Ransomware

Ransomware India: business क्यों ransom भरते हैं जो afford नहीं

Ransomware India में SMB/hospital क्यों pay करते हैं — breach से extortion तक, pay क्यों fail होता है, backups/CERT-In, और आज के 7 preparation steps।

CyberSathi DeskAI-assisted · editorially reviewed
Ransomware India: business क्यों ransom भरते हैं जो afford नहीं

वह hospital जो “no” नहीं कह सका

Ransomware India में SMB और hospitals अक्सर ransom भर देते हैं जो afford नहीं — fear + broken backups। Bangalore, March 2023. 40-bed private hospital को IT vendor जैसा email — “firmware update” attachment। Admin ने खोला।

छह घंटे बाद हर computer lock — patient records, billing, lab, prescriptions। Black screen: “8 Bitcoin / 72 hours।”

Director ने पहले police या CERT-In नहीं — finance से Bitcoin cost पूछा (~₹27 लाख) और चार घंटे में authorize कर दिया। ICU patient, काम न करने वाले backups, liability का डर — ransom “सस्ता” लगा।

यह outlier नहीं। Ransomware India में यही shape आम हो गई।

Related: Ransomware day-zero SMB playbook · Phishing email 30 seconds · Data breach notification

Ransomware क्या है — India क्यों target

Industrial extortion in code: files lock (अक्सर copy के बाद), access के लिए money, publish threat real, deadline अक्सर fake — पर panic में पता नहीं चलता।

India ~2018–19 से target: (1) hospitals/banks/plants पर unpatched old systems, (2) crypto routing से payment trace कठिन, (3) demand “believable” band में (₹ tens of lakhs) — “maybe we can pay” वाली fishing zone।

Everything stop होने से पहले

Gurugram manufacturer Anand — CAD files locked, OEM contract ₹2.3 crore/year risk। Ransom ₹18 लाख। Insurance नहीं, bank lend नहीं, police “FIR + wait”। उन्होंने pay किया — numb transfer। Decrypt key तीन दिन लगा; delivery miss; contract गया। चार महीने बाद stolen designs publish threat — दूसरा ₹9 लाख। Pay + फिर भी loss।

Manual behind the malware

  1. Breach — phishing: salary/Aadhaar/VPN “verify”। Junior/accountant/IT click → credentials। देखें: WhatsApp scam · Fake KYC SMS
  2. Reconnaissance — weeks/months: map systems, find backups/admin, read decision-makers’ email।
  3. Deployment — Friday/holiday thin IT; network-wide; backups deliberately hit।
  4. Extortion — decrypt pay या dark web leak। कई businesses data theft बाद में सीखते हैं।

बहुत incidents quietly pay होकर “forgot” रह जाते हैं।

Pay क्यों almost never works

  • Decrypt incomplete / corrupted — paid के बाद partial recovery।
  • Data publish anyway — ~1/3 cases में payment के बाद भी leak।
  • Repeat target list — “paid fast” बेचा जाता है; months में दूसरा group।
  • Legal/finance risk — large opaque payments / misrepresentation investigation risk; money अक्सर recover नहीं।

Day-zero: pay first नहीं — containment: SMB playbook

क्या वास्तव में काम करता है

Pune unit Jan 2024 — ₹22 लाख demand — no। पहले से: air-gapped backup + quarterly restore test + network segmentation + phishing training + immediate report of click। 18 hours restore; criminals unpaid।

Boring prep upfront ही रोकता है।

आज से ये 7 काम

  1. इस हफ्ते backup audit — network-separate? Test restore under 1 hour?
  2. Critical systems list — एक दिन down = business destroy — पहले उन्हें secure करें।
  3. Network segment — accounts hit ≠ production auto-spread।
  4. People train — test phishing; clickers को specific coaching।
  5. Incident response doc — first call, pay decision owner, employee comms, restore guide — print + drawer।
  6. CERT-In report — cert-in.org.in · incident@cert-in.org.in (6-hour mindset)।
  7. Insurance broker — coverage में ransom recovery vs payment requirement clear करें।

Official crime trail: cybercrime.gov.in · 1930 · 1930 FAQ · Report guide

Frequently asked questions

Ransomware India में सबसे आम entry क्या है?

Phishing / credential theft, फिर quiet recon, फिर holiday deploy + backup kill।

Pay करने से files वापस मिलते हैं?

कभी partial; कभी corrupt; कभी leak फिर भी। Payment surrender है, guarantee नहीं।

सबसे पहले किसे call करें?

Containment + counsel/insurance + CERT-In — attackers negotiation पहले नहीं। Day-zero order: SMB playbook।

Backup “hai” काफी है?

नहीं — tested restore + air-gap / offline isolation चाहिए। Untested backup = false comfort।

Official resources

Read next