As someone who works in the defense industry, I can assure you that 45 GB of unencrypted emails is next to worthless from a commercial standpoint and a total non-event from a national security standpoint. This is probably more of a threat to individual employees than it is to anybody else.
To put it another way, if this data had value, the ransomware group wouldn't be leaking it for free.
> To put it another way, if this data had value, the ransomware group wouldn't be leaking it for free.
This is entirely incorrect and just speculation.
Most likely reason for not paying up is that law enforcement (involved in this case as well) does not like it and have even been considering a ban on ransom payments. This in no way implies this data has no value, it is very probable this data contains credentials (Citrix appliances) and might allow future compromises unless Boeing improves their security posture.
The formulation (3rd conditional) makes it clear the author is aware they're speculating.
> This [the dump is worthless] is entirely incorrect
Which isn't telling us why (the dump is valuable). You say that there's a legal ban on ransom, so the ban supposedly reduces market value. Black market participants evade bans, there is a black market value which clearly is the prime market for such loot. You write "it is very probable this data contains credentials" which is plausible, but the article you linked mentions logs and configs, not credentials. Maybe (before you point it out: that is also speculation) there were no credentials in the first place (dump was of low-value), or the hackers filtered them out for later use (seller filleted the fish), either way the resulting merchandise is of low value.
but, could you just imagine having to filter through 45 GB of emails! to try to find any value in that at all, might be expensive, even if you try to automate it.
firms this size may have plugins to mark the mails before sending them out. E.g. internal, external, sensitive labels and what not. Could make it easier to traverse.
>As someone who works in the defense industry, I can assure you...
Defence industry is broad, though, perhaps you needed to be for security reasons. However, stating your job then saying individual people don't matter but commercial entities do may make you unfit for certain defence careers.
Well, they could be in the "all are equal, some are more equal" camp. Lives have value, but some have more value... especially "ours".
Realistically, most people aren't going to spare more than an internet comment or a weekend protest for some atrocity going on across the world, anyway. The world teaches us to compartmentalize evil in order to go on living...
A few years ago I had to clean up my work account because I hit a 50 Gb capacity. Today I have 20 Gb used again. And I'm a single low level (in the hierarchy) engineer. Emails from different automated systems and confluence produce gigantic amount of not-quite-spam (because it is sometimes very useful).
If they had 500 Tb of emails, maybe it was a concern, but 45 Gb looks like a single account breach. Maybe some interesting confidential emails sent company wide, or department wide, but probably hardly anything worth it. That's why I think Boeing didn't pay and was right to do so.
I wouldn't be so sure. It's like criminals who steal passwords. Sometimes they just want to bulk sell the passwords at a lower value rather than delving into the accounts for higher gain. Sometimes they just want rid.
In this case, I wouldn't be surprised if the group want to make it clear that they're serious for other high-value targets
To put it another way, if this data had value, the ransomware group wouldn't be leaking it for free.