Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

201–210 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#201
The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast.

$5M for shutting down that major of a pipeline seems like too little, unless, of course, they weren't expecting the company to even pay. Now that these actors know that the oil (and quite likely other utilities) are more than willing to pay big bucks to get back online, they will be targeted far more.

There are so many reasons this is very very bad.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#202
post #173

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

Absolutely this. Paying a ransom should be illegal and company officers should face personal criminal liability for allowing it. If the CEO of Colonial was facing jail time, there is no way the payment would have happened.

I’ll go to prison for some time for being their new CFO. If some cash goes to myself or a close family member after I pay the ransomware as CCO.

Obviously this would be too transparent if done in the span of a week.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#203

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

Imagine making it illegal to hand over your wallet to a mugger holding a gun to you.

All you are doing is incentivizing companies to not report these attacks.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#204

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

it should be illegal if the government wants to help recoup the losses. If a have a firm that makes $100,000,000 a year in net-profit , paying a $5 ransomware is a cost of doing business, an unfortunate one nonetheless

It incentivizes more crime and should be illegal.

Businesses don't have a right to do whatever they want just because it is profitable.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#205
post #46

Earlier quoted context omitted.

That is an acceptable outcome. Let the victims suffer. That protects the rest of us, and serves as an object lesson in proper cyber security.

So let people who aren’t experts at physical security suffer break-ins, and physically weak people get beaten up? We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass. I love security but 99% of people don’t, and shouldn’t

> We have law enforcement so everyone can be free to focus on their own value-add in life without having to learn 1000 skills to cover their own ass.

No, that's why we have division of labor. Law enforcement is just another brick in the wall. If a company is already making massive profits from the public by running critical services, why should tax payers fund their lack of diligence? Should we just fund their entire payroll while we're at it?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#206

Earlier quoted context omitted.

Paying Ransoms should be criminalized as there is far more damage from allowing this to continue then having a few systems wiped and restored from backups. Not taking steps to have cybersecurity in companies should be criminalized as well... I am a CEO and thinks CEO's should be held directly criminally responsible for this. Finally, any nation that allows hackers to operate from within their borders should be subjec…

If you think the 100X damages is overkill please reconsider within this framework: Any nation that harbors international terrorists by not at least attempting to hold them accountable is implicitly operating an outsourced covert activities team. The actions of any such team should be considered representative of that country and thus this would be an act of guerilla warfare.

Nukem from orbit, it's the only way to be sure.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#207
Dumb question: why can’t crypto currencies and exchanges place the ransom tokens on some kind of blocklist, thereby forever tainting those coins? As I understand, the rise of “privacy wallets” has greatly increased the anonymity of such transactions. But, at the end of the day, don’t we always have a ledger of the coin ids? I’m curious how the coins actually get laundered back into cash.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#208
post #173

Earlier quoted context omitted.

Absolutely this. Paying a ransom should be illegal and company officers should face personal criminal liability for allowing it. If the CEO of Colonial was facing jail time, there is no way the payment would have happened.

The Obama administration secretly organized an airlift of $400 million worth of cash to Iran that coincided with the January 2016 release of four Americans detained in Tehran, according to U.S. and European officials and congressional staff briefed on the operation afterward. Wooden pallets stacked with euros, Swiss francs and other currencies were flown into Iran on an unmarked cargo plane, according to these offici…

To be fair, that was Iranian money in the first place that had been frozen.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#209
post #139

Earlier quoted context omitted.

You have a point. They should do minimum due diligence to harden their networks. However... how much do you want to bet that the CEO of a pipeline company has the knowledge to make this happen? One has to be an intelligent customer to make something like this happen.

Well then, perhaps there should be minimum requirements to become CEO of a large corporation in regulated areas like pipelines? If the alternative is large harm to the public, this seems like a no-brainer to me for future legislation.

So should the president of the United States be an expert on tactical jet engines? And also have a PHD in economics? And also be an expert in immunology? And power plant operations? How about the national airspace system?

People are quick to conclude that Colonial’s security was “bad.” But do we know that to be true? A sophisticated, potentially state-sponsored organization initiated this attack. The best security in the world is not 100% secure. It might be wise to get the facts before rushing to judgement.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#210

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

Are there enough Infosec people to fill every open job for it in the USA? I would imagine that it is like software development, where the unemployed software devs are the kind that can't figure out git.

I doubt there are enough infosec people which means in theory that compensation should rise which will then attract more people into the field. Until they're trained and experienced, whoever provides the best place to work (compensation and intangibles that lead to satisfaction) would get the help they need while others would be more vulnerable to attack. But from what I've seen, this isn't happening. There's lots of complaints about there not being enough workers but instead of boosting compensation and/or quality of employment, the positions simply stay open for extended periods of time.
Post reply on HN