Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

191–200 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#191

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

Giving up your wallet while at gunpoint should also be illegal!

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#192
post #116

Earlier quoted context omitted.

> So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up? First, in many jurisdictions, paying protection money for physical security is illegal. Second, Colonial Pipeline has an operating revenue of $1.32 billion. I suppose in the USA it's technically a person, but... it's not actually a person. > We have law enforcement so everyone can be free to focus on th…

So, you are saying that there are jurisdictions where home security systems are illegal? Night watchmen/security guards and body guards are illegal? Where would these jurisdictions be located?

I don't think that's even close to what I'm saying. I'm not even really sure what you are trying to communicate here; are you insinuating that ADT or Ring hire roving bands of bandits who break into houses that aren't protected by their security systems? If not, I genuinely don't know what you're trying to say here.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#193

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

Realistically, ransomware will just never stop until IT systems are sufficiently hardened.

Some ransomware is time-delayed because of this, so it isn't clear which backup is still untainted.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#194
post #173

Earlier quoted context omitted.

Absolutely this. Paying a ransom should be illegal and company officers should face personal criminal liability for allowing it. If the CEO of Colonial was facing jail time, there is no way the payment would have happened.

I would sooner have security negligence be criminalized as there are a number of products that are critical to the economy and peoples health. Having a companies systems get wiped out can have a monumental amount of collateral damage.

Paying Ransoms should be criminalized as there is far more damage from allowing this to continue then having a few systems wiped and restored from backups.

Not taking steps to have cybersecurity in companies should be criminalized as well... I am a CEO and thinks CEO's should be held directly criminally responsible for this.

Finally, any nation that allows hackers to operate from within their borders should be subject to 100x over damages caused sanctions. Countries without strong governments to enforce this should have direct airstrikes conducted against the individual hackers.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#195
post #173

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

Absolutely this. Paying a ransom should be illegal and company officers should face personal criminal liability for allowing it. If the CEO of Colonial was facing jail time, there is no way the payment would have happened.

The Obama administration secretly organized an airlift of $400 million worth of cash to Iran that coincided with the January 2016 release of four Americans detained in Tehran, according to U.S. and European officials and congressional staff briefed on the operation afterward.

Wooden pallets stacked with euros, Swiss francs and other currencies were flown into Iran on an unmarked cargo plane, according to these officials. The U.S. procured the money from the central banks of the Netherlands and Switzerland, they said.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#196
post #39
post #8

Too many companies prefer to skimp on security since it has no apparent payoff until it's too late. What I want to know are the circumstances of the hack; how did it work, what systems did it affect, what security were they lacking. Sadly these details are often ignored or hidden from view. Attacks of this kind should get a public report so that other companies can learn or at least be shamed into changing. It seems…

Part of the problem is it's very hard to value security because, frankly, so much security is theatrics and snake oil. For instance, look at the consumer market, which is where an executive without security knowledge is coming from. All the big VPN vendors make security promises that are, frankly, false advertising. AV products are notorious for including warnings for viruses that pad their counts. That's not countin…

The fact that are so many ads and info sessions about IT-sec are from people who seem to have never written a line of code in their entire life is worrying.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#197

Earlier quoted context omitted.

Here we have a coordination problem, like the prisoner’s dilemma. People who pay ransom are the defectors, improving their situation at the cost of making the problem much worse for everyone. If fewer people paid ransom, ransomware would be less profitable and would happen less often and we’d all be better off. The government can help coordination by making defecting more costly (with criminal penalties).

Civil penalties may be more palatable. If organizations are willing and able to pay a ransom, there should be no problem with paying a fine as well.

You've finally found a way to fund open source development.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#198

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

I wonder how long you’d sit it out losing money before you paid. I think it’s very easy to talk a big game until you’ve lost many multiples of the ransom with no end in sight. It’s literally just a waiting game for the hackers, they have nothing to lose and everything to gain. So what if you don’t pay, you can just leave them screwed and move on to the next one.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#199

>The company paid the hefty ransom in untraceable cryptocurrency within hours after the attack in Monero? Wonder how they converted USD.

I'm wondering too. Now in TFA I read:

"The company paid the hefty ransom in difficult-to-trace cryptocurrency within hours after the attack..."

I don't know why you got "untraceable" and I get "difficult to trace" when reading the article.

Bitcoin ain't exactly difficult to trace. I wonder if Colonial took the "discount" of 30% and paid in Monero or if they paid in Bitcoin.

Oh well it looks at least one company is going to give a bit more sh-t about its IT security ; )

And another thing: often these news are followed, a few weeks/months later by "How the hackers who got a $5m ransom from Colonial got caught".

Waiting for that one...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#200

Earlier quoted context omitted.

I would sooner have security negligence be criminalized as there are a number of products that are critical to the economy and peoples health. Having a companies systems get wiped out can have a monumental amount of collateral damage.

Paying Ransoms should be criminalized as there is far more damage from allowing this to continue then having a few systems wiped and restored from backups. Not taking steps to have cybersecurity in companies should be criminalized as well... I am a CEO and thinks CEO's should be held directly criminally responsible for this. Finally, any nation that allows hackers to operate from within their borders should be subjec…

If you think the 100X damages is overkill please reconsider within this framework:

Any nation that harbors international terrorists by not at least attempting to hold them accountable is implicitly operating an outsourced covert activities team. The actions of any such team should be considered representative of that country and thus this would be an act of guerilla warfare.

Post reply on HN