Ransomware attacks on financial institutions can have effects beyond the attacked institution itself. When the attacked institution is forced offline, other financial market participants are left unable to complete transactions or obtain information, disturbing normal operations of financial markets. In this paper, we argue that such spillover effects are an important aspect of ransomware attacks and that cybersecurity management should be concerned with them and their mitigation. We illustrate this using three recent cases of ransomware attacks by the LockBit group on financial institutions that had spillover effects on the wider financial market. We identify four lessons learned for market participants facing such spillovers: ensuring the quick substitution of blocked resources, preparing to execute automated processes manually, networking with industry associations, and actively involving regulators. Overall, we hope to raise awareness of spillover effects of ransomware attacks for cybersecurity research and practice.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Mitigating Spillover Effects of Ransomware in Financial Markets: Lessons from the LockBit Attacks

  • Frederic Schlackl,
  • Alina Dulipovici,
  • Vincent Grégoire

摘要

Ransomware attacks on financial institutions can have effects beyond the attacked institution itself. When the attacked institution is forced offline, other financial market participants are left unable to complete transactions or obtain information, disturbing normal operations of financial markets. In this paper, we argue that such spillover effects are an important aspect of ransomware attacks and that cybersecurity management should be concerned with them and their mitigation. We illustrate this using three recent cases of ransomware attacks by the LockBit group on financial institutions that had spillover effects on the wider financial market. We identify four lessons learned for market participants facing such spillovers: ensuring the quick substitution of blocked resources, preparing to execute automated processes manually, networking with industry associations, and actively involving regulators. Overall, we hope to raise awareness of spillover effects of ransomware attacks for cybersecurity research and practice.