The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
Colonial Pipeline Paid Hackers Nearly $5M in Ransom
301–310 of 524 posts
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#302Earlier quoted context omitted.
The bigger the difference between the cost of the downtime and the ransom, the most likely it is to be paid. Assuming you were in a TV show, and offered two options: Spin wheel 1 with a 95% chance of winning $5M, or spin wheel 2 with a 50% chance of winning $50M, which one are you going to spin? The EV is higher on the second one, sure, but taking the near-certain 5M may still be a better choice - a bird in the hand…
The difference in actual value between the two for me at least is much smaller than the difference in numerical value. Both amounts are enough for me to never work another day in my life, and instead focus on building what I want to build. Past that massive increase in quality of life extra money is relatively meaningless (to me) . This is the same reason that people who decry spending money on lottery tickets as a s…
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#303The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
At least according to https://finance.yahoo.com/news/colonial-pipeline-paid-hacker...
Krehel (chief executive officer and founder of digital forensics firm LIFARS and a former cyber expert at Loews Corp) said a $5 million ransom for a pipeline was “very low.” “Ransom is usually around $25 million to $35 million for such a company. I think the threat actor realized they stepped on the wrong company and triggered a massive government response,” he said.Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#304I don't have much to add here, but I've been going to Def Con and the other Las Vegas security conferences for a few years. Every year there is a section for infrastructure security (factories, refineries, etc). Its always the smallest section and the least populated. But its simultaneously the "most important" in terms of how much damage can be done from a single attack. Every year I went and was always terrified by…
It sounds like it may have just been the billing system that was hacked, not the infrastructure. I've seen similar patterns and so I was surprised by this.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#305It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…
You don't need infosec staff to know that you should have backups of the data on your important computers/servers. Being hit by ransomware is not an indicator of total IT incompetence. Having no good options but to pay the ransom absolutely is. All ransomware is doing is exposing the existing hope-based DR plans (that is to say, lack thereof) in the industry.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#306The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…
I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#307Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#308Rotate the keys periodically and sweep all unstolen bitcoin into a bonus fund split between everyone who had access to the machines which held the private keys. Give devops real skin in the game for keeping boxes secure.
Could also develop a convention for deriving private keys from security secrets - make it so if someone gets your AWS root key, they can test the credentials to see if the company has offered a enough funds that they are willing to announce (and thus burn) their access by transferring those funds away. I wonder if you could 'license' these coins in a way that it would be legal (or at least more-legal) to take them without prior consent: if there was a legal means to monetize 'misplaced' credentials many hackers might choose that over the legally riskier and less-moral traditional alternatives.
Credential rotation would certainly be more fun if it meant I was going to get a bonus!
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#309Earlier quoted context omitted.
You do not need actual disruptions in supply to create a shortage. The threat of a disruption or a shortage for such a critical commodity can create a situation that it becomes a self fulfilling prophecy (short term). That is what can often create bank runs and created the "great toilet paper shortage of 2020".
But the pipeline has been closed: https://abc11.com/business/theres-plenty-of-gas-in-the-us-th... And the toilet paper shortage was not purely panic-driven. People did shit at work before the pandemic, and that part of demand switched to a different supply chain. The panic-induced bullwhip was probably stronger than the original demand spike, but the whole thing wasn't just memed into existence.
Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom
#310Per the Boston Globe story [0] they were actually in the process of restoring from backups but it was going too slow. Something to remember: when downtime is so critical that key pieces of a country's infrastructure is at stake, backups can't be enough-- there also has to be a rapid recovery plan to actually use them. [0] https://www.bostonglobe.com/2021/05/13/business/colonial-pip...
>Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said.