Ransomware: From 20,000 Mailed Floppy Disks to a Billion-Dollar Racket

The first ransomware attack arrived by post. In 1989 a biologist named Joseph Popp mailed around 20,000 floppy disks labeled as AIDS information to attendees of a World Health Organization conference. On the 90th boot, the hidden program locked the machine and demanded a $189 cashier’s check sent to a P.O. box in Panama for the fictitious PC Cyborg Corporation. Popp never stood trial. He was declared mentally unfit, and at one point wore cardboard boxes on his head.

This episode tracks how that crude stunt became an industry. In 1996, researchers Adam L. Young and Moti Yung described cryptoviral extortion, a hybrid encryption scheme inspired by the facehugger in Alien. Criminals then spent years looking for a safe way to get paid, moving from premium text messages to fake police warnings to prepaid vouchers, until CryptoLocker paired strong encryption with Bitcoin in 2013. What followed was ransomware as a service, WannaCry, Colonial Pipeline, and data theft that makes backups alone useless.

  • Hybrid encryption locks files with a fast symmetric key, then seals that key with the attacker’s public key. The private key never touches the victim’s computer.
  • The Reveton police trojan displayed the FBI seal or the Metropolitan Police logo, accused victims of crimes, and sometimes switched on the webcam to show their own face.
  • WannaCry spread in 2017 using EternalBlue, an NSA exploit leaked by the Shadow Brokers. It hit over 230,000 computers in 150 countries and disrupted the UK’s National Health Service.
  • A 2019 ProPublica investigation found data recovery firms that claimed proprietary technology but were secretly paying the hackers and adding a markup.
  • In May 2024, Tokyo police arrested 25-year-old Ryuki Hayashi, who had no deep technical background and used generative AI to write ransomware.

Leave a Reply

Discover more from pplpod

Subscribe now to keep reading and get access to the full archive.

Continue reading