Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

301–310 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#301
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

I'd agree. But I would be surprised to see that level of action. At least for the next while. Considering the payment time on an invoice is averaging 270 days now. I would be surprised if they moved on this.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#302

Earlier quoted context omitted.

The bigger the difference between the cost of the downtime and the ransom, the most likely it is to be paid. Assuming you were in a TV show, and offered two options: Spin wheel 1 with a 95% chance of winning $5M, or spin wheel 2 with a 50% chance of winning $50M, which one are you going to spin? The EV is higher on the second one, sure, but taking the near-certain 5M may still be a better choice - a bird in the hand…

The difference in actual value between the two for me at least is much smaller than the difference in numerical value. Both amounts are enough for me to never work another day in my life, and instead focus on building what I want to build. Past that massive increase in quality of life extra money is relatively meaningless (to me) . This is the same reason that people who decry spending money on lottery tickets as a s…

Off topic, but I'm curious: What do you want to build and why can't you start building it now?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#303
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

It's kinda the opposite scenario. The hackers knew they were willing to pay more but didn't actually want to cause this much attention and so lowballed so they'd quickly pay.

At least according to https://finance.yahoo.com/news/colonial-pipeline-paid-hacker...

    Krehel (chief executive officer and founder of digital forensics firm LIFARS and a former cyber expert at Loews Corp) said a $5 million ransom for a pipeline was “very low.” “Ransom is usually around $25 million to $35 million for such a company. I think the threat actor realized they stepped on the wrong company and triggered a massive government response,” he said.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#304
post #297

I don't have much to add here, but I've been going to Def Con and the other Las Vegas security conferences for a few years. Every year there is a section for infrastructure security (factories, refineries, etc). Its always the smallest section and the least populated. But its simultaneously the "most important" in terms of how much damage can be done from a single attack. Every year I went and was always terrified by…

It sounds like it may have just been the billing system that was hacked, not the infrastructure. I've seen similar patterns and so I was surprised by this.

Don't matter if they lock your computer access out and encrypt all the data, ransomware is installed.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#305
post #66

It should be noted that Colonial had several infosec openings at the time of the attack. While having those filled might not have prevented this attack, it also might have or at least put them in a better response position. There are lots of infosec openings across the country but compensation doesn't seem to be rising in response. It appears that companies are fine with leaving these positions open for long periods…

You don't need infosec staff to know that you should have backups of the data on your important computers/servers. Being hit by ransomware is not an indicator of total IT incompetence. Having no good options but to pay the ransom absolutely is. All ransomware is doing is exposing the existing hope-based DR plans (that is to say, lack thereof) in the industry.

I used to deploy backup systems, and I had to explain to many customers that data protection is a security feature also. Very few "got" this.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#306
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

I think that would only be true if you thought it possible to obtain perfect security, but we’ve seen that even air-gapped systems are vulnerable to nation states motivated enough, and exploits are always laying in wait. This gets some bugs patched - but it also illustrates US infrastructure weaknesses to others.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#307
post #133
post #100

Earlier quoted context omitted.

A greyhat should launch ransomware and then not decrypt when the ransom is paid. Make the ransomware industry unreliable.

This is the chaotic evil way of dealing with the problem

Wouldn't it be chaotic neutral?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#308
I love the idea of sprinkling bitcoin private keys in text files around your infrastructure, so any hacker that gets access can take the funds, but you'll be alerted to it and can quarantine the box and investigate the intrusion. Maybe include "Email us with a write up of how you got in and a bitcoin address, and we'll send more bitcoin based on how helpful it was"

Rotate the keys periodically and sweep all unstolen bitcoin into a bonus fund split between everyone who had access to the machines which held the private keys. Give devops real skin in the game for keeping boxes secure.

Could also develop a convention for deriving private keys from security secrets - make it so if someone gets your AWS root key, they can test the credentials to see if the company has offered a enough funds that they are willing to announce (and thus burn) their access by transferring those funds away. I wonder if you could 'license' these coins in a way that it would be legal (or at least more-legal) to take them without prior consent: if there was a legal means to monetize 'misplaced' credentials many hackers might choose that over the legally riskier and less-moral traditional alternatives.

Credential rotation would certainly be more fun if it meant I was going to get a bonus!

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#309

Earlier quoted context omitted.

You do not need actual disruptions in supply to create a shortage. The threat of a disruption or a shortage for such a critical commodity can create a situation that it becomes a self fulfilling prophecy (short term). That is what can often create bank runs and created the "great toilet paper shortage of 2020".

But the pipeline has been closed: https://abc11.com/business/theres-plenty-of-gas-in-the-us-th... And the toilet paper shortage was not purely panic-driven. People did shit at work before the pandemic, and that part of demand switched to a different supply chain. The panic-induced bullwhip was probably stronger than the original demand spike, but the whole thing wasn't just memed into existence.

The pipeline was shut down as a preventive measure (we're being told) just in case the attackers had made their way into the control systems. Trucking of gas has been increased to compensate for the closure of the pipeline, and there was emergency legislation passed in Congress to lift regulations that would have prevented these higher levels of trucking. The gas supply has been just fine here in the Northeast; the issues I've heard about have been in the South and Southeast due to panic buying (in areas of the country that shouldn't have been negatively affected by the closure of the TX->NY pipeline).

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#310

Per the Boston Globe story [0] they were actually in the process of restoring from backups but it was going too slow. Something to remember: when downtime is so critical that key pieces of a country's infrastructure is at stake, backups can't be enough-- there also has to be a rapid recovery plan to actually use them. [0] https://www.bostonglobe.com/2021/05/13/business/colonial-pip...

TFA says the opposite - that backups are faster than the decryption tool supplied by the hackers. Would you run a tool supplied to you by the hackers on your network? This thing could be scrubbing, adding backdoors, really anything.

>Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said.

Post reply on HN