{"id":19638,"date":"2022-07-20T06:30:07","date_gmt":"2022-07-20T14:30:07","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/07\/20\/news-13371\/"},"modified":"2022-07-20T06:30:07","modified_gmt":"2022-07-20T14:30:07","slug":"news-13371","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/07\/20\/news-13371\/","title":{"rendered":"Will new EU crypto rules change how ransomware is played?"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2019\/10\/cw_bitcoin_symbol_atop_stacked_bitcoins_with_abstract_financial_chart_by_microstockhub_gettyimages-1043663584_2400x1600-100813837-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Evan Schuman| Date: Wed, 20 Jul 2022 05:55:00 -0700<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">Cryptocurrency has always been the payment method of choice for bad guys. Get hit with an enterprise ransomware attack and plan to pay? You\u2019ll need crypto. The key reason cyberthieves love cryptocurrency so much is that it is far harder to trace payments.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That is why a move being attempted by the European Union has so much potential. The EU \u2014 in a move that will likely be mimicked by many other regional regulatory forces, including in the United States \u2014 is putting in place tracking requirements for all cryptocurrency.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I<\/span><span style=\"font-weight: 400;\">f it is successful, and the EU has an excellent track record on precisely these kinds of changes, cryptocurrency may quickly fade as the thief\u2019s payment of choice. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">What does that mean for enterprise IT and security? It&#8217;s entirely plausible that the ransomware fights you\u2019ll have in 2023 and 2024 may not necessarily require crypto. The bad guys might come up with ways to more safely use Visa, wire tranfers or ACH payments. (Do you know how much easier paying ransom becomes if you can charge a PayPal account or use Zelle or Venmo?)<\/span><\/p>\n<p><span style=\"font-weight: 400;\">One big slice of the nightmare of paying ransomware is the difficulty in quickly obtaining a large amount of cryptocurrency. The enterprise can\u2019t hold it for the future, given how extremely volatile its value is. You think you are tucking away $5 million worth of crypto, only to discover that it\u2019s worth $42,000 when you try and use it.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">So what exactly has the EU done? The Council of the European Union said the bloc has reached a \u201cprovisional agreement\u201d on a new landmark regulatory framework for cryptocurrencies. The agreement\u2019s text is not final, so it\u2019s not clear what will ultimately be included. An EU official told <\/span><span style=\"font-weight: 400;\">me<\/span><span style=\"font-weight: 400;\">\u00a0\u201cthe text will be ready in time for the confirmation of the provisional agreement by ambassadors of EU member states at one of the Coreper meetings, not before September.\u201d\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cNot before September\u201d? As deadlines go, that&#8217;s relatively meaningless. But given that it&#8217;s been announced, the change seems more likely than not to happen.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">From the EU statement: \u201cThe aim of this recast is to introduce an obligation for crypto asset service providers to collect and make accessible certain information about the originator and the beneficiary of the transfers of crypto assets they operate. This is what payment service providers currently do for wire transfers. This will ensure traceability of crypto-asset transfers in order to be able to better identify possible suspicious transactions and block them.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The statement also promised \u201c<\/span><span style=\"font-weight: 400;\">the new agreement requires that the full set of originator information travel with the crypto-asset transfer, regardless of the amount of crypto assets being transacted. There will be specific requirements for crypto-asset transfers between crypto-asset service providers and un-hosted wallets.<\/span><span style=\"font-weight: 400;\">\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">By the way, the EU in this document also listed \u201cnon-cooperative jurisdictions for tax purposes,\u201d which include\u00a0<\/span><span style=\"font-weight: 400;\">American Samoa, Fiji Guam, Palau, Panama, Samoa, Trinidad, Tobago, the U.S. Virgin Islands, and Vanuatu.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Another interesting detail is what the EU promised consumers, though it is less clear how well anyone can deliver when it comes to consumer protections. The new agreement \u201c<\/span><span style=\"font-weight: 400;\">will protect consumers against some of the risks associated with the investment in crypto-assets, and help them avoid fraudulent schemes. Currently, consumers have very limited rights to protection or redress, especially if the transactions take place outside the EU. With the new rules, crypto-asset service providers will have to respect strong requirements to protect consumers wallets and become liable in case they lose investors\u2019 crypto-assets. (The agreement) will also cover any type of market abuse related to any type of transaction or service, notably for market manipulation and insider dealing.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Those are fine goals, but let\u2019s not forget that they are imposing rules on criminals who pretty much earn their living by ignoring laws and other restrictions. The penalties for these violations is unlikely to be more of a deterrent than getting caught and charged with extortion, theft, fraud, and perhaps espionage. Against that backdrop, some EU penalties don\u2019t deliver much of a fear factor.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That all said, cryptocurrency exchanges are, sort of, mostly legal operations. If new rules can make those operations less hospitable to the thieves, that\u2019s good. WIll it be enough to push them into the arms of PayPal and their counterparts? That will be very interesting to watch.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3667281\/will-new-eu-crypto-rules-change-how-ransomware-is-played.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2019\/10\/cw_bitcoin_symbol_atop_stacked_bitcoins_with_abstract_financial_chart_by_microstockhub_gettyimages-1043663584_2400x1600-100813837-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Evan Schuman| Date: Wed, 20 Jul 2022 05:55:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p><span style=\"font-weight: 400;\">Cryptocurrency has always been the payment method of choice for bad guys. Get hit with an enterprise ransomware attack and plan to pay? You\u2019ll need crypto. The key reason cyberthieves love cryptocurrency so much is that it is far harder to trace payments.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That is why a move being attempted by the European Union has so much potential. The EU \u2014 in a move that will likely be mimicked by many other regional regulatory forces, including in the United States \u2014 is putting in place tracking requirements for all cryptocurrency.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">I<\/span><span style=\"font-weight: 400;\">f it is successful, and the EU has an excellent track record on precisely these kinds of changes, cryptocurrency may quickly fade as the thief\u2019s payment of choice. <\/span><\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3667281\/will-new-eu-crypto-rules-change-how-ransomware-is-played.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[21359,17965,714,12747],"class_list":["post-19638","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-financial-services-industry","tag-mobile-payment","tag-security","tag-technology-industry"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19638","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19638"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19638\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19638"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19638"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19638"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}