How to Respond to a Cyber Extortion Demand

BCLP
Contact

Cyber extortion refers to a situation in which a third party threatens that if an organization does not pay money, or take a certain action, the third party will take an adverse action against the organization.  Among other things, threats may include exploiting a security vulnerability identified by the extorter, reporting the organization’s security vulnerability to the press, or reporting the organization’s security vulnerability to regulators. 

Below is a checklist for organizations that are confronted by a cyber extortion demand.

  1.  Is the threat credible?
  2.  If the exploitation of a security vulnerability is threatened, can the organization identify the vulnerability without the aid of the extortionist?
  3.  If the disclosure of non-public information is threatened, is there any evidence that the information has not already been disclosed or shared with others?
  4.  If an extortion demand is paid, what is the likelihood that your organization will receive similar demands in the near future?
  5.  If your organization were to pay the demand, is it likely that the recipient of the funds may be associated with terrorism or located in a restricted country?
  6.  Is cyber extortion covered under your cyber insurance policy?

The following provides a snapshot of information concerning cyber extortion.

9,715

The number of entities that reported being victimized by cyber extortion over a six month period.1

85%

Estimate of the percentage of cyber extortion cases that are not reported.2

$2,500 - $100,000

Range of unsolicited demands related to alleged security vulnerabilities made to Bryan Cave clients between 2014 and 2015.

 

[1] Id. 

[2] NYA International, Cyber Extortion Risk Report (Oct. 2015) at 3.

[View source.]

 

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© BCLP | Attorney Advertising

Written by:

BCLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

BCLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide