This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Quel rôle la cryptomonnaie joue-t-elle sur la propagation et l’évolution des attaques de rançongiciels ?

Download resources

About this session

In a radio talk-show format, Sébastien Lapointe of Desjardins hosts Nicolas Bergevin (Armis) and Éric Hébert (Quebecor) on whether cryptocurrency drives the ransomware wave. Bergevin recalls the original promise of decentralised, low-cost payments for the unbanked, then explains how pseudonymous wallets made it the payment rail of choice for criminals. Hébert traces the lineage of extortionware from fake antivirus and police lock-screen scams through CryptoLocker in 2013 to the leak of state-grade exploit tools between 2016 and 2018, which let ransomware spread across thousands of machines and gave rise to ransomware-as-a-service. Asked whether crypto should be regulated or banned, both dismiss a ban as unenforceable and point instead to KYC rules on exchanges, blockchain-tracing firms, tax authorities hungry for revenue and the partial recovery of the Colonial Pipeline ransom. They warn that criminals will simply raise ransoms and move to peer-to-peer wallets, and close by urging organisations to keep hardening their posture, test continuity plans and watch for attacks that arrive through SaaS suppliers.

 Au cours des dernières années, la quantité et la qualité des campagnes de rançongiciels a connu une hausse significative et si rien ne change, l'impact desrançongiciels persistera probablement dans un avenir prévisible. Il est d’ailleurs préoccupant de constater que les attaques récentes ciblent de plus en plus les organisations qui prodiguent des services essentiels à la population.  La popularité de la cryptomonnaie et l’augmentation des attaques de rançongiciels est-elle une coïncidence ? Est-ce que des moyens comme réglementer la cryptomonnaie ou interdire le paiement de rançon par cryptomonnaie pourrait contribuer à diminuer significativement l’ampleur des attaques de rançongiciels ? 

Afin de faire le tour de ces questions et de tenter une réponse, Sébastien Lapointe s’entretient avec les experts en sécurité de l’information, Éric Hébert et Nicolas Bergevin, le tout dans un format dans un format radio talk show.  

Key takeaways

  • Do not wait for regulation: keep raising your security posture with awareness programs, good practices and tested business-continuity plans, because a ransomware hit is no longer an improbable scenario.
  • Expect ransom demands to rise as more of each payment gets traced and seized; attackers will price in the share they lose to authorities.
  • Watch your SaaS suppliers: the newer pattern is compromising one provider to reach all its customers, so even an untargeted organisation can be hit collaterally.
  • Treat crypto as a traceable asset, not an anonymous one: public ledgers, exchange KYC and blockchain-analytics firms are how the Colonial Pipeline funds were partly recovered.
  • Remember the lineage: today's ransomware combines CryptoLocker-style encryption with leaked state-grade propagation tools, so containing lateral movement matters as much as backups.

Speakers

Sébastien Lapointe
Sébastien Lapointe
Business information security officer · Desjardins group
Sébastien Lapointe recently joined the Desjardins Group in a new role as the business information security officer (BISO) of IT. A financial cooperative that manages $229 billion requires uncompromising security and in his role one Sebastien’s main… Read moreRead less

Sébastien Lapointe recently joined the Desjardins Group in a new role as the business information security officer (BISO) of IT. A financial cooperative that manages $229 billion requires uncompromising security and in his role one Sebastien’s main responsibility is to implement the security operating model for the IT business sector. Prior to that, he was working for the Société de transport de Montréal (STM) as the Chief Architecture and Information Security Officer where he leads a multidisciplinary team of experts specialized in IT and OT technology. Sebastien has over 20 years of experience in the field of information security and risk management. His career started in the public sector working for the government of Canada as an IT security analyst. Strong from this experience he tackled the consulting business working with big IT firms and financial institutions. His work was mainly focused on building IT security architecture and IT security threat and risk assessments. He also co-founded CyberAction Canada a non-profit organization seeking to provide research and awareness on the secure usage of information and communication technology to protect the dignity and the personal integrity of children on the Internet. He holds multiple security certifications and a Specialized Graduate Diploma in IT governance, audit and security from Sherbrooke University.

Éric G. Hébert
Éric G. Hébert
CISO · Quebecor
CISO and Vice-President of Quebecor, which includes Videotron, Quebecor Media and TVA, among others, Éric Hébert has extensive experience in team leadership, cybersecurity program management, risk management and governance. Wherever it goes, it… Read moreRead less

CISO and Vice-President of Quebecor, which includes Videotron, Quebecor Media and TVA, among others, Éric Hébert has extensive experience in team leadership, cybersecurity program management, risk management and governance. Wherever it goes, it strives to instill cultural change that is conducive to information security and to mitigate divergent views. His pragmatic approach is appreciated by the CEOs, Directors and other VPs he works with. In a career of more than 25 years, he is most often found as a CISO, trusted advisor or lecturer. He maintains a regular presence in the information security community and regularly shares his experiences and opinions during conferences and interviews.

Nicolas Bergevin
Nicolas Bergevin
Senior Account Executive · Armis

Resources

Tags

More from GoSec 2021

Also from Sébastien Lapointe

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.