BlackCat ransomware group implodes after apparent payment by Change Healthcare

A major ransomware attack on U.S. healthcare processor Change Healthcare, reportedly involving a $22M payment to the BlackCat gang, has reignited debate over whether organizations should ever pay digital extortion demands. Commenters weigh the trade-offs between immediate business and patient safety needs and the long-term societal harm of funding and incentivizing cybercrime, including calls to outlaw ransom payments or even certain cryptocurrencies. The thread also delves into why robust security, backups, and encryption are far from simple in large organizations, and how misaligned incentives and cost pressures leave critical infrastructure chronically vulnerable.

Legality and Ethics of Paying Ransoms

  • Many argue ransom payments should be illegal; some compare it to “not negotiating with terrorists.”
  • Counterpoint: bans may push payments underground via shady “data recovery” firms and reduce reporting, as seen in historical kidnapping cases.
  • Some see limited exceptions (e.g., law-enforcement‑controlled payments) or cases where immediate harm (e.g., interruption of medical care) justifies payment.
  • Debate over whether paying constitutes participation in organized crime and whether it should be prosecuted (e.g., via RICO).

Incentives, Risk, and Security Investment

  • Paying ransoms is seen as reducing incentives to invest heavily in security; if you can pay $22M once, why spend that on prevention?
  • Others note all organizations operate under risk tolerance and finite budgets; perfect security is impossible, even for well‑resourced entities.
  • Some emphasize that as long as ransom is an option, many companies will underinvest and treat security as a cost center.

Backups, Data Exfiltration, and Technical Defenses

  • Simple “offsite backups” are deemed inadequate: attackers often delete or encrypt backups, or compromise backup infrastructure.
  • Distinction between “data loss” (recoverable via backup) and “data leakage” (stolen data used for double extortion). Backups don’t fix leakage.
  • Encryption at rest and in transit helps but can’t fully prevent theft, since data must be decrypted somewhere; attackers often target those points.
  • Discussion of field‑level encryption and “translucent databases,” but consensus that most organizations don’t implement such rigor.
  • Effective defense requires layered controls, immutable backups, tested recovery, MFA/SSO, least privilege, and dedicated security leadership.

Ransomware Ecosystem, Reputation, and Exit Scams

  • Historically, many groups honored deals to maintain a reputation and keep the “business model” working.
  • BlackCat’s apparent rug‑pull against its affiliates is seen as a breakdown of that reputation logic and an example of “no honor among thieves.”
  • Some apply game theory: when payouts reach “life‑changing” levels, actors may treat attacks as one‑shot games and defect (exit scams).

Cryptocurrency and Policy Ideas

  • Some propose banning crypto (or at least Bitcoin–fiat exchange) to choke off ransomware economics; others value crypto as money outside state control.
  • Note that many sophisticated groups now prefer Monero over Bitcoin for privacy.
  • More radical suggestions include legal bounties or “hacking back,” but concerns are raised about attribution, false flags, and escalation.