Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

381–390 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#381

Earlier quoted context omitted.

The bigger the difference between the cost of the downtime and the ransom, the most likely it is to be paid. Assuming you were in a TV show, and offered two options: Spin wheel 1 with a 95% chance of winning $5M, or spin wheel 2 with a 50% chance of winning $50M, which one are you going to spin? The EV is higher on the second one, sure, but taking the near-certain 5M may still be a better choice - a bird in the hand…

Re. this group doing its research: one of my past employers got hit by a patent troll C&D demand, threatening to sue. It was clearly bogus but also clearly enough of a hassle that the company didn’t want to pick the fight if one could be avoided. Our clients were actually throwing their support behind us fighting it, offering their legal resources. But at the end of the day what the higher ups told us is that this pa…

Yeah, unfortunately the games that go into extortion mean that fighting back only makes sense (a) on such a long time scale that no one is considering it while being extorted, or (b) because it's the right thing to do.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#382
I thought that it was because the billing system wasn’t accessible and that the gas itself wasn’t affected (the actual infrastructure). Yes, still very bad, but it seems there should be contingency plans for this sort of thing.

1. One primary source of gas for the Eastern sea board? Wtf?

2. The TSA overseas pipelines (lower standards and poor oversight) whereas electricity is regulated by the Dept of Energy? What the actual fucK? Nothing against then TSA but shouldn’t they focus on transportation security?

3. They didn’t have a director of cyber security and are now recruiting? If you’re running critical infrastructure shouldn’t you be putting a few dollars into this sort of thing already?

What a cluster fuck.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#383

Earlier quoted context omitted.

I agree. I’d give 60% odds that there is at least one significant attack (ransomware plus shutdown) on US power grids in the next 18 months.

Taking out a fuel pipeline in non-heating months seems a lot less likely to cause casualties than downing a power grid. Dead people get different responses than theft, even massive theft. Also, knowing how scary oil companies are, I wouldn't be surprised if some people turned up dead over the colonial hack. Even if they get the attribution wrong, a dead hacker group would have a chilling effect on such activities.

As per reports the ransomware had no effect in any of the physical pumping/operational systems required to pump/operate the pipeline, it only affected their billing system and they stopped pumping because later it would have difficult to reconcile the billing for it, not because the ransomware disabled the pumps.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#384

I hear online that the ransomware had no effect on the Colonials ability to physically pump the oil, it affected only its billing systems, but they stopped pumping anyway because it would have been difficult to reconcile the accounting/billing if they continue to operate without the billing system being live. Is this true?

The far more plausible story that I've heard: it had no effect on the control network because there's only one-way communication, but the one-way was only enforced at software level, so they weren't taking chances with leaving it up and having the control network compromised.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#385
There is an axiom to never negotiate with terrorists. While we all know that isn’t always entirely true, let’s recognize that this payout will be considered a turning point.

Regardless whether or not you believe ransomware should be paid, my takeaway is that these ransomware attacks have done more for promoting “cyber security” than all the marketing budgets of every security vendor combined. If you’re employed as a security engineer or thinking about getting into the industry, there has never been a better time to ask for more money and more authority.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#386

Earlier quoted context omitted.

Too grandiose a word for a targeted assassination of a handful of folks.

Not if the hacker group is a nation state. Sure, small time hacking is cute and all, but the US isn’t going to just roll over and be all like “oh no, you hit critical infrastructure that had a big impact on peoples life. Carry on”

Even this time too government was aware that Colonial paid the Ransom. The question was asked in the Whitehouse press breifing, it was told that this is essentially a private sector matter, Government will not advice Colonial in this regard. Also they said it was Colonial's prerogative to decide and act.

Transcript of Whitehouse Press Briefing: https://www.whitehouse.gov/briefing-room/press-briefings/202...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#388

Reminder that these same clowns have leaked over a million gallons of gasoline into a nature preserve in North Carolina. https://www.eenews.net/stories/1063725961

I really want to be supportive of pipelines as a better option than trains or trucks, but it's really hard to do when things like this don't result in enormous payouts against these companies.

The US legal system is not capable enough to allow for large pipelines.

Also, this and coal are the sort of stuff that nuclear replaces...

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#389
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

It's kinda the opposite scenario. The hackers knew they were willing to pay more but didn't actually want to cause this much attention and so lowballed so they'd quickly pay. At least according to https://finance.yahoo.com/news/colonial-pipeline-paid-hacker... Krehel (chief executive officer and founder of digital forensics firm LIFARS and a former cyber expert at Loews Corp) said a $5 million ransom for a pipeline w…

Yup. They start doing this kind of damage, and they can start to expect the wrong kind of attention -- a kinetic response, as in cruise missile into the upper left window, circular error probable = 50cm., or similar.

Unless Vlad starts frowning on this behavior, which persists at his pleasure, it may take that (or a seriously escalatory cyber response) to lower the threat to acceptable levels.

Post reply on HN