News: 1620927851

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ransomware victim Colonial Pipeline paid $5m to get oil pumping again, restored from backups anyway – report

(2021/05/13)


Colonial Pipeline's operators reportedly paid $5m to regain control of their digital systems and get the pipeline pumping oil following last week's ransomware infection.

News of the payoff was [1]broken by Bloomberg – which not only cited anonymous sources but also mocked other news outlets' anonymous sources for saying earlier this week that the American pipeline operator would never pay the ransom.

"On Wednesday, media outlets including the Washington Post and Reuters reported that the company had no immediate intention of paying the ransom. Those reports were based on anonymous sources," gloated Bloomberg, while avoiding describing its unnamed "people familiar with the company's efforts" in the same terms.

Very generally speaking, when you see "people familiar with the matter" or words to that effect in US news coverage, it means someone at an organization – typically a PR or a high-level exec – briefed the journalist on background, meaning the hack can use the information but not attribute it to anyone or anything in particular

Media braggadocio aside, the Colonial Pipeline Company of Georgia is said to have paid $5m as a ransom to regain control of its systems. Bloomberg claimed, citing its familiar-yet-anonymous sources, that the decryption utility supplied by the criminals following this payment was so slow in operation that Colonial continued restoring its systems from backups, as it has been since the weekend.

Restoring from good, working backups isn't such a bad idea, because you should wipe infected computers and start afresh anyway, just in case the ransomware hid something nasty on the file systems.

[2]

[3]

[4]

Speculation abounded as to precisely what led to the shutdown of the pipeline on Friday, May 7 though the most likely explanation is that rather than compromising the operational technology (OT) controlling the pipeline's pumps and valves, the ransomware KO'd back-office systems used for monitoring oil flows and generating billing records based on those flows.

If you can pump oil but can't tell who you're pumping it to or how much they're taking, your oil-as-a-service business will miss out on significant profits and your engineers will rapidly lose sight of how much wear and tear safety-critical systems are enduring. Hence the shutdown.

The Colonial Pipeline says it carries 100 million gallons a day of refined fuels between Houston, Texas, and New York Harbor, or 45 percent of all fuel needed on the United States' East Coast. The pipeline carries fuel for cars and trucks, jet fuel, and heating oil, and there are [5]reports of gasoline shortages. Today, the biz said it had restarted operations on Wednesday evening, and is now making "substantial progress" in delivery supplies to markets.

[6]

The Colonial Pipeline company's website was offline at the time of writing, returning this error message. Click to enlarge if this interests you that much

Brett Callow of specialist anti-ransomware firm Emsisoft told The Register that the reported payoff was relatively small, saying: "The highest demand to have become publicly known is $50m and, given the massive disruption this incident is causing and its cost implications, $5m seems surprisingly modest. Still, if it really has been paid, it'll certainly help keep critical infrastructure in the ransomware gangs' crosshairs. If a sector proves to be profitable, they'll attack it again and again and again."

[7]Colonial Pipeline was looking to hire cybersecurity manager before ransomware attack shut down operations

[8]South Korea orders urgent review of energy infrastructure cybersecurity

[9]US declares emergency after ransomware shuts oil pipeline that pumps 100 million gallons a day

[10]Happy to pay out to ransomware masterminds? Yup, we thought so

Colonial was [11]hiring a new cybersecurity manager a month ago. Whoever gets that gig probably has a very interesting few days ahead of them.

The ransomware gang operates under the moniker Darkside and is tracked by Western infosec companies under at least a dozen different names. It is said to have been active since August last year and to have been responsible for around 80 compromises so far. When the pipeline stopped last week, and the FBI [12]got involved , the Russian-speaking criminals behind the crew issued a statement via their Tor-hosted blog claiming they were just doing business and had no ulterior motive.

[13]

Translated, this seems to have been a desperate plea to the powers-that-be in their Russian-speaking homeland not to track them down and send them to the gulag for triggering international attention after knocking out a piece of critical technology supplying the US East Coast's liquid hydrocarbon needs. ®

Get our [14]Tech Resources



[1] https://www.bloomberg.com/news/articles/2021-05-13/colonial-pipeline-paid-hackers-nearly-5-million-in-ransom

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJ2heecV@iefDawMCck4VAAAAMA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJ2heecV@iefDawMCck4VAAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJ2heecV@iefDawMCck4VAAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.usatoday.com/story/money/2021/05/12/gas-shortages-colonial-pipeline-attack-affect-you/5054294001/

[6] https://regmedia.co.uk/2021/05/13/colonial_pipeline_website.jpg

[7] https://www.theregister.com/2021/05/13/colonial_pipeline_hiring_cybersecurity_manager/

[8] https://www.theregister.com/2021/05/12/south_korea_security_review/

[9] https://www.theregister.com/2021/05/10/colonial_pipeline_ransomware/

[10] https://www.theregister.com/2021/05/12/learn_to_frustrate_modern_ransomware/

[11] https://www.theregister.com/2021/05/13/colonial_pipeline_hiring_cybersecurity_manager/

[12] https://www.fbi.gov/news/pressrel/press-releases/fbi-statement-on-compromise-of-colonial-pipeline-networks

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJ2heecV@iefDawMCck4VAAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/

Phew. Glad I'm no longer in I T

TVC

So glad I no longer work in I T. I'd be heading for a nervous breakdown.

There's money in

Andy Non

oil ransomware. Way to go to encourage more of it.

$5 million for criminals

Pascal Monett

Well guys, looks like you can now budget $10 million for your backup procedures, because they'll be back in a quarter or two and you obviously need to lock down your backup procedures to something a bit more robust.

And there should be a fine of 10 times your blackmail money to prevent this kind of thing from happening.

Re: $5 million for criminals

lglethal

Easy. Make the law state that any ransomware payment must be deducted directly from the CEO's salary. And he may not be reimbursed or receive any salary increase for the next 5 years.

We would never see another payment made, I guarantee that!

Re: $5 million for criminals

TomPhan

In reality the CEO will be in line for an increased bonus due to the brave and courageous leadership shown during this time of crisis.

Re: $5 million for criminals

Jon 37

Paying a ransom is aiding and abetting computer hackers. You're also funding them to do more hacks. People who pay should be subject to criminal charges and thrown in prison.

Criminal to pay Criminals?

cosymart

I thought that in most jurisdictions it's illegal to give criminals money especially for blackmail?

Re: Criminal to pay Criminals?

Anonymous Coward

Insurance rewards for stolen high value property are quite common.

It's often illegal to pay a ransom to terrorist organizations

Ransomware pays ..... See !!!???

Anonymous Coward

This is why ransomware is taking over the internet.

It pays so well and if you can advertise how successful your 'Ransomware as a Service' is, it will pull in even more business selling on the 'skills' to get even more on a 'franchise' basis.

Companies that pay should be unable to get company insurance in future, as they are increasing the costs and risks for everyone else.

Maybe, the warnings and requests for funding to protect the companies infrastructure/data from these threats will be taken more seriously ....... no silly me .... of course not, as the threat only impacts others !!!!! :)

Just a thought, the next big target should be the Bank accounts of the people that are successfully getting paid for this stuff.

More money for each hit and they are not likely to complain to the Bank/Police if someone hacks them.

You only need to worry about the FSB or SVR [Not sure where one ends and the other starts :) ] and Putin wanting the money back !!! :)

They need a deep anal probe of their staff

fredesmite2

... how this crap got inside .. and which poorly educated #TrumpTrash opened a email on an unpatched Windows desktop,

Re: They need a deep anal probe of their staff

Korev

You mean a penetration test?

The entire IT and " security " team

fredesmite2

needs fired

Re: The entire IT and " security " team

alain williams

Let's first find out which bean counter refused extra funding to beef up security and backups.

News this AM said there was no payoff

fredesmite2

spox on CNN no money was paid

Pretty cool though

tojb

Russian hacker gang.... called “Darkside”... takes down oil supply to the eastern US.... I feel like I’ve already seen a bunch of movies like this.

You think this is bad

Anonymous Coward

Die Hard 4.0 was optimistic.

It seems that nuclear and hydro power plants have exposed SCADA systems, requiring some ridiculously simple techniques like phoning a non listed number with the right guessed extension to gain access.

Sure its not "exposed to the Internet" as such but with the right credentials and a suitably modified laptop with freely downloaded demo software can get you access to things like the ECCS and cause all kinds of mayhem.

Fortunately settled for proof of concept, and AFAICT no harm was done but the point is if someone had malicious intent they could potentially bring down the entire grid for weeks just by feeding the software plausible-but-bad values.

My last experiment got me access to people in the know at an undisclosed location, who actually were aware of uh, "things" and were astonished how one individual could access their secure phone network without even a verification step so settled for a brief technical discussion and left it at that.

All truths are true to an extend, including this one. -XA