'I put the interests of the country first': Colonial Pipeline CEO on why oil biz paid off ransomware crooks
- Reference: 1623256090
- News link: https://www.theregister.co.uk/2021/06/09/old_vpn_colonial_pipeline/
- Source link:
Speaking yesterday before the [1]Senate Homeland Security Committee , Joseph Blount was quizzed about the incident before it became clear that a poorly secured legacy VPN was to blame.
[2]Fastly 'fesses up to breaking the internet with an 'an undiscovered software bug' triggered by a customer
[3]Doncaster insurance firm One Call hit by not-dead-at-all Darkside ransomware gang
[4]Eufycam Wi-Fi security cameras streamed video feeds from other people's homes
[5]Colonial Pipeline was looking to hire cybersecurity manager before ransomware attack shut down operations
Last week, Charles Carmakal, senior VP at cybersecurity firm Mandiant, which responded to the incident, [6]revealed in an interview , that crooks accessed Colonial Pipeline's network using an old VPN and password thought to have fallen into the wrong hands via the dark web, although investigations are still ongoing.
Speaking yesterday, Blount added that the password used to gain access to the VPN was "complex" – it wasn't just "colonial123", he told the hearing.
Giving an account of the events surrounding the 7 May [7]cyberattack , Blount said he had no choice but to pay up once the scale of the breach was known.
[8]
"I know how critical our pipeline is to the country," Blount said in the hearing, "and I put the interests of the country first."
[9]
He went on: "I made the decision to pay, and I made the decision to keep the information about the payment as confidential as possible.
"It was the hardest decision I've made in my 39 years in the energy industry."
[10]
The operators of the Colonial Pipeline – which stretches 5,500 miles between Texas and New York, and can carry up to 3 million barrels of fuel per day – reportedly paid $5m to regain access to their systems.
As El Reg reported, the [11]Department of Justice on Monday said it has recovered 63.7 Bitcoins , right now worth $2.1m and falling, of the 75 or so BTC the Colonial Pipeline operators paid the ransomware miscreants who infected the fuel provider's computers. You can watch footage of the hearing [12]here . ®
Get our [13]Tech Resources
[1] https://www.hsgac.senate.gov/hearings/threats-to-critical-infrastructure-examining-the-colonial-pipeline-cyber-attack
[2] https://www.theregister.com/2021/06/09/fastly_explains_web_blackout/
[3] https://www.theregister.com/2021/05/21/darkside_ransomware_doncaster/
[4] https://www.theregister.com/2021/05/17/in_brief_security/
[5] https://www.theregister.com/2021/05/13/colonial_pipeline_hiring_cybersecurity_manager/
[6] https://www.bloomberg.com/news/articles/2021-06-04/hackers-breached-colonial-pipeline-using-compromised-password
[7] https://www.theregister.com/2021/05/10/colonial_pipeline_ransomware/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YME5-UcXa7bANyQqxqoSfAAAAJc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YME5-UcXa7bANyQqxqoSfAAAAJc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YME5-UcXa7bANyQqxqoSfAAAAJc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.theregister.com/2021/06/08/antiransomware_task_force/
[12] https://www.hsgac.senate.gov/hearings/threats-to-critical-infrastructure-examining-the-colonial-pipeline-cyber-attack
[13] https://whitepapers.theregister.com/
Re: Er ...
Oilpipelinebatterystaple
Re: Er ...
Colonial1!
Has upper and lower-case letters, numbers, and symbols.
Re: So "Coloni4l123!" then?
No, the password was, literally the string "complex". It says so right there in the article :-)
Re: So "Coloni4l123!" then?
Speak friend, and enter?
Re: So "Coloni4l123!" then?
Maybe it was "1complexpassword" - but most likely it was something like GJt75$fhSwE09^ but written down on a sticky note attached to the underside of the keyboard because good safe passwords are very hard to remember... If I was in the malware business I would be financing an office cleaning company...
I put the interests of the country first
Ahead of shareholders?
Isn't that the very definition of communism ?
Re: I put the interests of the country first
What's good for GM^H^H Continental Pipeline is good for the country
I Regret that I Have Only One Country to Give for My Money!
The hackers didn't shut down the pipeline. The hackers hacked the billing system. Colonial shut down their own pipeline because they couldn't bill their customers.
That's what I call "Putting the Country First".
Also: Using a "legacy VPN", reusing passwords, and no recovery infrastructure is a security plan. Got it.
Many of you know just how cheap corporate types are when it comes to IT and security. There will be more like this, unfortunately.
The Big Lie
Colonial will keep saying that they Did The Right Thing to drown out the voices saying "Errrm, no...".
SCADA-BOOM!
It isn't only the billing system
It isn't a single pipe from point A to point B. It is a huge number of pipes that go to a lot of places and carry a lot of different stuff like various grades of gas, jet fuel, and other products. They have to know what to send where, and their internal systems manage that as well.
It isn't as simple as "they should have just turned it on and made everything free"
Re: It isn't only the billing system
Fair enough. So, what could they realistically do without the system? I don't want to just jump on people, but it sounds like they were at fault for not securing their systems. I was sort of hoping to hear more from knowledgeable industry types in this publication. So far it's only us in the peanut gallery giving Bronx Cheers.
They, and other similarly situated companies hold our lives in their hands. Ask Texans, who froze to death when their power went out because companies went cheap by not protecting their turbines against freezing, after they had been warned. This is a common problem.
I've been reading about the threat to SCADA and industrial systems for years. What's being done? People seem to wait until the "Big One" to do something.
Re: It isn't only the billing system
Worse, the systems were almost secure, leading to a bit of complacency. If you read the neighboring story about Identity and Access Management, you'd know how difficult it is maintaining a list of every VPN and other hole in Hadrian's Wall that let those annoying Pictsies in. Oopsie!
It's a pretty standard response to go on lockdown when a breach is suspected, so I don't blame Colonial for their first actions. I do blame them for having a network design that was easy to move about once inside. The days one can trust local systems to be clean ended with the "I Love You" email virus, and Management will just have to pay to do things a bit differently.
To other admins: I'm in the midst of a similar security upgrade, so I share your headache.
I. do. not. get. it.
I worked for a company with a particularly...interesting system. They did their billing on the second of the month, starting at 0200. It needed to lock the database that our company ran on, it took hours to run, and it tended to break.
In that area, Comcast did it's monthly network thingy on the second of the month, starting at 0100.
Guess who drove 40 minutes to work once a month at 0100?
Explain to me exactly why the correct business decision is to allow critical infrastructure controllers to be connected to the internet in the first place. Use small words.
Er ...
' ... the password used to gain access to the VPN was "complex" – it wasn't just "colonial123" ... '
So "Coloni4l123!" then?