Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

291–300 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#291

Colonial is being widely lambasted for a culture of absolutely lackadaisical security. Call me callous but numerous federal agencies exist to issue security best practices and exploit announcements. numerous vendors also exist. play stupid games, win stupid prizes. Not paying the ransom would have been tantamount to complete dissolution of the company. it would have tirggered a much wider investigation into the compa…

> paying the ransom puts their shareholders at risk of serious sanctions and indictment from the US Dept. of the Treasury

This (almost certainly) isn't true. It may put management at risk of sanctions, but shareholders are shielded by the corporate veil.

I say "almost certainly" because in some cases prosecutors can go after shareholders, but this is limited to cases where a specific shareholder is involved in decision making.

https://en.wikipedia.org/wiki/Piercing_the_corporate_veil#Un...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#292

Earlier quoted context omitted.

The bigger the difference between the cost of the downtime and the ransom, the most likely it is to be paid. Assuming you were in a TV show, and offered two options: Spin wheel 1 with a 95% chance of winning $5M, or spin wheel 2 with a 50% chance of winning $50M, which one are you going to spin? The EV is higher on the second one, sure, but taking the near-certain 5M may still be a better choice - a bird in the hand…

The difference in actual value between the two for me at least is much smaller than the difference in numerical value. Both amounts are enough for me to never work another day in my life, and instead focus on building what I want to build. Past that massive increase in quality of life extra money is relatively meaningless (to me) . This is the same reason that people who decry spending money on lottery tickets as a s…

> The difference in actual value between the two for me at least is much smaller than the difference in numerical value.

That was exactly one of the reasons why I showed that example.

While this may be different for a gang that has to split the money N ways, the "bird in the hand" might still be worth the two (or ten) in the bush, due to this or other factors.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#293
post #125
post #83

In Cambodia, people buy dirt to increase their property’s elevation so that their neighbor’s house floods when the monsoon comes. Then the neighbor has to pay for more dirt and so on throughout the whole neighborhood. It seems like the attackers are finding the paths of least resistance. Beefing up security at each organization isn’t fixing the underlying problem. It’s just making the next entity the more likely targ…

Suppose that everyone has raised their house up on a pile of dirt. The rain comes down. It fills up the large ditches between people's houses, and leaves the houses dry. Suppose I implement better, but imperfect, security. It now costs an attacker $6 million, in salaries, paying for exploits, whatever, to hack my system. They still can only get $5 million in ransom. The attack isn't worth doing anymore, so they find…

I don't think you understand how dirt works. Especially when it gets rained on.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#294
post #25

Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if the attackers had full control over their network. Another possibility: Colonial staff could not be sure that if they used their backups, everything would be encrypted immediately again - possibly the backup servers as wel…

If the attackers had full access, they probably broke into the financial systems, issued the bitcoin transactions and paid themselves directly. I mean, why bother going through the hassle of trying to teach people how to do all of that stuff?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#295
post #245

Earlier quoted context omitted.

It absolutely does affect backups. If you stand to gain $5M from an attack you can also target the backup systems and still easily end up profitable. Only if you stand to gain less than $100k does the budget actually start to get tight. As for how you attack the backup system it depends. If it push based you send your payload during the push. If it is pull based you craft your payload in the data that will be backed…

I can’t speak for other industries but in the financial industry (in the US at least) periodic backups are required on physical tapes both off- and on-site. Barring a Mr. Robot hack of the institution and Iron Mountain to burn the tapes the absolute worst-case scenario in a ransomeware attack on a financial institution is an afternoon of data lost.

You just hack the machines that are loading the data onto the physical tapes or the system that is collecting the data to put onto the tapes. Essentially, at some point the data goes from where it is being used to the tapes and you just takeover one of the systems in that pathway. You then wait for 6 months silently encrypting the data before you make your demands. Now the absolute worst case is that 6 months of data is lost or however long you were hiding. Industry studies indicate that the average time between infiltration and detection of an agent actively exfiltrating data is a few months, so a few months for an agent not even pushing data out over the network, just silently corrupting data going to your off-site backups that you are not looking at is very reasonable.

Backups are not the end of the story unless you are dealing with attackers with only $10k to their name which is essentially what everybody without backups is losing their minds over and being defeated by. That is a literal rounding error of a rounding error of a rounding error for the financial industry. People spend more on lunch than that. A moderately sophisticated attack with a few million behind it is literally 100x the resources of most of these attacks and that is still just a microscopic pittance compared to the financial industry. Think about that, if you want to reach the $1M level you need a system that can defend against an adversary with 100x the resources of a basic ransomware attack. The gap is so large that the capabilities fundamentally change and intuition for how to defeat a $10k attack does not generalize.

And, we have not even considered a system that would even be considered barely adequate for the financial industry. If you want to get to something barely adequate for the financial industry, like say protecting against an attack funded to a level comparable to one day of disrupted operations for JP Morgan, you would need to protect against an attack on the order of $500M, literally 500x more than those "good" systems and 50,000x better than these basic systems. The gaps are ludicrous and the lessons at one scale do not really apply when you go up another 2 or 4 orders of magnitude.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#297

I don't have much to add here, but I've been going to Def Con and the other Las Vegas security conferences for a few years. Every year there is a section for infrastructure security (factories, refineries, etc). Its always the smallest section and the least populated. But its simultaneously the "most important" in terms of how much damage can be done from a single attack. Every year I went and was always terrified by…

It sounds like it may have just been the billing system that was hacked, not the infrastructure.

I've seen similar patterns and so I was surprised by this.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#298
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

Sounds like a $50m incentive to hire a security team.

From my experience. They will hire you but they won't pay your invoice until net-270

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#299

Earlier quoted context omitted.

What I have heard regarding ransoms like these is that the perpetrators goal is to incentivize the transaction goes smoothly, or it won’t continue to work. So they have to follow through with unlocking and they have to use an amount of money low enough to make the decision obvious.

Well from the article, the decryption tool was so slow they kept using backups along with it. Sounds like future hackers need to improve their decryption tools, or companies where speed matters (like utilities) won't bother paying.

This was the error yeah.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#300
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

The bigger the difference between the cost of the downtime and the ransom, the most likely it is to be paid. Assuming you were in a TV show, and offered two options: Spin wheel 1 with a 95% chance of winning $5M, or spin wheel 2 with a 50% chance of winning $50M, which one are you going to spin? The EV is higher on the second one, sure, but taking the near-certain 5M may still be a better choice - a bird in the hand…

Re. this group doing its research: one of my past employers got hit by a patent troll C&D demand, threatening to sue. It was clearly bogus but also clearly enough of a hassle that the company didn’t want to pick the fight if one could be avoided. Our clients were actually throwing their support behind us fighting it, offering their legal resources. But at the end of the day what the higher ups told us is that this patent troll was “very professional. They did their research on us and know exactly how much we can afford or pay them without going out of business.” So we ended up paying and I guess it all worked out ok from there.
Post reply on HN