Dear miscreants (not actually directed at Salesforce this time):
Please send the files to the New York Times and Der SPiegel. They need more awards for exposing corruption.
Salesforce won't pay a ransom demand to criminals who claim to have stolen nearly 1 billion customer records and are threatening to leak the data if the CRM giant doesn't pony up some cash. "Salesforce will not engage, negotiate with, or pay any extortion demand," Allen Tsai, a Salesforce spokesperson, told The Register. It …
There are two things that are indispensable to stop ransomware.
One is to harden your systems and up security. That costs money and implies expertise and employee education - none of which are simple. One would think that, after 3 decades now of businesse integrating IT, it would be a given, but here we are.
The second is to never, ever give the scumbags a single dime. They want money, they're not going to waste their time if it is clear that no money will be forthcoming.
Now, the only thing left is to hope that Salesforce will be true to its word and not do like the US Government, who always said loud and clear that they "do not negociate with terrorists" and yet have been caught red-handed doing just that.
Both those methods are good, but they are scattershot -- you have to target each individual organisation with those two mitigations and ask/hope/pray they will do the right thing.
What I would like to see is more done to track cryptocurrency. May be more scalable to start aggressively going after CC exchanges.
But we live in a world where expressing opinions is more dangerous than actually stealing money :-(