Connect with us

Published

on

Anne Neuberger, deputy national security advisor for cyber and emerging technologies, speaks during a news conference in the James S. Brady Press Briefing Room at the White House in Washington, D.C., U.S., on Monday, May 10, 2021 amid the Colonial fuel pipeline ransomware attack.

Bloomberg | Bloomberg | Getty Images

With ransomware attacks surging and 2024 on track to be one of the worst years on record, U.S. officials are seeking ways to counter the threat, in some cases, urging a new approach to ransom payments.

Ann Neuberger, U.S. deputy national security adviser for cyber and emerging technologies, wrote in a recent Financial Times opinion piece, that insurance policies — especially those covering ransomware payment reimbursements — are fueling the very same criminal ecosystems they seek to mitigate. “This is a troubling practice that must end,” she wrote, advocating for stricter cybersecurity requirements as a condition for coverage to discourage ransom payments.

Zeroing in on cyber insurance as a key area for reform comes as the U.S. government scrambles to find ways to disrupt ransomware networks. According to the latest report by the Office of the Director of National Intelligence, by mid-2024 more than 2,300 incidents already had been recorded — nearly half targeting U.S. organizations — suggesting that 2024 could exceed the 4,506 attacks recorded globally in 2023.

Yet even as policymakers scrutinize insurance practices and explore broader measures to disrupt ransomware operations, businesses are still left to grapple with the immediate question when they are under attack: Pay the ransom and potentially incentivize future attacks or refuse and risk further damage.

For many organizations, deciding whether to pay a ransom is a difficult and urgent decision. “In 2024, I attended a briefing by the FBI where they continued to advise against paying a ransom,” said Paul Underwood, vice president of security at IT services company Neovera. “However, after making that statement, they said that they understand that it’s a business decision and that when companies make that decision, it is taking into account many more factors than just ethics and good business practices. Even the FBI understood that businesses need to do whatever it takes to get back to operations,” Underwood said.

The FBI declined to comment.

“There’s no black or white here,” said cybersecurity expert Bryan Hornung, CEO of Xact IT Solutions. “There’s so many things that go into play when it comes to making the decision on whether you’re even going to entertain paying the ransom,” he said.

The urgency to restore operations can push businesses into making decisions they may not be prepared for, as does the fear of increasing damage. “The longer something goes on, the bigger the blast radius,” Hornung said. “I’ve been in rooms with CEOs who swore they’d never pay, only to reverse course when faced with prolonged downtime.”  

In addition to operational downtime, the potential exposure of sensitive data — especially if it involves customers, employees, or partners — creates heightened fear and urgency. Organizations not only face the possibility of immediate reputational damage but also class-action lawsuits from affected individuals, with the cost of litigation and settlements in some cases far outweighing the ransom demand, and driving companies to pay just to contain the fallout.

“There are lawyers out there who know how to put together class-action lawsuits based on what’s on the dark web,” Hornung said. “They have teams that find information that’s been leaked — driver’s licenses, Social Security numbers, health information — and they contact these people and tell them it’s out there. Next thing you know, you’re defending a multimillion-dollar class-action lawsuit.”  

Ransom demands, data leaks, and legal settlements

A notable example is Lehigh Valley Health Network. In 2023, the Pennsylvania-based hospital refused to pay the $5 million ransom to the ALPHV/BlackCat gang, leading to a data leak affecting 134,000 patients on the dark web, including nude photos of about 600 breast cancer patients. The fallout was severe, resulting in a class-action lawsuit, which claimed that “while LVHN is publicly patting itself on the back for standing up to these hackers and refusing to meet their ransom demands, they are consciously and internationally ignoring the real victims.”

LVHN agreed to settle the case for $65 million.

Similarly, background-check giant National Public Data is facing multiple class-action lawsuits, along with more than 20 states levying civil rights violations and possible fines by the Federal Trade Commission, after a hacker posted NPD’s database of 2.7 billion records on the dark web in April. The data included 272 million Social Security numbers, as well as full names, addresses, phone numbers and other personal data of both living and deceased individuals. The hacker group allegedly demanded a ransom to return the stolen data, though it remains unclear whether NPD paid it.

What is clear, though, is that the NPD did not immediately report the incident. Consequently, its slow and incomplete response — especially its failure to provide identity theft protection to victims — resulted in a number of legal issues, leading its parent company, Jerico Pictures, to file for Chapter 11 on Oct. 2.

NPD did not to respond to requests for comment.

Darren Williams, founder of BlackFog, a cybersecurity firm that specializes in ransomware prevention and cyber warfare, is firmly against paying ransoms. In his view, paying encourages more attacks, and once sensitive data has been exfiltrated, “it is gone forever,” he said.

Even when companies choose to pay, there’s no certainty the data will remain secure. UnitedHealth Group experienced this firsthand after its subsidiary, Change Healthcare, was hit by the ALPHV/BlackCat ransom group in April 2023. Despite paying the $22 million ransom to prevent a data leak and quickly restore operations, a second hacker group, RansomHub, angry that ALPHV/BlackCat failed to distribute the ransom to its affiliates, accessed the stolen data and demanded an additional ransom payment from Change Healthcare. While Change Healthcare hasn’t reported if it paid, the fact that the stolen data was eventually leaked on the dark web indicates their demands most likely were not met.

The fear that a ransom payment may fund hostile organizations or even violate sanctions, given the links between many cybercriminals and geopolitical enemies of the U.S., makes the decision even more precarious. For example, according to a Comparitech Ransomware Roundup, when LoanDepot was attacked by the ALPHV/BlackCat group in January, the company refused to pay the $6 million ransom demand, opting instead to pay the projected $12 million to $17 million in recovery costs. The choice was primarily motivated by concerns about funding criminal groups with potential geopolitical ties. The attack affected around 17 million customers, leaving them unable to access their accounts or make payments, and in the end, customers still filed class-action lawsuits against LoanDepot, alleging negligence and breach of contract.

American companies are behind the curve in defending against cyber hacks, says Binary's David Kennedy

Regulatory scrutiny adds another layer of complexity to the decision-making process, according to Richard Caralli, a cybersecurity expert at Axio.

On the one hand, recently implemented SEC reporting requirements, which mandate disclosures about cyber incidents of material importance, as well as ransom payments and recovery efforts, may make companies less likely to pay because they fear legal action, reputational damage, or shareholder backlash. On the other hand, some companies may still opt to pay to prioritize a quick recovery, even if it means facing those consequences later.

“The SEC reporting requirements have certainly had an effect on the way in which organizations address ransomware,” Caralli said. “Being subjected to the consequences of ransomware alone is tricky to navigate with customers, business partners, and other stakeholders, as organizations must expose their weaknesses and lack of preparedness.” 

With the passage of the Cyber Incident Reporting for Critical Infrastructure Act, set to go into effect around October 2025, many non-SEC regulated organizations will soon face similar pressures. Under this ruling, companies in critical infrastructure sectors — which are often small and mid-sized entities — will be obligated to disclose any ransomware payments, further intensifying the challenges of handling these attacks.

Cybercriminals changing nature of data attack

As fast as cyber defenses improve, cybercriminals are even quicker to adapt.

“Training, awareness, defensive techniques, and not paying all contribute to the reduction of attacks. However, it is very likely that more sophisticated hackers will find other ways to disrupt businesses,” Underwood said.

A recent report from cyber extortion specialist Coveware highlights a significant shift in ransomware patterns.

While not an entirely new tactic, hackers are increasingly relying on data exfiltration-only attacks. That means sensitive information is stolen but not encrypted, meaning victims can still access their systems. It’s a response to the fact that companies have improved their backup capabilities and become better prepared to recover from encryption-based ransomware. The ransom is demanded not for recovering encrypted files but to prevent the stolen data from being released publicly or sold on the dark web.

New attacks by lone wolf actors and nascent criminal groups have emerged following the collapse of ALPHV/BlackCat and Lockbit, according to Coveware. These two ransomware gangs were among the most prolific, with LockBit believed to have been responsible for nearly 2,300 attacks and ALPHV/BlackCat over 1,000, 75% of which were in the U.S.

BlackCat executed a planned exit after pilfering the ransom owed to its affiliates in the Change Healthcare attack. Lockbit was taken down after an international law-enforcement operation seized its platforms, hacking tools, cryptocurrency accounts, and source codes. However, even though these operations have been disrupted, ransomware infrastructures are quickly rebuilt and rebranded under new names.

“Ransomware has one of the lowest barriers to entry for any type of crime,” said BlackFog’s Williams. “Other forms of crime carry significant risks, such as jail time and death. Now, with the ability to shop on the dark web and leverage the tools of some of the most successful gangs for a small fee, the risk-to-reward ratio is quite high.”

Making ransom a last resort

One point on which cybersecurity experts universally agree is that prevention is the ultimate solution.

As a benchmark, Hornung recommends businesses allocate between one percent and three percent of their top-line revenue toward cybersecurity, with sectors like health care and financial services, which handle highly sensitive data, at the higher end of this range. “If not, you’re going to be in trouble,” he said. “Until we can get businesses to do the right things to protect, detect, and respond to these events, companies are going to get hacked and we’re going to have to deal with this challenge.”

Additionally, proactive measures such as endpoint detection — a type of “security guard” on your computer that constantly looks for signs of unusual or suspicious activity and alerts you — or response and ransomware rollback, a backup feature that kicks in and will undo damage and get you your files back if a hacker locks you out of your system, can minimize damage when an attack occurs, Underwood said.

A well-developed plan can help ensure that paying the ransom is a last resort, not the first option.

“Organizations tend to panic and have knee-jerk reactions to ransomware intrusions,” Caralli said. To avoid this, he stresses the importance of developing an incident response plan that outlines specific actions to take during a ransomware attack, including countermeasures such as reliable data backups and regular drills to ensure that recovery processes work in real-world scenarios.

Hornung says ransomware attacks — and the pressure to pay — will remain high. “Prevention is always cheaper than the cure,” he said, “but businesses are asleep at the wheel.”

The risk is not limited to large enterprises. “We work with a lot of small- and medium-sized businesses, and I say to them, ‘You’re not too small to be hacked. You’re just too small to be in the news.'”

If no organization paid the ransom, the financial benefit of ransomware attacks would be diminished, Underwood said. But he added that it wouldn’t stop hackers.

“It is probably safe to say that more organizations that do not pay would also cause attackers to stop trying or perhaps try other methods, such as stealing the data, searching for valuable assets, and selling it to interested parties,” he said. “A frustrated hacker may give up, or they will try alternative methods. They are, for the most part, on the offensive.”

Continue Reading

Technology

U.S. greenlights AI chip exports to Gulf tech giants after Saudi Crown Prince’s Washington visit

Published

on

By

U.S. greenlights AI chip exports to Gulf tech giants after Saudi Crown Prince's Washington visit

U.S. President Donald Trump and Crown Prince and Prime Minister Mohammed bin Salman of Saudi Arabia stand for a photo with Tesla CEO Elon Musk, Nvidia CEO Jensen Huang and other participants at the U.S.-Saudi Investment Forum at the Kennedy Center on Nov. 19, 2025 in Washington, DC.

Win McNamee | Getty Images

The U.S. has approved sales of advanced Nvidia chips to Saudi Arabia’s HUMAIN and the United Arab Emirates’ G42, authorizing the state-backed firms to buy up to 35,000 chips, worth an estimated $1 billion.

The approval of these chip exports marks a major reversal for the U.S., which had previously balked at the idea of direct exports to state-backed AI companies in the Gulf. Export controls were put into place to avoid advanced American technology making its way to China through the back door of Gulf Arab states.  

Before former President Joe Biden left office in January, he administered a final round of export restrictions on advanced AI chips, targeting companies like Nvidia, in a sweeping effort to keep that cutting-edge U.S. intellectual property out of China’s reach.

Now, President Donald Trump is moving to expand the reach of such advanced technology in order to “promote continued American AI dominance and global technological leadership,” the U.S. Commerce Department said in a statement published on Wednesday. 

The U.S. Commerce Department approved the chip exports, with the condition the state-backed AI outfits agree to “rigorous security and reporting requirements,” overseen by the Department of Commerce’s Bureau of Industry and Security.

Saudi’s Victory Lap

The export approval follows Saudi Crown Prince Mohammed bin Salman’s trip to Washington this week where the Kingdom pledged to spend $1 trillion in the U.S., up from $600 billion originally committed during Trump’s Gulf tour in May.

“Even if we don’t get to that, both sides have skin in the game,” Afshin Molavi, senior fellow at the Foreign Policy Institute of the Johns Hopkins University School of Advanced International Studies, told CNBC’s Dan Murphy.

Saudi pledges $1 trillion investment as dealmakers head to DC

Saudi Arabia’s AI company HUMAIN, backed by its nearly $1 trillion Public Investment Fund signed a long list of partnerships with Adobe, Qualcomm, AMD, Cisco, GlobalAI, Groq, Luma, and xAI at a U.S.-Saudi Investment Forum held in Washington, D.C this week. Notably, HUMAIN will be teaming up with Elon Musk’s xAI to build a 500 megawatt data center in the Kingdom.

“What we want to do in 2026 is to build the capacity equivalent to what Saudi has built in the last 20 years, in one year,” Tareq Amin, CEO of HUMAIN, said at the summit. HUMAIN is hoping to position Saudi Arabia as the third biggest global AI hub, after the likes of the U.S. and China.

Winning over the U.S. Commerce Department

Continue Reading

Technology

Nvidia earnings takeaways: Bubble talk, ‘half a trillion’ forecast and China orders

Published

on

By

Nvidia earnings takeaways: Bubble talk, 'half a trillion' forecast and China orders

Nvidia Q3 earnings: Here are the key takeaways

Nvidia on Wednesday reported fiscal third-quarter earnings that beat expectations, and provided a strong forecast for the current quarter.

Wall Street welcomed the report, and Nvidia stock rose after the release and during the conference call. Other stocks in the so-called artificial intelligence trade also saw a boost.

A closer look at Nvidia’s report shows that it continues to dominate the market for AI chips called GPUs, and CEO Jensen Huang sounded confident in the company’s products and bullish on the company’s outlook during a call with analysts.

Nvidia said it expects about $65 billion in sales in the current quarter, which ends in late January. That would be 65% growth on an annual basis.

Here are three key takeaways from Nvidia’s earnings:

Nvidia rejects bubble talk

On Wednesday’s earnings call with analysts, Huang began his comments by rejecting the premise of an “AI bubble” held by some investors who are concerned about the billions of dollars being spent on Nvidia chips and potential return on investment.

“There’s been a lot of talk about an AI bubble,” Huang said. “From our vantage point, we see something very different.”

Huang said there were three different kinds of uses for AI that are currently growing, and that all three are contributing to the boom in infrastructure investments.

He said that non-AI software, like for data processing, was increasingly being run on the company’s GPUs, that AI will create new kinds of apps, and that “agentic AI” which doesn’t need user input, will require additional computing power.

Huang said that people will soon start appreciating what’s happening underneath the surface of the AI boom, versus “the simplistic view of what’s happening to CapEx and investment.”

Bernstein analysts said in a note that Huang’s comments helped settle investor fears of a bubble after a recent pullback in AI names, saying “perhaps the AI trade is not yet dead after all.”

“More than just good numbers, we believe investors needed some hand-holding from Jensen which he provided in spades,” the analysts wrote.

‘Half a trillion’ forecast is on track

Last month, Huang said at a conference in Washington, DC, that his company had orders for $500 billion in AI chips in 2025 and 2026.

On Wednesday, the company said that the forecast was still on track. Any long-term outlook from Nvidia is important to the technology industry because Nvidia counts many of the most powerful technology customers as customers.

Nvidia said on Wednesday that its order backlog didn’t even include a few recent announcements, like the company’s deal with Anthropic or the expansion of a deal with Saudi Arabia this week.

“The number will grow,” CFO Colette Kress said on the call, saying the company was on track to hit the forecast. “We’ll probably be taking more orders.”

“We see the opportunity to grow for quite some time,” Huang said.

Several analyst notes on Thursday drew attention to the $500 billion forecast and the addition of the recently announced deals.

Jefferies said Nvidia “answered the bell” in its earnings report and said the numbers should help steady the AI trade into the end of the year.

“We don’t expect every AI bear to be satisfied, but these results and added context from management around demand outlook should offer some near-term reprieve,” the analysts wrote.

“Insignificant” China orders

Nvidia fought over the summer to gain licenses to export its H20 chip, a slowed-down version of 2022 technology, to China. Some analysts projected the China business could be worth $50 billion per year to Nvidia.

The company eventually got the licenses this summer after Huang personally met with President Donald Trump and struck a deal to give the U.S. government 15% of China sales.

But it turns out that the sales of H20 chips during the quarter was “insignificant.” Kress told analysts that the company recorded $50 million in H20 sales during the period.

“Sizable purchase orders never materialized in the quarter due to geopolitical issues and the increasingly competitive market in China,” Kress said.

Nvidia has argued that the U.S. government should allow exports of the most advanced chips because it’s better for national security if Chinese developers get used to Nvidia technology, rather than being forced to use Chinese chips and make them better.

The H20 is old technology, but Nvidia wants to gain approval to send a version of its current-generation Blackwell chip in China.

“While we were disappointed in the current state that prevents us from shipping more competitive data center compute products to China, we are committed to continued engagement with the US and China governments and will continue to advocate for America’s ability to compete around the world,” Kress said.

Analysts at Melius said Thursday that the lack of China sales made the numbers “all the more extraordinary” and projected Nvidia would generate nearly $400 billion in free cash flow over the next nine quarters.

“Currently Nvidia isn’t delivering to China and we are not counting on this situation to get straightened out,” the firm said.

Read more CNBC tech news

CNBC’s Sam Subin contributed to this story.

Continue Reading

Technology

Waymo to begin manual drives in Minneapolis, Tampa and New Orleans, aims to open service in 2026

Published

on

By

Waymo to begin manual drives in Minneapolis, Tampa and New Orleans, aims to open service in 2026

Waymo driverless vehicles charge at a Waymo charging station in Santa Monica, California, U.S., May 30, 2025.

Daniel Cole | Reuters

Alphabet’s Waymo on Thursday announced that it will soon begin manually driving its robotaxi vehicles in Minneapolis, Tampa and New Orleans.

The Google sister company will start operating test drives in that trio of towns with human drivers in hopes of launching its driverless robotaxi service there as soon as next year, the company said.

If Waymo does begin operating in those markets next year, that would bring the robotaxi company’s list of 2026 planned expansions to 15 cities.

On Tuesday, Waymo said it plans to start operating its vehicles with no human driver in Dallas, Houston, San Antonio, Miami and Orlando in the coming weeks, with plans to open service to the public there next year. The company has also previously announced plans to expand to Detroit, Denver, Las Vegas, Nashville, San Diego, Washington, D.C., and London in 2026.

A spokesperson said Waymo will wait until its technology is validated in Minneapolis, Tampa and New Orleans before committing to 2026 service launches.

“2026 is very much on the table, but we’ll be led by our safety framework,” Waymo spokesperson Ethan Teicher said in an email. 

With more than 250,000 weekly paid trips, Waymo’s robotaxi service currently operates in Austin, the San Francisco Bay Area, Phoenix, Atlanta and Los Angeles markets. The company has provided more than 10 million paid rides since launching in 2020.

Last week, Waymo began offering freeway routes in the San Francisco, Phoenix and Los Angeles markets. The company said it will gradually extend freeway trips to more riders and locations over time.

The addition of freeway rides marked an important milestone for Waymo and the robotaxi industry due to the challenges conditions of operating at such high speeds. Next year, Waymo will set its sights on achieving another key milestone: operating in markets known for harsh winter conditions.

Along with Denver and Detroit, the addition of Minneapolis means Waymo believes its nearly ready to begin serving riders in regions where its driverless vehicles would need to be ready to brave snow and frigid forecasts.

“We currently operate at freezing temperatures, including with frost and hail, and we’re validating our system to navigate harsher weather conditions,” Teicher said. “We’ll have small fleets to start that we expand over time.”

This week, Amazon-owned Zoox began allowing select San Francisco users to hail its driverless vehicles. San Francisco is the second market where Zoox now offers a free service, after its launch in Las Vegas in September. The company plans to remove its rider waitlist for San Francisco entirely in 2026.

WATCH: Waymo launches paid robotaxi rides on freeways

Watch: Waymo launches paid robotaxi rides on freeways

Continue Reading

Trending