@FlyingLawyer this is a somewhat common question without a great answer. Ransomware itself rarely exfiltrates - I’m not aware of any that actually does. When you think about it, exfiltration complicates, and likely breaks the commodity ransomware business model. Not to mention that most computers and company networks have much more data that can be easily exfiltrated on some reasonable timeline. That means exfiltration would have to be targeted to certain files/types. However...

also, last month we compromised two separate clients online bank credentials and gained access to them. literally just a straight up password and account number - no "what is the 1st and 3rd character...." - German banks need to step their game up

Hackers are increasingly destroying logs to hide attacks

According to a new report, 72 percent of incident response specialists have came across hacks where attackers have destroyed logs to hide their tracks.

Interesting news read: zdnet.com/article/hackers-are-

Operating one's own local DNS resolution servers is one of the simplest and lowest-cost things an IT administrator can do to monitor and protect applications, services, and users from potential risks.

