Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

51–60 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#53
It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position.

There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods of time. As long as the position actually exists, they're not all that concerned with filling it. This might be complacency creep. Everyone staffed up after the cluster of breaches that happened around the time of the Target and Equifax breaches. A lack of other high profile breaches or attacks might be why many companies have become lax in keeping their staffs full.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#54

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

> Paying ransom should be illegal.

Perhaps instead it should not be legal to say publicly you paid a ransom but ok to pay the ransom. That would tamp down a bit the publicity that encourages more actors. That would be a quick and easy fix along the lines of insider trading.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#55

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

>Paying ransom should be illegal

In certain cases, it is: https://www.sidley.com/en/insights/newsupdates/2020/10/offic...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#56
post #24

Earlier quoted context omitted.

Now we have one less critical piece of infrastructure that could be trivially knocked out by a hostile state.

They are installing more software from the hacker voluntarily after paying the ransom. At this rate it looks more like they just hired a competent and highly unethical vendor..

That’s one hell of a way to provide “red-team” security testing services

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#57
post #50
post #25

Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if the attackers had full control over their network. Another possibility: Colonial staff could not be sure that if they used their backups, everything would be encrypted immediately again - possibly the backup servers as wel…

I am curious what your thoughts are on other commenters making as if it is possible to prevent these types of attacks by just taking security 'more seriously'. My guess is that you know that no matter how much is spent with a large entity and many employees it's near impossible to prevent this type of attack. People make mistakes people are easily fooled people don't follow what they are told to do and so on. I can't…

You cannot completely eliminate risk but you certainly can reduce it and be prepared for what to do when one of those low probability risks ends up happening.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#59
post #29
post #7

So they paid a penetration-testing firm a consultancy fee to help harden their network.

Could you elaborate on where you see the hardening taking place? Colonial had a threat actor in their network and by paying the ransom, they supposedly left without doing any more damage. I don’t think they patched a lot of systems or hardened their servers.

They "helped harden", as in they verified that the network needs hardening.

/s

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#60
post #46
post #33

Earlier quoted context omitted.

I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.

That is an acceptable outcome. Let the victims suffer. That protects the rest of us, and serves as an object lesson in proper cyber security.

So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up?

We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t

Post reply on HN