back to article MIT Sloan quietly shelves AI ransomware study after researcher calls BS

Do 80 percent of ransomware attacks really come from AI? MIT Sloan has now withdrawn a working paper that made that eyebrow-raising claim after criticism from security researcher Kevin Beaumont. The withdrawn paper [PDF], co-authored by researchers from MIT Sloan and Safe Security, claimed, "Our recent analysis of over 2800 …

  1. Anonymous Coward
    Anonymous Coward

    They probably used AI to write it!

    1. Claptrap314 Silver badge

      Probably? Probably?

  2. vogon00

    2/10, Must try harder

    Had a quick read of it and came to the conclusion that I am not competent to comment seriously.

    Others are though. Based on their assessments, I have to say I expected better from MIT. Having said that, MIT Sloan is a school of business/leadership...what on earth made them think they were competent to comment on or research the technical subject of hacking with AI when most of the ROW can't make sense of it. Just re-spinning the hype to suit their own agenda.

    MIT Engineering qualifications still appear trustable, the business school qualifications less so -)

    1. elDog Silver badge

      Re: 2/10, Must try harder

      I wouldn't single out poor MIT Sloan for having their business school failures. After all, many graduates of these types of schools are either failures or contribute to the same in the corporate world.

      1. Pascal Monett Silver badge
        Trollface

        Some of them are even in Government these days.

      2. Gene Cash Silver badge

        Re: 2/10, Must try harder

        Heck, over here at UCF, we had a school of engineering whose building was sinking into the ground and cracking in two, and a school of business that went broke.

        No, I don't mention my degree, why do you ask?

    2. Anonymous Coward
      Anonymous Coward

      Re: 2/10, Must try harder

      It would have been better if your dog had eaten your assignment rather having written it.

      2 marks for your dog - keep this up he will graduate before you.

  3. Bill Gray Silver badge

    "...In 2024, 80.83 percent of recorded ransomware events were attributed to threat actors utilizing AI."

    Coincidentally, 80.83% of all statistics are made up and have no factual basis. The rate may be higher among statistics given with meaningless precision.

    1. Doctor Syntax Silver badge

      Too many (in)significant figures in a statistic is always a strong warning signal.

      1. Bill Gray Silver badge

        I'll occasionally see instances where (say) an asteroid has been estimated to be roughly 200 km in diameter, and a press release will duly divide by 1.609344 and tell us that, according to the Institute for Advanced Meaningless Precision, the asteroid is 124.2745 miles across. When I see a precise figure given in non-metric units, I'll often convert to metric and be amused to see how close it comes to a "round" number.

    2. WolfFan Silver badge

      98.92467% of MS Windows 11 users want to visit Redmond, Washington. By air. Using a Tu-95 and with a copy of the Tsar Bomba, only at full power. https://en.wikipedia.org/wiki/Tsar_Bomba

  4. HuBo Silver badge
    Pint

    Refreshing

    I love Beaumont and Hutchins' takes on this, which I'd summarize as: it's absurd jaw droppingly bad corporate marketing bozos cyberslop nonsense ... just rolls off the tongue!

    Great to see outlandish AI claims being taken down a notch this way.

  5. Pascal Monett Silver badge
    FAIL

    Brilliant career move, there

    MIT authors Michael Siegel, Sander Zeijlemaker, alongside Safe Security's Vidit Baxi and Sharavanan Raajah.

    These people have just completely trashed their professional reputation. They will forever be remembered for publishing a piece of AI-written filth.

    They're going to have to work very hard to regain a veneer of competence in the industry.

    Serves them right.

    1. Graham Cobb

      Re: Brilliant career move, there

      Actually, the corporate guys (Baxi and Raajah) have done little harm to their reputation, and probably increased their value to their employers (and future employers). It is a few years now since I did corporate technical marketing but companies are always looking for ways to get external validation of the benefits of their product. Even if you do have a great product it is has hard to let the world know; and if you don't you still need to highlight what it can do. This support from MIT Sloan authors was quite a feather in their cap!

      Respected institutions (including various publications, universities, research groups, analysts, etc) are always underfunded and are looking for corporate sponsorships or sponsored gigs (speaking at conferences, tradeshows, user group meetings, etc). Their views often carry a lot of weight with customers so they can charge a lot of money for endorsing suppliers. Of course, they don't normally go as far as saying one supplier is better than another but they are often willing to endorse or promote a particular talking point which highlights something which happens to be a competitive strength of one supplier.

      But it is a very difficult tightrope to walk. Even while avoiding direct endorsement of a product, they have to be careful not to just endorse the marketing talking points of the supplier. I had many difficult calls and negotiations with various experts we were sponsoring in various ways in order to arrive at words they would use which supported our talking points and strengths, without endorsing or recommending our products. Some of them were very good at getting to a reasonable and fair compromise protecting their position, reputation and institution while saying enough to support our claims that we would pay them (and come back again for another article or speaking gig). I understood their position and they understood mine, and we negotiated like adults.

      I suspect that Siegel and Zeijlemaker have had a roasting from MIT and will be much more careful next time.

  6. BartyFartsLast Silver badge

    Even AIs don't agree?

    To paraphrase Christine Keeler, well it would say that wouldn't it

    1. Bebu sa Ware Silver badge
      Happy

      Re: Even AIs don't agree?

      "To paraphrase Christine Keeler, well it would say that wouldn't it"

      Mandy Rice-Davies surely ?

      Christine is the one sitting astride a chair in her birthday suit. (unfortunately there isn't a cold shower icon.)

  7. Bebu sa Ware Silver badge
    Black Helicopters

    "When 80% of Ransomware Attacks are AI-Driven"

    Without fear of contradiction I would say 100% of Ransomware Attacks are money driven — your money at that.

    I imagine a fair number of papers in this area are similarly driven.

    "The incentives are… not well managed here, and the industry is very sick,"

    One might say that of the nation as a whole — "the unrelenting drift into grift."

  8. Eric 9001

    It's not clear as to what use LLM's would have for writing ransomware.

    It's really not that hard - all that is needed;

    * id+encryption key generation.

    * Sending that data to a remote server.

    * Encryption of user files + deletion of originals.

    * Popping up the ransom message with instructions how to pay and receive the decryptor (or writing the ransom message to a file on the desktop) and of course the attacker can also just take payment and not supply decryption.

    * Or if the encryption and payment checking is too hard, add an .encrypted extension to every file (windows will make the files mostly unusable and also makes it hard to remove the extension) and make the program remove the extension when the "payment has been made (non-payment will result in deletion of all files)" button is pressed.

    All of that is mostly a copy-paste job from stackoverflow.

    A LLM could be used to write the email demanding that the "pdf.exe" file is viewed immediately and the ransom message, but it's really easier to just type the 1 or 2 needed sentences and copy-paste the cryptocurrency address (using a LLM even risks the cryptocurrency address being modified to the wrong one).

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon