It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…
I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…
DarkSide ransomware gang quits after servers, Bitcoin stash seized
81–90 of 623 posts
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#82It was a mistake to attack the business side of the oil company, because it created what could be sold as reasonable doubt to shut down the pipeline. As a result, the ransom had the optics of an attack on infrastructure. As evidenced by the coverage of Americans desperately filling up containers. This created the impetus for the US to treat this as an incident far and above the ambient ransomware activities leading u…
I think the question is, how come an attack on a hospital does not have the optics of an attack on infrastructure? (It almost seems oil does not require infrastructure - you can, theoretically, prep for an oil infrastructure outage by storing it containers, same as you do with water and food. But you can't really prep for a medical infrastructure outage. Is it just that, as a result, there were no photos of people ho…
An attack on a hospital affects someone if they work there or are using that hospital. A pipeline attack affects people who drive cars places and need gas. The latter group is much larger than the former.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#83> The REvil representative said its program was introducing new restrictions on the kinds of organizations that affiliates could hold for ransom, and that henceforth it would be forbidden to attack those in the “social sector” (defined as healthcare and educational institutions) and organizations in the “gov-sector” (state) of any country. Affiliates also will be required to get approval before infecting victims. Sta…
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#84Seems like they should invest more into cybersecurity, if someone was able to “steal” their Bitcoin and take over their infrastructure ;). But honestly, this only shows that IT systems are nowadays so complex that you cannot get them right and be able to truly protect you, no matter if you’re good or bad guy.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#85Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…
it can be harder to trace, but the bigger problem is trying to turn it into cash, which is hard to do anonymously regardless of the currency used (BTc, XMR, etc). THe FBI,Secret Service, are mostly focused on the conversion of crypto to cash, not the intermediary steps.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#86Earlier quoted context omitted.
When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."
Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#87Earlier quoted context omitted.
When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."
Well, if it's more expensive to prevent the attack than to pay the ransom, what's the point? ;)
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#88Can crypto actually be non-traceable? I remember currencies like Monero or ZCash advertising privacy from the last crypto craze. I mean if you have 100M in some account, can you actually run it trough "private" currencies to remove traces? BTC, ETH etc. all seems super traceable, even more so than in regular banking. Also how are criminals getting their money out with no one noticing, does Panama/Malta etc. have Krak…
Each localbitcoins account can trade up to $200k a year without any kind of in-person verification.
Also a lot of exchanges let you cash out via western union so... you could theorically send yourself say 10k or 20k a a month with that, there's no need to just withdraw it all at once.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#89Earlier quoted context omitted.
Nope. Monero is actually private and untraceable.
Until someone cracks it, that is. If it becomes the crypto of choice for some of the bigger fish, you can bet the government will find a way to trace it.
There is a literal virtual tumbler built into the transaction protocol called ring signatures.
Stealth addresses (an additional crypto key pair) obfuscate senders and receivers.
They also hide the amount transferred which blew my mind.
Re: DarkSide ransomware gang quits after servers, Bitcoin stash seized
#90Earlier quoted context omitted.
When I heard that this pipeline company started advertising a job opening for CyberSecurity Advisor in the last few days, and heard today the ransom of about $5 million was paid, my first reaction was to say "I bet the salary for that position is a lot less than $5 million, and I bet the budget for that department will be less, too..."
I think you're spot-on here - the ransom is seen as a "cost of doing business", and until recently security was seen as "a problem that happens to other people". Sadly my experience is that organisations like this will take their $5m ransom (or other remediation cost), assume it's a one-off, then divide it by their number of ransom-free years, and proclaim it was better value for money than hiring 2 or 3 senior secur…