Colonial Pipeline Paid Hackers Nearly $5M in Ransom
51–60 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#52It's better to have criminals who are only interested in a relatively small payout exposing to the general public how vulnerable critical infrastructure is than people who are interested in causing mass destruction.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#53There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods of time. As long as the position actually exists, they're not all that concerned with filling it. This might be complacency creep. Everyone staffed up after the cluster of breaches that happened around the time of the Target and Equifax breaches. A lack of other high profile breaches or attacks might be why many companies have become lax in keeping their staffs full.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#54Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.
Perhaps instead it should not be legal to say publicly you paid a ransom but ok to pay the ransom. That would tamp down a bit the publicity that encourages more actors. That would be a quick and easy fix along the lines of insider trading.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#55Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.
In certain cases, it is: https://www.sidley.com/en/insights/newsupdates/2020/10/offic...
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#56Earlier quoted context omitted.
Now we have one less critical piece of infrastructure that could be trivially knocked out by a hostile state.
They are installing more software from the hacker voluntarily after paying the ransom. At this rate it looks more like they just hired a competent and highly unethical vendor..
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#57Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if the attackers had full control over their network. Another possibility: Colonial staff could not be sure that if they used their backups, everything would be encrypted immediately again - possibly the backup servers as wel…
I am curious what your thoughts are on other commenters making as if it is possible to prevent these types of attacks by just taking security 'more seriously'. My guess is that you know that no matter how much is spent with a large entity and many employees it's near impossible to prevent this type of attack. People make mistakes people are easily fooled people don't follow what they are told to do and so on. I can't…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#58Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#59So they paid a penetration-testing firm a consultancy fee to help harden their network.
Could you elaborate on where you see the hardening taking place? Colonial had a threat actor in their network and by paying the ransom, they supposedly left without doing any more damage. I don’t think they patched a lot of systems or hardened their servers.
/s
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#60Earlier quoted context omitted.
I understand the sentiment, but you'd end up re-victimizing the victim. Someone who felt like they had no choice but to pay could later be prosecuted, while the the actual criminal walks free in anonymity.
That is an acceptable outcome. Let the victims suffer. That protects the rest of us, and serves as an object lesson in proper cyber security.
We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t