Live data from Hacker News

Colonial Pipeline Paid Hackers Nearly $5M in Ransom

bloomberg.com

411–420 of 524 posts

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#411

Earlier quoted context omitted.

I agree. I’d give 60% odds that there is at least one significant attack (ransomware plus shutdown) on US power grids in the next 18 months.

Basic game theory dictates that the cost of ransoms will continue to rise until it hits the price point at which the targeted company would have to replace its compromised systems from scratch. 5M, 50M, 500M, 5B, 50B? I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions

The government seems to have no problem with utilities doing this or worse to their own customers (PG&E, Texas power grid, Flint Michigan). But I guess if they could blame a foreign power that's an opportunity for a profitable war.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#412

Earlier quoted context omitted.

Yea, I think I tend to agree with you. It may cause a lot of pain in the short term, but being forced to pay penetration testers seems like it could be a net good in the long term for security in general. I don't think nation state attackers would be so kind as to un-fuck your system after they cripple it, even for a massive fee.

I don’t know. Did any of it matter? It was bad when people started hoarding gas. Just a few unfathomably stupid people - as always in this country. If idiots didn’t hoard gas, nothing would really have gone wrong. The preppers are the other side of the same coin. The only thing they seem to never run out of is toilet paper. Who the fuck cares? Pentesters have the same energy. They tell you about what software not to…

>If idiots didn’t hoard gas, nothing would really have gone wrong.

Maybe. But, I tend to lay the blame with the foreign criminals/adversaries who attacked us rather than a panicky handful of my fellow country people.

Not sure why some here are blaming the victims while giving the criminals a pass, and even thanking them as if unsolicited, live pentesting on critical infrastructure with a side order of extortion is a good thing.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#413

Earlier quoted context omitted.

Basic game theory dictates that the cost of ransoms will continue to rise until it hits the price point at which the targeted company would have to replace its compromised systems from scratch. 5M, 50M, 500M, 5B, 50B? I wonder how the government would react if a hacker group held gas/power/clean water/etc. hostage for millions of Americans for a ransom in the tens of billions

The government seems to have no problem with utilities doing this or worse to their own customers (PG&E, Texas power grid, Flint Michigan). But I guess if they could blame a foreign power that's an opportunity for a profitable war.

> The government seems to have no problem with utilities doing this or worse to their own customers (PG&E, Texas power grid, Flint Michigan).

The “utility" acting in Flint was state and state-imposed local government officials, 9 of whom have been criminally indicted for their role, so manifestly the government has something of a problem with it.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#414
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

I think you're kidding yourself if you think a company that gets "hacked" by off the shelf cryptoware is going to step up their game enough to have any chance of stopping a targeted state actor.

The fact they caved so quickly tells me they are years away from a reasonable security posture.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#415

Earlier quoted context omitted.

>If the US were to be serious about corporate IT security What happened to the responsibility of corporations for corporate security? Including corporations that are the victims of attacks, and corporations that sell buggy operating systems and applications? Why does the government have to provide the red teams? The general attitude is all government agencies are wasteful and incompetent, except in this circumstance…

Agree. The govt need not provide the teams as they must compete for talent like anyone else and don't have much to spare. The govt only has a relative abundance of talent [largely interspersed with its contractors] in highly regulated activites like making nuclear weapons, where private entities don't participate.

One of the functions of the government is to educate and train its population. I think using that function could resolve the shortage or high cost of talent.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#416
post #201

The fact this was paid off, and paid off so rapidly means that targeting major infrastructure for massive payoffs is going to become more and more prominent. The next time though, it'll be $50M. I work with people in the oil fields and I know the numbers they are playing with and the fact that a single well being down can easily be $100,000 lost per hour. So obviously they want these systems back up fast. $5M for shu…

I think these ransoms are net good. I'd rather greedy hackers shake them down for money then having the country get crippled by political terrorists or enemy nation states that can't be negotiated or reasoned with. There are lots of infrastructure management teams taking security more seriously than they were a month ago. That alone is worth more than $5M

I’d rather we pay the $5M in ransom, and then $5T to track the hackers down and eliminate them. Certainly someone died due to the pipeline shutdown. Eliminating the hackers would be fully justified.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#417

Earlier quoted context omitted.

I might agree if I had any faith that the people who paid this ransom would do any more than the bare minimum to close this one specific vulnerability and nothing else.

So they'll be out of business sooner or later then and a company that follows security best practices will take over ideally.

Yes, "ideally" that's what would happen. Do you really expect that to happen in practice?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#418
post #298

Earlier quoted context omitted.

Sounds like a $50m incentive to hire a security team.

From my experience. They will hire you but they won't pay your invoice until net-270

You're the second person who mentioned net-270 in this thread. What's the context?

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#419
post #25

Disclaimer: I work as a CISO in a large corporation. The interesting bit in this article is not necessarily the sum of the ransom, but that Colonial decided to pay quasi-immediately. It seems as if the attackers had full control over their network. Another possibility: Colonial staff could not be sure that if they used their backups, everything would be encrypted immediately again - possibly the backup servers as wel…

Having read the release by the attacker, my initial thought is that the immediacy of paying was probably due to the threat of the release of sensitive data, not the ability to restore operations. I’m sitting here wondering what exactly about the release of their financials and internal procedures prompted them to immediately pay $4-5m in the hopes of preventing it from happening?

If this is the case, then paying the ransom will turn out to be a stupid idea.

If the threat was to release sensitive information, surely the firm would be asking the attackers for details of the sensitive information they claim to have.

If the attackers come back with nothing then it was just a bluff.

However if the attackers come back with real information then paying the ransom is just stupid, as the attacker still have the sensitive information and can repeat the payment demands ad infinitum.

Re: Colonial Pipeline Paid Hackers Nearly $5M in Ransom

#420

Earlier quoted context omitted.

A price increase that effectively stops people from hoarding gas would be equally as effective at stopping people who need gas from affording it.

Addressing legitimate problems of hardship can be dealt with from the other end, by channeling resources to those people. In the mean time, higher prices mean that supply isn't interrupted, and for the vast majority of people that means that you don't fill up your car and your wife's car and your lawnmower and a 55gal drum, because it's not worth it. You just skip a few trips and let your gas tank get below half a ta…

By “theoretical people” I think you’re referring to a very sizable portion of the population.
Post reply on HN