Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

241–250 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#241

Earlier quoted context omitted.

It's the 3-letter agencies where the expertise lies. Maybe a new agency needs to be created outside of the intelligence agencies?

Yes, at least a 16-letter agency consisting of uppercase lowercase letters and special characters would be much better ;)

I like to use foreign letters like ß and ö in my passwords.

Good luck guessing that password. I'm not even German.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#243

Earlier quoted context omitted.

Realistically, ransomware will just never stop until IT systems are sufficiently hardened.

Or sufficiently backed up, right? If you’ve got a backup and quick recovery process ransomware is impotent.

If hackers take the slow route, all backups may be encrypted too. Or at least, compromised.

Also, backups are often taken but rarely is their actual recoverability tested.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#244

Earlier quoted context omitted.

Realistically, ransomware will just never stop until IT systems are sufficiently hardened.

Nah. It will never stop. The problem is information density. So long as billions of records that are needed for the business exist in a device the size of a shoebox, we’re fucked. An insider can always take the shoebox, lock the shoebox, etc. Three stories of paper files in file cabinets can’t be ransomed short of a physical bomb threat. Don’t know what the solution is. But I do know the problem. Exfiltrarion is simi…

There is a part of me that would like to go back to the way we dud business before the internet, and computers.

I think three daily encrypted backups mandated by law would be enough to stop the multi-million dollar ransoms.

We will still see companies paying ransom for a business days loss, but not complete shutouts? And infrastructure specific operations, like this pipe line, should be air gapped.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#245
post #218
post #142

Earlier quoted context omitted.

No. The security problem is not a lack of effort or laxness, it is a fundamental inability to solve the problem. At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. The absolute best of the best commercial IT systems implemented as envisioned with full support can maybe protect up to the $10M level and I am just extrapolating upwards since I have never had any secu…

> At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. Even if that's true, it doesn't affect backups. Back your fucking systems up properly, and if you are attacked by ransomware, then do a scorched earth restore.

It absolutely does affect backups. If you stand to gain $5M from an attack you can also target the backup systems and still easily end up profitable. Only if you stand to gain less than $100k does the budget actually start to get tight.

As for how you attack the backup system it depends. If it push based you send your payload during the push. If it is pull based you craft your payload in the data that will be backed up. If it is not append-only you can easily nuke the entire available history. If it is append-only, but that is only done in software you just need to take over the software. If it is in hardware you just infiltrate then silently encrypt any new data until it would be painful to revert that far back in time. Given that the mean-time to discovery is on the order of months that is quite painful. If they regularly test their backups you just silently decrypt the data on restore until it is time to strike. There are plenty of ways to beat vulnerable backup systems in that sort of budget.

Like, seriously, with a $5M budget you can literally purchase and burn multiple zero days for every system in the chain and still come out ahead. You can hire 10-50 full time software engineers for a year per attack. Most systems have serious vulnerabilities discovered by lone individuals working for a few months in their free time let alone a team of 50 people. The current backup systems survive because most of these attacks are being done with budgets closer to $10k-$100k to maximize profit and growth rate and that is not really enough money to pay for the second arm of the attack. But with a $5M return they could easily allocate a few million to capitalize on the opportunity if that is what is needed once all the juicier targets have been eaten.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#247

Ugh. This ransomware crap doesn't stop until the money stops . At this point, ransomware operators are bribing insiders to install their custom, AV-evading ransomware directly on company servers (e.g. https://www.secureworldexpo.com/industry-news/fbi-sting-the-... ). No need to trick someone into running a malicious Word attachment when you can just wire someone $1M to do it deliberately! And, best of all, you can se…

>ransomware

I prefer to think of them as bug bounties. Too often, bugs are reported now to bug bounty programs and are either grossly underpaid for the bug's actual value, or deflected as not a real issue at all. Ransomware is ultimately the result. "Fuck you, pay me."

https://www.youtube.com/watch?v=3XGAmPRxV48

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#248
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

What I have heard regarding ransoms like these is that the perpetrators goal is to incentivize the transaction goes smoothly, or it won’t continue to work.

So they have to follow through with unlocking and they have to use an amount of money low enough to make the decision obvious.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#249
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

Sounds like a $50m incentive to hire a security team.
Post reply on HN