Correction: Consumers Paid Nearly $5M in Ransom to Hackers.
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
271–280 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#272Earlier quoted context omitted.
If the US were to be serious about corporate IT security, they'd empower and indemnify DoD, NSA, private industry red teams to pentest against everything with a US point of presence or customers, using commercial available / in the wild methods. This would have the beneficial side effect of flushing all the incompetent paper-pushers / requirement-box-checkers out of the security industry. If you're found vulnerable,…
>If the US were to be serious about corporate IT security What happened to the responsibility of corporations for corporate security? Including corporations that are the victims of attacks, and corporations that sell buggy operating systems and applications? Why does the government have to provide the red teams? The general attitude is all government agencies are wasteful and incompetent, except in this circumstance…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#273I'm not really anti-crypto, but a strong disadvantage to society is that these attacks are made much more easily because they can bypass traditional financial institutions.
The crypto still interfaces directly with the financial system on all ends. The company move money to an exchange (using the financial system), and the hacker cashes in the crypto eventually (using the financial system).
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#274Earlier quoted context omitted.
I agree. I’d give 60% odds that there is at least one significant attack (ransomware plus shutdown) on US power grids in the next 18 months.
Basic game theory dictates that the cost of ransoms will continue to rise until it hits the price point at which the targeted company would have to replace its compromised systems from scratch. 5M, 50M, 500M, 5B, 50B? I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions
War.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#275The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#276The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
Assuming you were in a TV show, and offered two options: Spin wheel 1 with a 95% chance of winning $5M, or spin wheel 2 with a 50% chance of winning $50M, which one are you going to spin? The EV is higher on the second one, sure, but taking the near-certain 5M may still be a better choice - a bird in the hand is worth two in the bush.
Additionally, this group is said to do its research and adjust ransoms accordingly, so it seems likely that the ransom amount was a carefully thought out choice.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#277Earlier quoted context omitted.
> At a $5M payout there are essentially 0 commercial IT systems in the world that can stop such an attack. Even if that's true, it doesn't affect backups. Back your fucking systems up properly, and if you are attacked by ransomware, then do a scorched earth restore.
It absolutely does affect backups. If you stand to gain $5M from an attack you can also target the backup systems and still easily end up profitable. Only if you stand to gain less than $100k does the budget actually start to get tight. As for how you attack the backup system it depends. If it push based you send your payload during the push. If it is pull based you craft your payload in the data that will be backed…
Barring a Mr. Robot hack of the institution and Iron Mountain to burn the tapes the absolute worst-case scenario in a ransomeware attack on a financial institution is an afternoon of data lost.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#278It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
You don't need infosec staff to know that you should have backups of the data on your important computers/servers. Being hit by ransomware is not an indicator of total IT incompetence. Having no good options but to pay the ransom absolutely is. All ransomware is doing is exposing the existing hope-based DR plans (that is to say, lack thereof) in the industry.
Part of paying the ransom is the promise that the ransomer will not just unlock your system, but will also delete all the data they downloaded (which often includes a pile of PII that the ransomee doesn't want published).
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#279It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
You don't need infosec staff to know that you should have backups of the data on your important computers/servers. Being hit by ransomware is not an indicator of total IT incompetence. Having no good options but to pay the ransom absolutely is. All ransomware is doing is exposing the existing hope-based DR plans (that is to say, lack thereof) in the industry.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#280The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M