Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes. Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the compa…
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
251–260 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#252The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#253One thing that this attack has proven is that if we ever reach the point where we engage in military conflict with either Russia or China we are going to be functioning as if we experienced a country wide emp within a few days. Our infrastructure is massively vulnerable.
A global hot war between super powers would be disastrous for everyone involved. That’s why it probably won’t happen. I’d be more worried about rogue actors, terrorists and other “mad men” who might get their hands on a dirty bomb or fry the power grid in New York in January.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#254Earlier quoted context omitted.
I wonder how long you’d sit it out losing money before you paid. I think it’s very easy to talk a big game until you’ve lost many multiples of the ransom with no end in sight. It’s literally just a waiting game for the hackers, they have nothing to lose and everything to gain. So what if you don’t pay, you can just leave them screwed and move on to the next one.
Or if you're running a service which can't wait. Like a medical clinic with no access to patient records.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#255[0]https://www.bostonglobe.com/2021/05/13/business/colonial-pip...
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#256The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
Sounds like a $50m incentive to hire a security team.
The insurance may demand better practices for lower premium in turn
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#257The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
What I have heard regarding ransoms like these is that the perpetrators goal is to incentivize the transaction goes smoothly, or it won’t continue to work. So they have to follow through with unlocking and they have to use an amount of money low enough to make the decision obvious.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#258It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
No. The security problem is not a lack of effort or laxness, it is a fundamental inability to solve the problem. At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. The absolute best of the best commercial IT systems implemented as envisioned with full support can maybe protect up to the $10M level and I am just extrapolating upwards since I have never had any secu…
And yet Apple still manages to keep its private signing keys secure. Even from the FBI.
It’s doable.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#259The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#260I mean yeah, there are already attempts to blame everyone, but management who effectively made it clear that long term paying 5MM is cheaper than actually being careful, but I remain hopeful.