The Case of Maastricht University Paying Ransom After a Cyber Attack
摘要
On October 15, 2019, criminal hackers sent a phishing email to several individuals within Maastricht University. One of the employees clicks on the link in this email, resulting in the installation of malware from an external server on this employee’s workstation. A second phishing email is clicked by another employee the following day. The hackers demanded 200,000 euros in bitcoins. With the involvement of experienced parties and the Police, the Board must decide whether to pay the ransom. The decision to pay or not to pay the ransom was a heavy moral assessment for the university’s board and a ‘devil’s dilemma’, ‘with very significant moral objections’ towards paying the ransom.