So, supposedly, Colonial paid the ransom "within hours after the attack". And, supposedly, the attack didn't even hit any ICS, just the payment infrastructure ( https://www.zdnet.com/article/colonial-pipeline-ransomware-a... ). Why are there still gas shortages 6 days later? Not a rhetorical question at all. To me, the idea that the infrastructure we rely on is controlled by middle managers with no sense of urgency a…
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
231–240 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#232That’s retirement money. Live on an island, doing drugs and drinking champagne for the rest of your life money. Im in the wrong line of work.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#233Earlier quoted context omitted.
If the US were to be serious about corporate IT security, they'd empower and indemnify DoD, NSA, private industry red teams to pentest against everything with a US point of presence or customers, using commercial available / in the wild methods. This would have the beneficial side effect of flushing all the incompetent paper-pushers / requirement-box-checkers out of the security industry. If you're found vulnerable,…
>If the US were to be serious about corporate IT security What happened to the responsibility of corporations for corporate security? Including corporations that are the victims of attacks, and corporations that sell buggy operating systems and applications? Why does the government have to provide the red teams? The general attitude is all government agencies are wasteful and incompetent, except in this circumstance…
The problem does not fix itself until the investors start truly losing money, the care, unlike the Equifax case. Until the portfolio value cannot go down 90% there is not going to be a change in corporate actionism.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#234I am definitely not an expert in these areas and I'm sure someone 100x smarter than I am has thought of this and discounted it already, but is there any ability to decompile the executable provided to Colonial and get to patterns of source code, then compel github to search their repositories for any patterns of that code? Not sure if that is even legal or whether a judge would authorize that fishing expedition, but…
are you assuming the ransomware is collaboratively coded on github?
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#235Paying ransom should be illegal. Ransom funds illegal activities. Not indirectly, like buying coffee or poppyseed or whatever, but literally money that is directly reinvested in criminal activity- like ransomware.
Imagine making it illegal to hand over your wallet to a mugger holding a gun to you. All you are doing is incentivizing companies to not report these attacks.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#236Earlier quoted context omitted.
To be fair, that was Iranian money in the first place that had been frozen.
It was still a ransom. “I’ll give you money, you release our hostages.”
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#237All that money and lawlessness that went into enabling security agencies must be crowned as the worst investment ever
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#238Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#239Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…
I think ransomware is the best thing that happened in computer security in a long time. All these companies keeping lots of people data or even being relevant to national security having completely no incentive to stay secure. Now There is incentive to test their security. A single person being able to compromise your company when paid a lot is a security issue that needs to be addressed.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#240The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…