strategies<\/em>, Fall 2016 E-Newsletter (Digital Mountain, Santa Clara, C.A.), 2016, at 1, http:\/\/digitalmountain.com\/enews\/FALL_2016_Article2.pdf, https:\/\/perma.cc\/8CKR-3Q3A.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref35\" name=\"_ftn35\">[35]<\/a><em> See <\/em>Largent, <em>supra<\/em> note 22.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref36\" name=\"_ftn36\">[36]<\/a> <em>Id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref37\" name=\"_ftn37\">[37]<\/a> <em>See<\/em> <em>id<\/em>.<\/p>\n<p><em>\u00a0<\/em><\/p>\n<p><a href=\"#_ftnref38\" name=\"_ftn38\">[38]<\/a> <em>See <\/em>U.S. Dep&#8217;t of Justice, Protecting Your Networks from Ransomware 2, https:\/\/www.justice.gov\/criminal-ccips\/file\/872771\/download, https:\/\/perma.cc\/3GT6-ARH.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref39\" name=\"_ftn39\">[39]<\/a> <em>See <\/em>Largent,<em> supra <\/em>note 22, at 1.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref40\" name=\"_ftn40\">[40]<\/a> <em>See <\/em>O\u2019Gorman &amp; McDonald, <em>supra <\/em>note 19, at 4.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref41\" name=\"_ftn41\">[41]<\/a> <em>See<\/em> <em>Practical Steps to Thwart Ransomware and other Cyberbreaches<\/em>, YourABA (Dec. 2016), http:\/\/www.americanbar.org\/publications\/youraba\/2016\/december-2016\/be-prepared-to-thwart-ransomware-and-other-cyber-attacks.html, https:\/\/perma.cc\/U5G4-VX97.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref42\" name=\"_ftn42\">[42]<\/a> <em>See <\/em>Largent, <em>supra<\/em> note 22.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref43\" name=\"_ftn43\">[43]<\/a> <em>Id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref44\" name=\"_ftn44\">[44]<\/a> <em>See <\/em>O\u2019Gorman &amp; McDonald, <em>supra<\/em> note 19, at 4.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref45\" name=\"_ftn45\">[45]<\/a> Fed. Bureau of Investigation, Ransomware, www.blockchainalliance.org\/docs\/Ransomware_e-version.pdf, https:\/\/perma.cc\/66XL-V4J7.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref46\" name=\"_ftn46\">[46]<\/a> Deepen Desai, <em>Malvertising, Exploit Kits, ClickFraud &amp; Ransomware: A Thriving Underground Economy<\/em>, ZScaler (Apr. 21, 2015), https:\/\/www.zscaler.com\/blogs\/research\/malvertising-exploit-kits-clickfraud-ransomware-thriving-underground-economy, https:\/\/perma.cc\/C4PN-TM4C.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref47\" name=\"_ftn47\">[47]<\/a> <em>See <\/em>Largent, <em>supra<\/em> note 22.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref48\" name=\"_ftn48\">[48]<\/a> <em>See Ransomware on the Rise: Norton Tips on How to Prevent Getting Infected<\/em>, Norton by Symantec, https:\/\/us.norton.com\/ransomware\/article, https:\/\/perma.cc\/7MZU-XYVU<em>. <\/em><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref49\" name=\"_ftn49\">[49]<\/a> <em>See <\/em>Fed. Bureau of Investigation, <em>supra<\/em> note 45.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref50\" name=\"_ftn50\">[50]<\/a> Ramsey &amp; Morse, <em>supra<\/em> note 23, at 5.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref51\" name=\"_ftn51\">[51]<\/a> <em>See <\/em>Azad Ali et al., <em>supra<\/em> note 16, at 62.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref52\" name=\"_ftn52\">[52]<\/a> O\u2019Gorman &amp; McDonald,\u00a0<em>supra <\/em>note 19, at 5.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref53\" name=\"_ftn53\">[53]<\/a> <em>See <\/em>Haley S. Edwards, <em>A Devastating Type of Hack Is Costing People Big Money<\/em>, Time (Apr. 21, 2016), http:\/\/time.com\/4303129\/hackers-computer-ransom-ransomware\/, https:\/\/perma.cc\/AAQ3-52BB.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref54\" name=\"_ftn54\">[54]<\/a> O\u2019Gorman &amp; McDonald, <em>supra <\/em>note 19, at 2.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref55\" name=\"_ftn55\">[55]<\/a> <em>See <\/em>Ali et al., <em>supra <\/em>note 16, at 61\u201362.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref56\" name=\"_ftn56\">[56]<\/a> Edwards, <em>supra <\/em>note 53.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref57\" name=\"_ftn57\">[57]<\/a> Tom Spring, <em>Dirt Cheap Stampado Ransomware Sells on Dark Web for $39<\/em>, ThreatPost (July 14, 2016, 12:35 PM), https:\/\/threatpost.com\/dirt-cheap-stampado-ransomware-sells-on-dark-web-for-39\/119284\/, https:\/\/perma.cc\/A4HS-ZF3H.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref58\" name=\"_ftn58\">[58]<\/a> Largent, <em>supra <\/em>note 22.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref59\" name=\"_ftn59\">[59]<\/a> Pollack, <em>supra <\/em>note 14, at 5.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref60\" name=\"_ftn60\">[60]<\/a> Ricci Dipshan, <em>Danger Ahead: 3 New Ransomware Developments in 2016; From Hybrid Ransomware to Attacks on Mobile Devices and New Entrants in the Field, Experts Warn of a Difficult Year Ahead<\/em>, Law Tech. News (May 31, 2016).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref61\" name=\"_ftn61\">[61]<\/a> Edwards, <em>supra <\/em>note 53.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref62\" name=\"_ftn62\">[62]<\/a> Spring, <em>supra <\/em>note 57.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref63\" name=\"_ftn63\">[63]<\/a> <em>See, e.g.<\/em>, Antigone Peyton, <em>A Litigator\u2019s Guide to the Internet of Things<\/em>, 22 Rich. J. L. &amp; Tech. 9, \u00b6 1 (2016), http:\/\/jolt.richmond.edu\/v22i3\/article9.pdf, https:\/\/perma.cc\/VSZ7-85LE.<\/p>\n<p><u>\u00a0<\/u><\/p>\n<p><a href=\"#_ftnref64\" name=\"_ftn64\">[64]<\/a> <em>See <\/em>van der Meulen, <em>supra<\/em> note 8, at 45.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref65\" name=\"_ftn65\">[65]<\/a> Dipshan, <em>supra<\/em> note 60.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref66\" name=\"_ftn66\">[66]<\/a> <em>See <\/em>Scott &amp; Spaniel, <em>supra <\/em>note 2, at 4.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref67\" name=\"_ftn67\">[67]<\/a> Spring, <em>supra <\/em>note 57.<\/p>\n<p><a href=\"#_ftnref68\" name=\"_ftn68\"><\/a><\/p>\n<p>[68] Scott &amp; Spaniel, <em>supra <\/em>note 2, at 3.<\/p>\n<p><a href=\"#_ftnref69\" name=\"_ftn69\"><\/a><\/p>\n<p>[69] <em>See id. <\/em>at 4.<\/p>\n<p><a href=\"#_ftnref70\" name=\"_ftn70\"><\/a><\/p>\n<p>[70] <em>See <\/em>Jon Neiditz, <em>Ransomware in Society and Practice<\/em>, Practising Law Inst. 39, 41.<\/p>\n<p><a href=\"#_ftnref71\" name=\"_ftn71\"><\/a><\/p>\n<p>[71] <em>Id. <\/em><\/p>\n<p><em>\u00a0<\/em><\/p>\n<p><a href=\"#_ftnref72\" name=\"_ftn72\">[72]<\/a> <em>Id. <\/em><\/p>\n<p><a href=\"#_ftnref73\" name=\"_ftn73\"><\/a><\/p>\n<p>[73] Ben Rossen, <em>Ransomware \u2013 A Closer Look<\/em>, Fed. Trade Comm\u2019n (Nov. 10, 2016, 11:05 AM), https:\/\/www.ftc.gov\/news-events\/blogs\/business-blog\/2016\/11\/ransomware-closer-look, https:\/\/perma.cc\/3HX4-NDE3.<\/p>\n<p><a href=\"#_ftnref74\" name=\"_ftn74\"><\/a><\/p>\n<p>[74] Kharraz, <em>supra <\/em>note 6, at 2.<\/p>\n<p><a href=\"#_ftnref75\" name=\"_ftn75\"><\/a><\/p>\n<p>[75] Dipshan, <em>supra<\/em> note 60.<\/p>\n<p><a href=\"#_ftnref76\" name=\"_ftn76\"><\/a><\/p>\n<p>[76] Thompson Information Services<em>, Malware Attack Causes System Shutdown at Medstar<\/em>, 15 No. 4 Guide Med. Privacy &amp; HIPAA Newsl. 2, at 1 (May 2016) [hereinafter <em>Malware Attack<\/em>]<\/p>\n<p><a href=\"#_ftnref77\" name=\"_ftn77\"><\/a><\/p>\n<p>[77] Rossen, s<em>upra <\/em>note 73.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref78\" name=\"_ftn78\">[78]<\/a> Edwards<em>, supra<\/em> note 53.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref79\" name=\"_ftn79\">[79]<\/a> Spring, <em>supra<\/em> note 57.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref80\" name=\"_ftn80\">[80]<\/a> Largent, <em>supra<\/em> note 22.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref81\" name=\"_ftn81\">[81]<\/a> <em>See Technical Intricacies of Ransomware and Safeguarding Strategies<\/em>, Digital Mountain (Fall 2016) http:\/\/digitalmountain.com\/enews\/FALL_2016_Article2.pdf, https:\/\/perma.cc\/QV3V-ESJQ.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref82\" name=\"_ftn82\">[82]<\/a> Pollack, <em>supra<\/em> note 14, at 14.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref83\" name=\"_ftn83\">[83]<\/a> <em>See<\/em> Brian Krebs, <em>CryptoLocker Crew Ratchets Up the Ransom<\/em>, Krebs on Security (Nov. 6, 2013, 12:13 AM), http:\/\/krebsonsecurity.com\/tag\/cryptolocker-decryption-service\/, https:\/\/perma.cc\/7369-JSKT.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref84\" name=\"_ftn84\">[84]<\/a> Jardine, <em>supra<\/em> note 20, at 10.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref85\" name=\"_ftn85\">[85]<\/a> O&#8217;Gorman &amp; McDonald, <em>supra<\/em> note 19, at 2.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref86\" name=\"_ftn86\">[86]<\/a> Pollack, <em>supra<\/em> note 14, at 5.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref87\" name=\"_ftn87\">[87]<\/a> Edwards, <em>supra<\/em> note 53.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref88\" name=\"_ftn88\">[88]<\/a> <em>See <\/em>Azad Ali et. al., <em>supra<\/em> note 16, at 64.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref89\" name=\"_ftn89\">[89]<\/a> <em>See <\/em>Sentinel One, <em>Ransomware is Here: What You Can Do About It?<\/em> 2, https:\/\/go.sentinelone.com\/rs\/327-MNM-087\/images\/Sentinel%20One_Ransomware%20is%20Here.pdf, https:\/\/perma.cc\/3H46-QJCB.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref90\" name=\"_ftn90\">[90]<\/a> Pollack, <em>supra<\/em> note 14, at 5.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref91\" name=\"_ftn91\">[91]<\/a> <em>Id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref92\" name=\"_ftn92\">[92]<\/a> Wolff, <em>supra <\/em>note 12.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref93\" name=\"_ftn93\">[93]<\/a> Neiditz, <em>supra <\/em>note 71, at 7 (citing Danny Palmer, <em>Ransomware is Now the Biggest Cybersecurity Threat<\/em>, ZDNet (May 6, 2016), http:\/\/www.zdnet.com\/article\/ransomware-is-now-the-top-cybersecurity-threat-warns-kaspersky\/, https:\/\/perma.cc\/84XM-57M3).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref94\" name=\"_ftn94\">[94]<\/a> <em>Id<\/em>. at 9.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref95\" name=\"_ftn95\">[95]<\/a> Merrion, <em>supra<\/em> note 4.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref96\" name=\"_ftn96\">[96]<\/a> <em>Id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref97\" name=\"_ftn97\">[97]<\/a> Largent, <em>supra <\/em>note 22.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref98\" name=\"_ftn98\">[98]<\/a> Wolff, <em>supra <\/em>note 12.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref99\" name=\"_ftn99\">[99]<\/a> <em>See <\/em>Sean Sposito, <em>PayPal, OthersBuy Stolen Data from Criminals to Protect Users<\/em>, San Francisco Chron. (Jan. 8, 2016), http:\/\/www.sfchronicle.com\/business\/article\/PayPal-others-buy-stolen-data-from-criminals-to-6744699.php, https:\/\/perma.cc\/XLE9-AX3Q.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref100\" name=\"_ftn100\">[100]<\/a> Daniel Crothers, <em>Cybersecurity for Lawyers \u2013 Part IV: Is Payment of Ransom in Your Budget?, <\/em>63 The Gavel 24, 24 (2016).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref101\" name=\"_ftn101\">[101]<\/a> Pollack, <em>supra<\/em> note 14, at 11 (quoting unnamed consultant \u201cD\u201d).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref102\" name=\"_ftn102\">[102]<\/a> <em>See <\/em>Mathew J. Schwartz, <em>Please Don\u2019t Pay Ransoms, FBI Urges, <\/em>Data Breach Today (May 4, 2016), http:\/\/www.databreachtoday.com\/blogs\/please-dont-pay-ransoms-fbi-urges-p-2120, https:\/\/perma.cc\/8ZND-KM2J.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref103\" name=\"_ftn103\">[103]<\/a> <em>See <\/em>A.B.A., <em>Practical steps to thwart ransomware and other cyberbreaches<\/em>, YourABA (Dec. 2016), http:\/\/www.americanbar.org\/publications\/youraba\/2016\/december-2016\/be-prepared-to-thwart-ransomware-and-other-cyber-attacks.html, https:\/\/perma.cc\/LFT2-UP9E.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref104\" name=\"_ftn104\">[104]<\/a> <em>See<\/em> Neiditz, <em>supra<\/em> note 70, at 41.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref105\" name=\"_ftn105\">[105]<\/a> <em>See<\/em> <em>id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref106\" name=\"_ftn106\">[106]<\/a> Jardine, <em>supra<\/em> note 20, at 10-11.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref107\" name=\"_ftn107\">[107]<\/a> Doug Pollack, Ransomware 101: What to Do When Your Data is Held Hostage, 5 (2016) (ebook).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref108\" name=\"_ftn108\">[108]<\/a> <em>See id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref109\" name=\"_ftn109\">[109]<\/a> <em>Id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref110\" name=\"_ftn110\">[110]<\/a> <em>See<\/em> <em>Fact Sheet: Ransomware and HIPAA<\/em>, Dept. of Health &amp; Hum. Serv., http:\/\/www.hhs.gov\/sites\/default\/files\/RansomwareFactSheet.pdf, https:\/\/perma.cc\/G6ZV-S87S (last visited Feb. 8, 2017).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref111\" name=\"_ftn111\">[111]<\/a> Paul Merrion, <em>HHS Clarifies When Ransomware Attacks Trigger HIPAA Notification<\/em>, CQ Roll Call, July 13, 2016, 2016 WL 3709987 [hereinafter <em>HHS Clarifies<\/em>].<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref112\" name=\"_ftn112\">[112]<\/a> Jocelyn Samuels, <em>Your Money or Your PHI: New Guidance on Ransomware, <\/em>OpenHealth News, July 11, 2016, http:\/\/www.openhealthnews.com\/news-clipping\/2016-07-11\/your-money-or-your-phi-hhs-issues-new-guidance-ransomware, https:\/\/perma.cc\/Q7P7-P8WL<strong>.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref113\" name=\"_ftn113\">[113]<\/a> John Neiditz &amp; David Cox, <em>Beyond Breaches: Growing Issues In Information Security<\/em>, Integro (2016), https:\/\/integrogroup.com\/uploads\/white_papers\/06_16_Beyond-Breaches.pdf, https:\/\/perma.cc\/U5EJ-SAC8.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref114\" name=\"_ftn114\">[114]<\/a> <em>HHS Clarifies<\/em>, <em>supra <\/em>note 111.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref115\" name=\"_ftn115\">[115]<\/a> <em>See generally <\/em>Azad Ali et. al., <em>supra <\/em>note 16, at 66 (describing the authors\u2019 personal experience with ransomware mechanisms).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref116\" name=\"_ftn116\">[116]<\/a> <em>See id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref117\" name=\"_ftn117\">[117]<\/a> <em>See <\/em>Adam Alessandrini, <em>Ransomware Hostage Rescue Manual<\/em>, KnowBe4 (2015) at 8, http:\/\/resources.idgenterprise.com\/original\/AST-0147692_Ransomware-Hostage-Rescue-Manual.pdf, https:\/\/perma.cc\/KNS8-BT5N.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref118\" name=\"_ftn118\">[118]<\/a> <em>See id.<\/em> at 7<em>.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref119\" name=\"_ftn119\">[119]<\/a> Tom Spring, <em>Dirt Cheap Stampado Ransomware Sells on Dark Web for $39<\/em>, ThreatPost, July 14, 2016, https:\/\/threatpost.com\/dirt-cheap-stampado-ransomware-sells-on-dark-web-for-39\/119284\/, https:\/\/perma.cc\/2LAV-63HE.<\/p>\n<p><a href=\"#_ftnref120\" name=\"_ftn120\"><\/a><\/p>\n<p>[120] <em>See<\/em> Crothers, <em>supra<\/em> note 100 at 24.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref121\" name=\"_ftn121\">[121]<\/a> <em>See<\/em> Scott &amp; Spaniel, <em>supra <\/em>note 2, at 3.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref122\" name=\"_ftn122\">[122]<\/a> <em>See <\/em>Ondrej Kehel, <em>Ransomware: To Pay or Not To Pay<\/em>, LexisNexis, Aug. 16, 2016, https:\/\/www.lexisnexis.com\/communities\/corporatecounselnewsletter\/b\/newsletter\/archive\/2016\/08\/16\/ransomware-to-pay-or-not-to-pay.aspx, https:\/\/perma.cc\/V2JJ-YHPT.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref123\" name=\"_ftn123\">[123]<\/a> <em>See <\/em>Azad Ali et. al., <em>supra <\/em>note 16, at 64.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref124\" name=\"_ftn124\">[124]<\/a> <em>See<\/em> Jardine, <em>supra <\/em>note 20, at 10.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref125\" name=\"_ftn125\">[125]<\/a> Scott &amp; Spaniel, <em>supra <\/em>note 2, at 4.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref126\" name=\"_ftn126\">[126]<\/a> <em>Id<\/em>. at 5.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref127\" name=\"_ftn127\">[127]<\/a> Michael Sutton, <em>Big Business Ransomware: A Lucrative Market in the Underground Economy<\/em>, DarkReading, July 1, 2016, http:\/\/www.darkreading.com\/vulnerabilities&#8212;threats\/big-business-ransomware-a-lucrative-market-in-the-underground-economy\/a\/d-id\/1326144, https:\/\/perma.cc\/3GUA-Z8UE.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref128\" name=\"_ftn128\">[128]<\/a> Maria Korolov, <em>Will Your Backups Protect You Against Ransomware?<\/em>, CSO (May 31, 2016) http:\/\/www.csoonline.com\/article\/3075385\/backup-recovery\/will-your-backups-protect-you-against-ransomware.html, https:\/\/perma.cc\/LM56-ZMY5.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref129\" name=\"_ftn129\">[129]<\/a> Doug Pollack, <em>How Ransomware Could Hold Your Business Hostage<\/em>, idexerts, Apr. 29, 2016, https:\/\/www2.idexpertscorp.com\/blog\/single\/how-ransomware-could-hold-your-business-hostage, https:\/\/perma.cc\/VK9J-B4J5.<\/p>\n<p>.<\/p>\n<p><a href=\"#_ftnref130\" name=\"_ftn130\">[130]<\/a> <em>See<\/em> Haley Sweetland Edwards, <em>A Devastating Type of Hack is Costing People Big Money<\/em>, Time (Apr. 21, 2016), http:\/\/time.com\/4303129\/hackers-computer-ransom-ransomware\/, https:\/\/perma.cc\/VS8M-CDZW.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref131\" name=\"_ftn131\">[131]<\/a> Nicole van der Meulen et. al., <em>Cybersecurity in the European Union and Beyond: Exploring the Threats and Policy Responses<\/em>, European Parliament at 35 (2015), http:\/\/www.europarl.europa.eu\/RegData\/etudes\/STUD\/2015\/536470\/IPOL_STU(2015)536470_EN.pdf, https:\/\/perma.cc\/242L-VJTM (citing Richard Pinson, <em>Computer threat: Cryptolocker virus is ransomware<\/em>, Nashville Business Journal, Aug. 10, 2015 http:\/\/www.bizjournals.com\/nashville\/blog\/2015\/08\/computer-threatcryptolocker-virus-is-ransomware.html, https:\/\/perma.cc\/69SN-RD2Y (last visited Oct. 12, 2015)).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref132\" name=\"_ftn132\">[132]<\/a> Michael Sutton,<em> Big Business Ransomware: A Lucrative Market in the Underground Economy<\/em>, DarkReading (July 1, 2016 11:20 AM) http:\/\/www.darkreading.com\/vulnerabilities&#8212;threats\/big-business-ransomware-a-lucrative-market-in-the-underground-economy\/a\/d-id\/1326144, https:\/\/perma.cc\/63LK-7855.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref133\" name=\"_ftn133\">[133]<\/a> O\u2019Gorman &amp; McDonald, <em>supra <\/em>note 19, at 4.<\/p>\n<p><strong>\u00a0<\/strong><\/p>\n<p><a href=\"#_ftnref134\" name=\"_ftn134\">[134]<\/a> <em>See id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref135\" name=\"_ftn135\">[135]<\/a> Ben Rossen, <em>How to Defend Against Ransomware<\/em>, Federal Trade Commission, Nov. 10, 2016, https:\/\/www.consumer.ftc.gov\/blog\/how-defend-against-ransomware, https:\/\/perma.cc\/7VVN-WG2L.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref136\" name=\"_ftn136\">[136]<\/a> Scott &amp; Spaniel, <em>supra <\/em>note 2, at 5.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref137\" name=\"_ftn137\">[137]<\/a> <em>Malware Attack<\/em>, <em>supra <\/em>note 76, at 1.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref138\" name=\"_ftn138\">[138]<\/a> Edwards, <em>supra <\/em>note 54.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref139\" name=\"_ftn139\">[139]<\/a> Rossen, <em>supra <\/em>note 73.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref140\" name=\"_ftn140\">[140]<\/a> Scott &amp; Spaniel, <em>supra <\/em>note 2, at 5.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref141\" name=\"_ftn141\">[141]<\/a> Merrion, <em>supra <\/em>note 4.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref142\" name=\"_ftn142\">[142]<\/a> <em>See <\/em>Azad Ali et. al., <em>supra <\/em>note 16, at 63.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref143\" name=\"_ftn143\">[143]<\/a> <em>See <\/em>Barber, Simon, Xavier Boyen, Elaine Shi, and Ersin Uzun,<em> Bitter to better\u2014how to make bitcoin a better currency<\/em>, International Conference on Financial Cryptography and Data Security, pp. 399-414. Springer Berlin Heidelberg (2012). <em>See also, Who is Satoshi Nakamoto<\/em>, CoinDesk, Feb. 19, 2016, http:\/\/www.coindesk.com\/information\/who-is-satoshi-nakamoto\/, https:\/\/perma.cc\/6JP8-NLRU.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref144\" name=\"_ftn144\">[144]<\/a> <em>See generally <\/em>Andy Greenberg, <em>Follow The Bitcoins: How We Got Busted Buying Drugs On Silk Road\u2019s Black Market<\/em>, Forbes (Sept. 5, 2013), https:\/\/www.forbes.com\/sites\/andygreenberg\/2013\/09\/05\/follow-the-bitcoins-how-we-got-busted-buying-drugs-on-silk-roads-black-market\/#3cd73b93adf7, https:\/\/perma.cc\/ZEA2-JPDR\u00a0(explaining why Bitcoin is used for underground transactions).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref145\" name=\"_ftn145\">[145]<\/a> Jamie Doward, <em>City Banks Plan to Hoard Bitcoins to Help Them Pay Cyber Ransoms<\/em>, The Guardian, Oct. 22, 2016, https:\/\/www.theguardian.com\/technology\/2016\/oct\/22\/city-banks-plan-to-hoard-bitcoins-to-help-them-pay-cyber-ransoms, https:\/\/perma.cc\/PG4H-2TVL.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref146\" name=\"_ftn146\">[146]<\/a> <em>See <\/em>Robert Mclean, <em>Hospital Pays Bitcoin Ransom After Malware Attack<\/em>, CNN, Feb. 17, 2016, http:\/\/money.cnn.com\/2016\/02\/17\/technology\/hospital-bitcoin-ransom\/, https:\/\/perma.cc\/78FT-GUMM.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref147\" name=\"_ftn147\">[147]<\/a> Doug Pollack, <em>Tradable, Untraceable, Sometimes Unavoidable: The Business of Bitcoin<\/em>, id Experts, June 20, 2016, https:\/\/www2.idexpertscorp.com\/blog\/single\/tradable-untraceable-sometimes-unavoidable-the-business-of-bitcoin, https:\/\/perma.cc\/VM4R-R2Y4.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref148\" name=\"_ftn148\">[148]<\/a> <em>See <\/em>Ramsey &amp; Morse, <em>supra <\/em>note 23, at 7.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref149\" name=\"_ftn149\">[149]<\/a> <em>IRS Virtual Currency Guidance: Virtual Currency Is Treated as Property of U.S. Federal Tax Purposes; General Rules for Property Transactions Apply<\/em>, IRS, Mar. 25, 2014, https:\/\/www.irs.gov\/uac\/newsroom\/irs-virtual-currency-guidance, https:\/\/perma.cc\/JP66-2H87.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref150\" name=\"_ftn150\">[150]<\/a> I.R.S. Notice 2014-21 at 3, Mar. 25, 2014, https:\/\/www.irs.gov\/irb\/2014-16_IRB\/ar12.html, https:\/\/perma.cc\/MX9U-WCWN.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref151\" name=\"_ftn151\">[151]<\/a> <em>See <\/em>Ramsey &amp; Morse, <em>supra <\/em>note 23, at 5.<\/p>\n<p><em>\u00a0<\/em><\/p>\n<p><a href=\"#_ftnref152\" name=\"_ftn152\">[152]<\/a> <em>Id.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref153\" name=\"_ftn153\">[153]<\/a> <em>Manhattan U.S. Attorney Announces Charges Against Two Florida Men for Operating an Underground Bitcoin Exchange<\/em>, FBI, July 21, 2015, https:\/\/www.fbi.gov\/contact-us\/field-offices\/newyork\/news\/press-releases\/manhattan-u.s.-attorney-announces-charges-against-two-florida-men-for-operating-an-underground-bitcoin-exchange, https:\/\/perma.cc\/Z85B-LT87.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref154\" name=\"_ftn154\">[154]<\/a> <em>Id.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref155\" name=\"_ftn155\">[155]<\/a> <em>Id.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref156\" name=\"_ftn156\">[156]<\/a> <em>Id.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref157\" name=\"_ftn157\">[157]<\/a> <em>See <\/em>David S. Cohen, <em>Kidnapping for Ransom: The Growing Terrorist Financing Challenge<\/em>, Council on Foreign Relations, Oct. 5, 2012, http:\/\/www.cfr.org\/terrorist-financing\/remarks-treasury-under-secretary-cohenkidnapping-ransom-growing-terrorist-financing-challenge\/p29376, https:\/\/perma.cc\/6X6P-NKHJ.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref158\" name=\"_ftn158\">[158]<\/a> Samuel Cutler, <em>Could the Administration&#8217;s New Hostage Policy Leave Banks Vulnerable?<\/em>, Sanction Law, June 24, 2015, http:\/\/sanctionlaw.com\/could-the-administrations-new-hostage-policy-leave-banks-vulnerable\/, https:\/\/perma.cc\/5B9Z-KX23.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref159\" name=\"_ftn159\">[159]<\/a> <em>See <\/em>18 U.S.C. \u00a7 2339B (2012).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref160\" name=\"_ftn160\">[160]<\/a> <em>See id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref161\" name=\"_ftn161\">[161]<\/a> Ramsey &amp; Morse, <em>supra<\/em> note 23, at 14.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref162\" name=\"_ftn162\">[162]<\/a> <em>See<\/em> Exec. Order No. 13,694, 80 Fed. Reg. 18,077 (Apr. 1, 2015).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref163\" name=\"_ftn163\">[163]<\/a> Ramsey &amp; Morse, <em>supra <\/em>note 23, at 14 (quoting Exec. Order No. 13,694, 80 Fed. Reg. at 18078).<\/p>\n<p><a href=\"#_ftnref164\" name=\"_ftn164\"><\/a><\/p>\n<p>[164] <em>See<\/em> <em>id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref165\" name=\"_ftn165\">[165]<\/a> <em>See <\/em>Cutler, <em>supra <\/em>note 158; <em>see also<\/em> <em>Statement by the President on the U.S. Government\u2019s Hostage Policy Review<\/em>, The White House Office of the Press Secretary, June 24, 2015, https:\/\/www.whitehouse.gov\/the-press-office\/2015\/06\/24\/statement-president-us-governments-hostage-policy-review, https:\/\/perma.cc\/W5J4-UNFK (\u201c[T]he United States government will not make concessions, such as paying ransom, to terrorist groups holding American hostages\u2026. At the same time, we are clarifying that our policy does not prevent communication with hostage-takers \u2013 by our government, the families of hostages, or third parties who help these families\u201d).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref166\" name=\"_ftn166\">[166]<\/a> <em>See Statement by the President on the U.S. Government\u2019s Hostage Policy Review<\/em>, <em>supra <\/em>note 165.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref167\" name=\"_ftn167\">[167]<\/a><em> See, e.g.<\/em>,<em> Manhattan U.S. Attorney Announces Charges Against Two Florida Men for Operating an Underground Bitcoin Exchange<\/em>, <em>supra<\/em> note 153. DOUBLE CHECK THIS TO SEE IF ACTUALY 18 USC 2339<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref168\" name=\"_ftn168\">[168]<\/a> <em>Incidents of Ransomware on the Rise: Protect Yourself and Your Organization,<\/em> FBI, April 29, 2016, https:\/\/www.fbi.gov\/news\/stories\/incidents-of-ransomware-on-the-rise\/incidents-of-ransomware-on-the-rise, https:\/\/perma.cc\/83FC-G2W8<\/p>\n<p>(citing Federal Bureau of Investigation Cyber Division Assistant Director James Trainor).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref169\" name=\"_ftn169\">[169]<\/a> <em>See<\/em> <em>OFAC FAQs: Sanctions Compliance<\/em>, U.S. Dep&#8217;t of the Treasury, https:\/\/www.treasury.gov\/resource-center\/faqs\/Sanctions\/Pages\/faq_compliance.aspx, https:\/\/perma.cc\/2ACP-XZ7V (last visited Mar. 31, 2017).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref170\" name=\"_ftn170\">[170]<\/a> <em>See<\/em> Jardine,<em> supra<\/em> note 20, at 11.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref171\" name=\"_ftn171\">[171]<\/a> Sposito, <em>supra<\/em> note 99.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref172\" name=\"_ftn172\">[172]<\/a> <em>See <\/em>United States v. Kozeny, 582 F. Supp. 2d 535, 540 (S.D.N.Y. 2008).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref173\" name=\"_ftn173\">[173]<\/a> Ramsey &amp; Morse, <em>supra <\/em>note 23, at 19 (emphasis added).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref174\" name=\"_ftn174\">[174]<\/a> <em>See <\/em>Korolov, <em>supra <\/em>note 128.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref175\" name=\"_ftn175\">[175]<\/a> <em>See, e.g.<\/em>, Ivan Hemmans &amp; David G. Ries, <em>Cybersecurity: Ethically Protecting Your Confidential Data in a Breach-A-Day World<\/em> (PowerPoint), at slides 18\u201321, April 27, 2016, http:\/\/www.americanbar.org\/content\/dam\/aba\/multimedia\/cle\/materials\/2016\/04\/ce1604lpi.authcheckdam.pdf, https:\/\/perma.cc\/V4T7-TAFT.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref176\" name=\"_ftn176\">[176]<\/a> <em>Comment on Rule 1.1<\/em>, American Bar Association: The Center for Professional Responsibility, http:\/\/www.americanbar.org\/groups\/professional_responsibility\/publications\/model_rules_of_professional_conduct\/model_rules_of_professional_conduct_table_of_contents.html, https:\/\/perma.cc\/GC6Q-4FN6 (last visited Feb. 12, 2017).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref177\" name=\"_ftn177\">[177]<\/a> <em>FBI Internet Crime Complaints<\/em>, Florida Atlantic University, http:\/\/www.fau.edu\/police\/images\/FBI%20Internet%20Crime%20Complaints.pdf, https:\/\/perma.cc\/5LLL-JGCE (last visited Feb. 12, 2017); <em>see also Incidents of Ransomware on the Rise: Protect Yourself and Your Organization<\/em>, <em>supra<\/em> note 168.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref178\" name=\"_ftn178\">[178]<\/a> Rossen, <em>supra <\/em>note 73.<\/p>\n<p><em>\u00a0<\/em><\/p>\n<p><a href=\"#_ftnref179\" name=\"_ftn179\">[179]<\/a> <em>See <\/em>15 U.S.C. \u00a7 6803; <em>see also Ransomware \u2013 Legal Liability and Enforcement<\/em>, Fall 2016 E-Newsletter (Digital Mountain, Santa Clara, C.A.), Oct. 24, 2016, http:\/\/digitalmountain.com\/enews\/FALL_2016_Article3.pdf, https:\/\/perma.cc\/7YWZ-C3GP.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref180\" name=\"_ftn180\">[180]<\/a> <em>Ransomware \u2013 Legal Liability and Enforcement<\/em>, <em>supra<\/em> note 179.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref181\" name=\"_ftn181\">[181]<\/a> <em>Fact Sheet: Ransomware and HIPAA<\/em>, <em>supra<\/em> note 110.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref182\" name=\"_ftn182\">[182]<\/a> <em>Malware Attack<\/em>, <em>supra <\/em>note 76 (quoting John Parmigiani, HIPAA consultant and editorial advisory board member).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref183\" name=\"_ftn183\">[183]<\/a> <em>See, e.g.<\/em>, United States v. Haymond, No. 08-CR-201-TCK, 2016 WL 4094886, at *2 (N.D. Okla. Aug. 2, 2016).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref184\" name=\"_ftn184\">[184]<\/a> <em>See <\/em>Virginia College Savings Plan v. Zhouda, 2016 WL 5920046 (UDRP-ARB Dec), at *2\u20133 (Lowry, Arb.).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref185\" name=\"_ftn185\">[185]<\/a> <em>See generally<\/em> Ed Silverstein, <em>Law Firm Among the Latest Victims of Ransomware Attack<\/em>, Law Technology News, Mar. 11, 2015, www.legaltechnews.com\/id=1202720266972\/Law-Firm-Among-the-Latest-Victims-of-Ransomware-Attack, https:\/\/perma.cc\/4QVA-3Z4B (detailing a law firm\u2019s recent ransomware attack).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref186\" name=\"_ftn186\">[186]<\/a> <em>See <\/em>Univ. of Montreal Pension Plan v. Bank of Am. Sec., LLC, 685 F. Supp. 2d 456, 462 (S.D.N.Y. 2010).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref187\" name=\"_ftn187\">[187]<\/a> <em>See <\/em>Korolov, <em>supra <\/em>note 128.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref188\" name=\"_ftn188\">[188]<\/a> James A. Sherer, Taylor M. Hoffman &amp; Eugenio E. Ortiz, <em>Merger and Acquisition Due Diligence: A Proposed Framework to Incorporate Data Privacy, Information Security, e-Discovery, and Information Governance into Due Diligence Practices<\/em>, 21 Rich J.L. &amp; Tech 5, \u00b6 36 (2015), http:\/\/jolt.richmond.edu\/v21i2\/article5.pdf, https:\/\/perma.cc\/4KBL-2GZ6.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref189\" name=\"_ftn189\">[189]<\/a> This is often a mandatory \u201cexception\u201d in many Records and Information Management and Information Governance policies. <em>See<\/em> Vicki Miller Luoma, <em>Computer Forensics and Electronic Discovery: The New Management Challenge<\/em>, 25 Computers &amp; Security 91, 96 (2006) (When creating an \u201celectronic document retention and deletion policy . . . [a]ny such policy must retain the flexibility to implement litigation holds by suspending routine document deletion\u201d in the face of a reasonable anticipation of litigation).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref190\" name=\"_ftn190\">[190]<\/a> <em>See <\/em>Crothers, <em>supra <\/em>note 100.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref191\" name=\"_ftn191\">[191]<\/a> <em>Ransomware: Past, Present, and Future<\/em>, <em>supra<\/em> note 22.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref192\" name=\"_ftn192\">[192]<\/a> <em>See id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref193\" name=\"_ftn193\">[193]<\/a> Tom Spring, <em>Dirt Cheap Stampado Ransomware Sells on Dark Web for $39<\/em>, ThreatPost (July 14, 2016, 12:35 PM), https:\/\/threatpost.com\/dirt-cheap-stampado-ransomware-sells-on-dark-web-for-39\/119284\/, https:\/\/perma.cc\/5FLX-GBPM.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref194\" name=\"_ftn194\">[194]<\/a> <em>See <\/em>Ben Dickson, <em>What makes IoT ransomware a different and more dangerous threat?<\/em>, Tech Crunch, Oct. 2, 2016, https:\/\/techcrunch.com\/2016\/10\/02\/what-makes-iot-ransomware-a-different-and-more-dangerous-threat\/, https:\/\/perma.cc\/8VEP-HUK4.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref195\" name=\"_ftn195\">[195]<\/a> Korolov, <em>supra <\/em>note 128.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref196\" name=\"_ftn196\">[196]<\/a> Sutton, <em>supra <\/em>note 127.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref197\" name=\"_ftn197\">[197]<\/a> <em>Id<\/em>.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref198\" name=\"_ftn198\">[198]<\/a> <em>See <\/em>Brian Buntz, <em>The 10 Most Vulnerable IoT Security Targets<\/em>, Internet of Things Institute, July 27, 2016, http:\/\/www.ioti.com\/security\/10-most-vulnerable-iot-security-targets?NL=IOT-001UBER&amp;Issue=IOT-001UBER_20160804_IOT-001UBER_796&amp;sfvc4enews=42&amp;cl=article_7&amp;utm_rid=CPG03000004380699&amp;utm_campaign=13637&amp;utm_medium=email&amp;elq2=6a8551b97117440a8d6f316007c6c548, https:\/\/perma.cc\/8UH5-QPVT.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref199\" name=\"_ftn199\">[199]<\/a> Korolov, <em>supra <\/em>note 128.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref200\" name=\"_ftn200\">[200]<\/a> <em>See generally <\/em>Speed (Twentieth Century Fox Film Corp. 1994) (a film in which a police officer must drive a bus above 50 miles per hour in order to prevent a bomb from exploding on the bus).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref201\" name=\"_ftn201\">[201]<\/a> <em>Raynham Remains Offline in Computer Virus Mystery<\/em>, Wicked Local (Mar. 11, 2016, 5:30 PM), http:\/\/www.wickedlocal.com\/news\/20160311\/raynham-remains-offline-in-computer-virus-mystery, https:\/\/perma.cc\/BWW8-J9DF (quoting Brian Contos, ICIT Fellow and VP &amp; Chief Sec. Strategist at Securonix).<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref202\" name=\"_ftn202\">[202]<\/a> <em>See <\/em>Wolff, <em>supra <\/em>note 12.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref203\" name=\"_ftn203\">[203]<\/a> <em>See <\/em>Sposito, <em>supra <\/em>note 99.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref204\" name=\"_ftn204\">[204]<\/a> <em>See <\/em>Cutler, <em>supra <\/em>note 158.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref205\" name=\"_ftn205\">[205]<\/a> <em>See<\/em> <em>Practical Steps to Thwart Ransomware and Other Cyberbreaches<\/em>, Your ABA, Dec. 2016, http:\/\/www.americanbar.org\/publications\/youraba\/2016\/december-2016\/be-prepared-to-thwart-ransomware-and-other-cyber-attacks.html, https:\/\/perma.cc\/5RX3-WWJG.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sherer Publication Version PDF Cite as: James A. Sherer, Melinda L. McLellan, Emily R. Fedeles, and Nichole L. Sterling,\u00a0Ransomware \u2013 Practical and Legal Considerations for Confronting the New Economic Engine of the Dark Web,\u00a023 Rich. J.L. &amp; Tech. Ann. Survey (2017), http:\/\/jolt.richmond.edu\/2017\/04\/30\/volume23_annualsurvey_sherer\/. &nbsp; By: James A. Sherer,* Melinda L. McLellan,** Emily R. Fedeles,*** and Nichole [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1228],"tags":[],"class_list":["post-6548","post","type-post","status-publish","format-standard","hentry","category-articles"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-1HC","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/6548","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=6548"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/6548\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=6548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=6548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=6548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}