Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

261–270 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#261

Dumb question: why can’t crypto currencies and exchanges place the ransom tokens on some kind of blocklist, thereby forever tainting those coins? As I understand, the rise of “privacy wallets” has greatly increased the anonymity of such transactions. But, at the end of the day, don’t we always have a ledger of the coin ids? I’m curious how the coins actually get laundered back into cash.

Read up on monero. Transactions in Monero are almost always untraceable.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#262

I'm not really anti-crypto, but a strong disadvantage to society is that these attacks are made much more easily because they can bypass traditional financial institutions.

The crypto still interfaces directly with the financial system on all ends. The company move money to an exchange (using the financial system), and the hacker cashes in the crypto eventually (using the financial system).

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#263

Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes. Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the compa…

> paying the ransom puts their shareholders at risk of serious sanctions and indictment from the US Dept. of the Treasury.

Treasury doesn’t indict anyone, that’s Justice’s job.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#264
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

I agree. I’d give 60% odds that there is at least one significant attack (ransomware plus shutdown) on US power grids in the next 18 months.

Basic game theory dictates that the cost of ransoms will continue to rise until it hits the price point at which the targeted company would have to replace its compromised systems from scratch.

5M, 50M, 500M, 5B, 50B?

I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#265

So, supposedly, Colonial paid the ransom "within hours after the attack". And, supposedly, the attack didn't even hit any ICS, just the payment infrastructure ( https://www.zdnet.com/article/colonial-pipeline-ransomware-a... ). Why are there still gas shortages 6 days later? Not a rhetorical question at all. To me, the idea that the infrastructure we rely on is controlled by middle managers with no sense of urgency a…

You do not need actual disruptions in supply to create a shortage. The threat of a disruption or a shortage for such a critical commodity can create a situation that it becomes a self fulfilling prophecy (short term). That is what can often create bank runs and created the "great toilet paper shortage of 2020".

But the pipeline has been closed: https://abc11.com/business/theres-plenty-of-gas-in-the-us-th...

And the toilet paper shortage was not purely panic-driven. People did shit at work before the pandemic, and that part of demand switched to a different supply chain. The panic-induced bullwhip was probably stronger than the original demand spike, but the whole thing wasn't just memed into existence.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#266
post #231

So, supposedly, Colonial paid the ransom "within hours after the attack". And, supposedly, the attack didn't even hit any ICS, just the payment infrastructure ( https://www.zdnet.com/article/colonial-pipeline-ransomware-a... ). Why are there still gas shortages 6 days later? Not a rhetorical question at all. To me, the idea that the infrastructure we rely on is controlled by middle managers with no sense of urgency a…

All you need for gas shortages is the rumor of gas shortages. Remember how we ran out of TP last year, for absolutely no reason whatsoever?

Just answered this at https://news.ycombinator.com/item?id=27148622

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#267

Dumb question: why can’t crypto currencies and exchanges place the ransom tokens on some kind of blocklist, thereby forever tainting those coins? As I understand, the rise of “privacy wallets” has greatly increased the anonymity of such transactions. But, at the end of the day, don’t we always have a ledger of the coin ids? I’m curious how the coins actually get laundered back into cash.

Coinbase and other exchanges do that actually, when they find that an address belongs to a hacker.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#269

Earlier quoted context omitted.

Sounds like a $50m incentive to hire a security team.

Or more likely insurance. The insurance may demand better practices for lower premium in turn

There were some news reports yesterday about insurance companies dropping cyber-ransom insurance from their offerings (AXA, I think). Very likely more insurance companies will do the same soon, or at least, refuse to insure the company unless they comply with some cybersecurity standards.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#270
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

I agree. I’d give 60% odds that there is at least one significant attack (ransomware plus shutdown) on US power grids in the next 18 months.

Taking out a fuel pipeline in non-heating months seems a lot less likely to cause casualties than downing a power grid. Dead people get different responses than theft, even massive theft. Also, knowing how scary oil companies are, I wouldn't be surprised if some people turned up dead over the colonial hack. Even if they get the attribution wrong, a dead hacker group would have a chilling effect on such activities.
Post reply on HN