Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

231–240 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#231

So, supposedly, Colonial paid the ransom "within hours after the attack". And, supposedly, the attack didn't even hit any ICS, just the payment infrastructure ( https://www.zdnet.com/article/colonial-pipeline-ransomware-a... ). Why are there still gas shortages 6 days later? Not a rhetorical question at all. To me, the idea that the infrastructure we rely on is controlled by middle managers with no sense of urgency a…

All you need for gas shortages is the rumor of gas shortages. Remember how we ran out of TP last year, for absolutely no reason whatsoever?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#232
post #224

That’s retirement money. Live on an island, doing drugs and drinking champagne for the rest of your life money. Im in the wrong line of work.

Yea, crime really does pay here. If I was a lone hacker in a nation with loose laws I’d be ransoming foreign systems and building a fortune.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#233
post #152

Earlier quoted context omitted.

If the US were to be serious about corporate IT security, they'd empower and indemnify DoD, NSA, private industry red teams to pentest against everything with a US point of presence or customers, using commercial available / in the wild methods. This would have the beneficial side effect of flushing all the incompetent paper-pushers / requirement-box-checkers out of the security industry. If you're found vulnerable,…

>If the US were to be serious about corporate IT security What happened to the responsibility of corporations for corporate security? Including corporations that are the victims of attacks, and corporations that sell buggy operating systems and applications? Why does the government have to provide the red teams? The general attitude is all government agencies are wasteful and incompetent, except in this circumstance…

“Too big to fail” and investors do not get hurt.

The problem does not fix itself until the investors start truly losing money, the care, unlike the Equifax case. Until the portfolio value cannot go down 90% there is not going to be a change in corporate actionism.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#234

I am definitely not an expert in these areas and I'm sure someone 100x smarter than I am has thought of this and discounted it already, but is there any ability to decompile the executable provided to Colonial and get to patterns of source code, then compel github to search their repositories for any patterns of that code? Not sure if that is even legal or whether a judge would authorize that fishing expedition, but…

are you assuming the ransomware is collaboratively coded on github?

The authors of the ransomware might have non-ransomware projects on github where an analysis of coding style gives them away. It's sounds like it would have a low probability of working but this is essentially what got the Unabomber caught. But writing styles in English might be easier to identify than in code. Maybe they'll use "cool headed logician" as a procedure name.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#235

Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.

Imagine making it illegal to hand over your wallet to a mugger holding a gun to you. All you are doing is incentivizing companies to not report these attacks.

Not a good analogy, for two reasons. First, workers who don't have equity in a company don't really have a gun to their head even if the existence of the company is at risk. The real "gun to the head" is the threat of jail time. Second, it has historically been difficult to convince dozens of people to coordinate with each other and do something illegal for little to no personal gain.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#236

Earlier quoted context omitted.

To be fair, that was Iranian money in the first place that had been frozen.

It was still a ransom. “I’ll give you money, you release our hostages.”

"I'll give you [back your] money, you release our hostages" -- but that doesn't fit the agenda as well, does it?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#237

All that money and lawlessness that went into enabling security agencies must be crowned as the worst investment ever

Many of those agencies seem more interested in making systems less secure so they can get in easily than in protecting systems from outsiders.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#238
And the group originally though responsible for this was actually just a ransomware-as-a-service partner here, and seem a little embarrassed about the while thing. Basically they said "yeah, we don't want our partners doing stuff that big so we'll ask them not to in the future." Hopefully that doesn't stop the full weight if the US intelligence services from coming down on them and every single other ransomware scammers they can find... And outlawing payments to these terrorists.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#239
post #150

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.

[deleted]

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#240
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

Yeah, but now there is also a massive bounty out for these hackers. Money needs to get out at some point and that's when they'll get nailed.
Post reply on HN