Scottish Daily Mail

UNITED FACE £15m FINE IF THEY PAY HACK­ERS

- By CHRIS WHEELER Crime · Hacking · Public Domain · Information Security · Tech · Copyright · Law · Manchester · United Kingdom · New York · Government of the United Kingdom · Cybercrime · Fine · New York Stock Exchange · U.S. Treasury · Office of Foreign Assets Control

MANCH­ESTER UNITED face a fine of up to £15mil­lion if they give in to the de­mands of cy­ber hack­ers hold­ing the club to ran­som. The ‘dou­ble-whammy’ threat emerged yes­ter­day as United con­tin­ued to fight the at­tack that has crip­pled the club’s sys­tems for more than a week, as re­vealed by Sports­mail. United are al­ready faced with a ran­som de­mand be­lieved to run into mil­lions of pounds — or risk highly-sen­si­tive informatio­n be­ing leaked into the pub­lic do­main. How­ever, if they pay the hack­ers to call off the at­tack, United could fall foul of new US leg­is­la­tion pun­ish­able by a fine of up to £15m. Although United are a UK-based com­pany, the Glazer-owned club are listed on the New York Stock Ex­change and sub­ject to US law. Their share price dropped yes­ter­day. The US Trea­sury De­part­ment an­nounced last month that any or­gan­i­sa­tions meet­ing the ran­som de­mands of hack­ers who ap­pear on their global hit list risk in­cur­ring a fi­nan­cial penalty — even if the vic­tims are not aware of the crim­i­nals’ iden­tity. The US Of­fice of For­eign As­sets Con­trol warned that pay­ing the ran­som would only boost the crim­i­nals’ fi­nances and en­cour­age them to strike again else­where. The OFAC state­ment read: ‘Com­pa­nies that fa­cil­i­tate ran­somware pay­ments to cy­ber ac­tors on be­half of vic­tims, in­clud­ing fi­nan­cial in­sti­tu­tions, cy­ber in­surance firms, and com­pa­nies in­volved in dig­i­tal foren­sics and in­ci­dent re­sponse, not only en­cour­age fu­ture ran­somware pay­ment de­mands but also may risk vi­o­lat­ing OFAC regulation­s. ‘Fa­cil­i­tat­ing a ran­somware pay­ment that is de­manded as a re­sult of cy­ber ac­tiv­i­ties may en­able crim­i­nals and ad­ver­saries with a sanc­tions nexus to profit and ad­vance their il­licit aims. Pay­ments may also em­bolden cy­ber ac­tors to en­gage in fu­ture at­tacks.’ The threat of a US fine for United is in ad­di­tion to the threat of a penalty of up to £18m from the in­de­pen­dent UK Gov­ern­ment body, Informatio­n Com­mis­sioner’s Of­fice, if the data pro­tec­tion of their huge fan­base has been breached — although the club are not aware that it has.

Newspapers in English

Newspapers from UK