Skip to content

The Birth of a Ransomware Urban Myth

April 17, 2017Data & Research3 min read


Collage of headlines and graphics repeating the claim that about 40 percent of ransomware victims pay, with an "urban myth" book cover in the middle

Would you be surprised to find that “nearly 40% of ransomware victims pay attackers,” according to a recent article published by DarkReading? I sure was. The number of victims that pay ransomware and the amount paid has been an elusive figure for years now. To date, law enforcement has not collected and published ransomware crime statistics like they have for other forms of criminal activity.

Junk research published by security vendors has always irked me because they use and misuse statistics to spread fear and sell products. Security threats are overblown and solutions are oversimplified, leading to a bevy of problems ranging from the creation of information security urban myths to poor corporate decision making based on faulty assumptions.

Sadly, the DarkReading article and underlying research is no exception. It’s a prime example of what’s wrong with vendor-sponsored research and how the rest of us pick up quotes, circulate and re-tweet without giving it a minute of critical thought. It’s easy to spot — just grab a statistic and follow it down the rabbit hole. Let’s dissect the ransomware payment rate and find out what’s really going on.

DarkReading published this article on April 14th, 2017 with the headline:

Dark Reading headline: "Nearly 40% of Ransomware Victims Pay Attackers," with the subhead "Ransomware is targeting more consumers, and many of them are paying hundreds to attackers."
Source: http://www.darkreading.com/attacks-breaches/nearly-40--of-ransomware-victims-pay-attackers/d/d-id/1328634

If you follow the article to the end, a link to the research is cited, along with the name of the security vendor that performed the research (Trustlook). They have a nice blog post and a cute, entertaining infographic — great reading material to send to the CISO tomorrow morning. The next step is to check the validly of the research and see exactly what Trustlook is claiming.

  • Trustlook is a security vendor and sells a suite of products that protects end-users from malware, including ransomware, and other forms of attack.
  • The research is based on a survey. Surveys are polls; you ask a group of people a question and record the answers.
  • Trustlook surveyed 210 of their Mobile Security product customers. Mobile Security is an Android-based anti-virus app.
  • Trustlook did not disclose a margin of error, which would indicate the survey is not statistically significant. This means the results only apply to the survey takers themselves and cannot be extrapolated to apply to a larger group or the general population.

This would be enough to make anyone that took a semester of college Stats roll their eyes and move on. However, the assertions in the infographic really take the cake. When percentages are used in statistics, the reader tends to forget or lose sight of the underlying numbers. Breaking down the percentages further:

  • We know 210 customers were surveyed (Trustlook disclosed this).
  • Of the 210, 45% have never heard of ransomware. Put another way, 94 out of 210 customers answered a survey about ransomware, but have never heard of ransomware. Trustlook conducted research and published a survey on ransomware in which nearly half of the respondents don’t know what ransomware is.
Reaction GIF from Star Wars of a woman in white with her hair in side buns, staring skeptically
  • 116 respondents had the wherewithal to understand the subject matter for a survey they are filling out.
  • Of the 116, 20 people had, at some point, been infected with ransomware.
  • Of the 20 that have been infected, 8 of them paid the ransom.

Let me say that again in case you missed it.

Trustlook found 8 of their customers that said they paid a ransom and turned it into this:

Trustlook graphic: "38% paid ransom," labeled "Percent of affected consumers that paid the ransom"
Source: https://newblogtrustlook.files.wordpress.com/2017/04/2017-trustlook-ransomware-survey.png

…and DarkReading expanded the claim to include all ransomware victims:

Dark Reading headline: "Nearly 40% of Ransomware Victims Pay Attackers"
Source: http://www.darkreading.com/attacks-breaches/nearly-40--of-ransomware-victims-pay-attackers/d/d-id/1328634

Two days later, it’s everywhere:

Google search for "Nearly 40% of Ransomware Victims Pay Attackers" returning about 7,720 results, with an arrow pointing to the count
Source: Google.com search

A new ransomware urban myth is born.

More on Data & Research

Leave a Reply

Heatmaps to Histograms: Field Notes

It’s a free newsletter for risk and security professionals, and each issue brings a practical CRQ technique, a case study from the field, and a tool or prompt you can use the same day.

Your welcome email includes Chapter 5 of the book, Your First Quantitative Risk Assessment, where you build a Monte Carlo simulation in Excel and run a complete risk analysis, free.

Delivered by Substack. No spam, and you can leave with one click.

Discover more from Tony Martin-Vegue

Subscribe now to keep reading and get access to the full archive.

Continue reading