Global fight against ransomware: collaboration is the key to resilience

Diplo is actively reporting from the 2024 Internet Governance Forum (IGF) in Riyadh, while the forum’s day one is still, and another essential panel of international experts shed light on the relentless rise of ransomware attacks and the global efforts to counter this growing cyber threat. Moderated by Jennifer Bachus of the US State Department, the session featured cybersecurity leaders Elizabeth Vish, Daniel Onyanyai, and Nils Steinhoff, who highlighted the scale of the crisis and the collaborative response through the Counter Ransomware Initiative (CRI).

Ransomware, described as ‘cybercrime as a service,’ has evolved from simple data encryption to complex extortion schemes targeting critical infrastructure worldwide. ‘Emerging markets are now increasingly in the crosshairs,’ noted Elizabeth Vish, pointing to growing vulnerabilities in developing economies that lack robust cybersecurity resources. With over $1.1 billion in crypto payments extracted by attackers in 2023 alone, ransomware continues to prove profitable, its impacts often crippling public services like hospitals and government institutions.

Established in 2021, the CRI is a coalition of nearly 70 nations dedicated to building collective cyber resilience. Operating under four pillars—policy development, capacity development, public-private partnerships, and the International Counter-Ransomware Task Force—the CRI offers platforms for real-time threat sharing, technical support, and global cooperation. Onyanyai emphasised the initiative’s mentorship model: ‘Advanced nations can guide less-prepared countries, ensuring no one faces this threat alone.’

Public-private cooperation emerged as a cornerstone of the fight. Vish stressed that private companies, often the first to detect attacks, ‘own critical infrastructure and can contribute threat intelligence and resilience strategies.’ Additionally, the role of cyber insurance was discussed as a tool for incentivising better cybersecurity hygiene while facilitating incident recovery.

The panellists underscored the need for collective preparation, emphasising proactive measures like multi-factor authentication and data backups. Vish coined the mantra: ‘Prepare, don’t pay.’ While CRI officially advocates a ‘no ransom’ stance, some countries still grapple with policies on payments.

The session concluded with a stark reminder: no country is immune to ransomware. Whether through emerging AI capabilities or evolving tactics, ransomware remains a persistent, global threat. As Jennifer Bachus aptly summarised: ‘Only through cooperation, capacity building, and resilience will we turn the tide against these cybercriminals.

All transcripts from the Internet Governance Forum sessions can be found on dig.watch.

Cambodian ministry and APLE team up to enhance online safety education through a new initiative

The Cambodian Ministry of Education, Youth and Sport (MoEYS) and Action Pour Les Enfants (APLE) have signed a three-year Memorandum of Understanding (MoU) to implement the ‘Promoting Internet Safety in Education’ project. That initiative promotes child online safety by integrating lessons on recognising and reporting online threats, such as grooming and coercion, into school curricula.

The project also aims to strengthen the capacities of educational institutions, including ministry departments and schools, while providing tailored resources and training for teachers to deliver online safety content. It involves collaboration with key stakeholders, including school administrations, teachers, education officials, parents, community members, and children, to foster a safer digital environment.

However, challenges such as limited resources and low awareness among parents and children pose significant barriers to implementation. The initial phase focuses on seven provinces, with plans for further expansion based on the project’s success.

Why does it matter?

APLE’s strong commitment to combating online sexual abuse and human trafficking reflects the urgency of addressing these critical issues in today’s digital society. The initiative aligns with national education strategies and ensures sustainability by equipping educators and students with the tools to navigate the internet safely.

Additionally, the project includes a comprehensive evaluation after three years to assess its impact and inform potential expansion to other provinces. That effort underscores the importance of empowering communities to prevent and report online exploitation effectively, creating a lasting effect on child safety.

Trump administration plans stronger response to cyber attacks

The incoming Trump administration is set to explore ways to impose higher costs on adversaries and private actors behind cyber attacks, according to Representative Mike Waltz, the pick for national security adviser. Waltz’s statement follows US allegations that a widespread Chinese cyberespionage operation, known as Salt Typhoon, targeted senior American officials and stole significant amounts of metadata.

The White House has revealed that at least eight telecommunications and infrastructure firms in the US were compromised during this campaign. While Waltz did not specify potential actions against Salt Typhoon, he emphasised the need to go beyond defensive measures and start taking offensive actions to deter cyber threats.

Waltz also highlighted the role of the US tech industry in strengthening national defence and exposing vulnerabilities in adversaries. Meanwhile, Chinese officials continue to deny involvement, dismissing the accusations as disinformation and asserting that Beijing opposes cyber attacks in all forms.

Serbian spyware targets activists and journalists, Amnesty says

Serbia has been accused of using spyware to target journalists and activists, according to a new Amnesty International report. Investigations revealed that ‘NoviSpy,’ a homegrown spyware, extracted private data from devices and uploaded it to a government-controlled server. Some cases also involved the use of technology provided by Israeli firm Cellebrite to unlock phones before infecting them.

Activists reported unusual phone activity following meetings with Serbian authorities. Forensic experts confirmed NoviSpy exported contact lists and private photos to state-controlled servers. The Serbian government has yet to respond to requests for comment regarding these allegations.

Cellebrite, whose phone-cracking devices are widely used by law enforcement worldwide, stated it is investigating the claims. The company’s representative noted that misuse of their technology could violate end-user agreements, potentially leading to a suspension of use by Serbian officials.

Concerns over these practices are heightened due to Serbia’s EU integration programme, partially funded by Norway and administered by the UN Office for Project Services (UNOPS). Norway expressed alarm over the findings and plans to meet with Serbian authorities and UNOPS for clarification.

Meta apps experience widespread outages across the United States

Facebook, Instagram, and WhatsApp experienced significant outages across the United States on Wednesday, leaving thousands of users unable to access the popular platforms. Outage tracking site Downdetector recorded over 27,000 reports for Facebook, 28,000 for Instagram, and more than 1,000 for WhatsApp. The disruptions began around 12:50 p.m. ET, with users encountering error messages such as ‘something went wrong.’

Meta acknowledged the issue in a post on X, assuring users that it was working to resolve the problem quickly. A spokesperson apologised for the inconvenience and said teams were working diligently to restore services to normal.

User frustration echoed on X, with many expressing concerns about the reliability of Meta’s platforms. Outages like this are not unprecedented. Earlier this year, Meta faced a similar global disruption that impacted hundreds of thousands of users. In October, Meta apps were also briefly offline due to technical issues, although those were resolved within an hour.

Meta’s platforms are among the most widely used social media and communication tools globally. The recurrence of technical problems highlights the challenges of maintaining the reliability of such massive online infrastructures.

TikTok’s request to temporarily halt the US ban rejected by US court

TikTok’s deadline is approaching as its Chinese parent company, ByteDance, prepares to take its case to the US Supreme Court. A federal appeals court on Friday rejected TikTok’s request for more time to challenge a law mandating ByteDance to divest TikTok’s US operations by 19 January or face a nationwide ban. The platform, used by 170 million Americans, now has weeks to seek intervention from the Supreme Court to avoid a shutdown that would reshape the digital landscape.

The US government argues that ByteDance’s control over TikTok poses a persistent national security threat, claiming the app’s ties to China could expose American data to misuse. TikTok strongly disputes these assertions, stating that user data and content recommendation systems are stored on US-based Oracle servers and that moderation decisions are made domestically. A TikTok spokesperson emphasised the platform’s intention to fight for free speech, pointing to the Supreme Court’s history of defending such rights.

The ruling leaves TikTok’s immediate fate uncertain, placing the decision first in the hands of President Joe Biden, who could grant a 90-day extension if progress toward a divestiture is evident. However, Biden’s decision would give way to President-elect Donald Trump, who takes office just one day after the 19 January deadline. Despite his previous efforts to ban TikTok in 2020, Trump recently opposed the current law, citing concerns about its benefits to rival platforms like Facebook.

Adding to the urgency, US lawmakers have called on Apple and Google to prepare to remove TikTok from their app stores if ByteDance fails to comply. As the clock ticks, TikTok’s battle with the US government highlights a broader conflict over technology, data privacy, and national security. The legal outcome could force millions of users and businesses to rethink their digital strategies in a post-TikTok world.

Krispy Kreme hit by IT disruption affecting US online orders

Krispy Kreme has reported a cybersecurity incident that disrupted online ordering systems across the United States. The doughnut chain discovered the unauthorised activity on 29 November and immediately launched an investigation with external cybersecurity experts.

While the company’s stores remain open for in-person orders, it warned that revenue losses from digital sales could materially impact its financial results. Shares of Krispy Kreme fell by around 2% in premarket trading following the announcement.

The company said it is actively working to mitigate the effects of the incident while maintaining operations at its global locations.

Serie A takes action against piracy with Meta

Serie A has partnered with Meta to combat illegal live streaming of football matches, aiming to protect its broadcasting rights. Under the agreement, Serie A will gain access to Meta’s tools for real-time detection and swift removal of unauthorised streams on Facebook and Instagram.

Broadcasting revenue remains vital for Serie A clubs, including Inter Milan and Juventus, with €4.5 billion secured through deals with DAZN and Sky until 2029. The league’s CEO urged other platforms to follow Meta’s lead in fighting piracy.

Italian authorities have ramped up anti-piracy measures, passing laws that enable swift takedowns of illegal streams. Earlier this month, police dismantled a network with 22 million users, highlighting the scale of the issue.

Experts at the IGF address the growing threat of misinformation in the digital age

In an Internet Governance Forum panel in Riyadh, Saudi Arabia, titled ‘Navigating the misinformation maze: Strategic cooperation for a trusted digital future’, moderated by Italian journalist Barbara Carfagna, experts from diverse sectors examined the escalating problem of misinformation and explored solutions for the digital era. Esam Alwagait, Director of the Saudi Data and AI Authority’s National Information Center, identified social media as the primary driver of false information, with algorithms amplifying sensational content.

Natalia Gherman of the UN Counter-Terrorism Committee noted the danger of unmoderated online spaces, while Mohammed Ali Al-Qaed of Bahrain’s Information and Government Authority emphasised the role of influencers in spreading false narratives. Khaled Mansour, a Meta Oversight Board member, pointed out that misinformation can be deadly, stating, ‘Misinformation kills. By spreading misinformation in conflict times from Myanmar to Sudan to Syria, this can be murderous.’

Emerging technologies like AI were highlighted as both culprits and potential solutions. Alwagait and Al-Qaed discussed how AI-driven tools could detect manipulated media and analyse linguistic patterns, while Al-Qaed proposed ‘verify-by-design’ mechanisms to tag information at its source.

However, the panel warned of AI’s ability to generate convincing fake content, fueling an arms race between creators of misinformation and its detectors. Pearse O’Donohue of the European Commission’s DigiConnect Directorate praised the EU’s Digital Services Act as a regulatory model but questioned, ‘Who moderates the regulator?’ Meanwhile, Mansour cautioned against overreach, advocating for labelling content rather than outright removal to preserve freedom of expression.

Deemah Al-Yahya, Secretary General of the Digital Cooperation Organization, emphasised the importance of global collaboration, supported by Gherman, who called for unified strategies through international forums like the Internet Governance Forum. Al-Qaed suggested regional cooperation could strengthen smaller nations’ influence over tech platforms. The panel also stressed promoting credible information and digital literacy to empower users, with Mansour noting that fostering ‘good information’ is essential to counter misinformation at its root.

The discussion concluded with a consensus on the need for balanced, innovative solutions. Speakers called for collaborative regulatory approaches, advanced fact-checking tools, and initiatives that protect freedom of expression while tackling misinformation’s far-reaching consequences.

All transcripts from the Internet Governance Forum sessions can be found on dig.watch.

Saudi Arabia hosts 19th annual Internet Governance Forum in Riyadh

The 19th annual Internet Governance Forum (IGF) officially began today in Riyadh, Saudi Arabia, bringing together global leaders, policymakers, innovators, and civil society under the theme ‘Building our multistakeholder digital future.’ Held from 15 to 19 December 2024, this most relevant international event serves as a platform for open dialogue on pressing issues surrounding the digital space.

The IGF 2024 kicks off with a focus on four key themes that reflect the growing complexities and opportunities of the digital age. First, ‘Harnessing innovation and balancing risks in the digital space’ explores ways to maximise the benefits of rapid digital transformation while tackling its associated risks. Through shared success stories and best practices, stakeholders aim to create a safer, more innovative digital landscape for all.

The second theme, ‘Enhancing the digital contribution to peace, development, and sustainability,’ positions digitalisation as a catalyst for socioeconomic change. Participants discuss how technology can drive sustainable development and improve the lives of both current and future generations, particularly in underserved regions.

Advancing inclusion remains a critical issue, so the third theme, ‘Advancing human rights and inclusion in the digital age,’ spotlights initiatives that ensure universal, meaningful connectivity while safeguarding digital rights. Discussions centre on bridging the digital divide, addressing inequalities, and fostering innovation that aligns with human rights principles.

Finally, the forum dedicates significant attention to ‘Improving digital governance for the Internet We Want.’ As global stakeholders continue to debate the future of Internet governance, this theme prioritises transparency, openness, and inclusive, bottom-up approaches to building a digital ecosystem that works for everyone.

The conference adopts a hybrid format, offering in-person participation in Riyadh alongside virtual attendance for delegates worldwide. With registration officially open, thousands of stakeholders from across governments, businesses, academia, and civil society are expected to engage in discussions and collaborative efforts to shape a resilient, inclusive, and innovative digital future.

For those unable to attend in person, Diplo is providing comprehensive coverage of the main sessions of IGF 2024. All updates, reports, and analyses can be followed live on the Digital Watch Observatory (dig.watch). In addition, Diplo has introduced chatbots for each event, allowing participants and online viewers to ask questions about specific sessions and get real-time insights on key discussions, topics, and outcomes.

With IGF 2024 underway, Riyadh has become the epicentre of global discussions on digital transformation, governance, and innovation. Through real-time reporting and interactive tools, Diplo ensures that audiences worldwide remain connected and informed, shaping a truly inclusive and multistakeholder digital future. With an eye toward global digital transformation, the forum sets the stage for shaping policies and solutions that will define the next chapter of our shared digital future.