News: 1626453013

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Wanted: State-backed bandits planning cyberattacks on US infrastructure. Reward: $10m

(2021/07/16)


The US is offering a $10m reward to anyone who dobs in digital outlaws responsible for foreign government-backed cyberattacks on critical national infrastructure such as pipelines, power grids, and communication networks.

The [1]cash incentive is part of the US State Department's Rewards for Justice (RFJ) programme and the ongoing war on cybercrime that has in recent months [2]crippled fuel pipelines and [3]meat production .

Since it was launched in 1984, the RFJ has paid some $200m to more than 100 informants across the world who have passed on titbits concerning national security.

[4]

Last month, President Joe Biden and Russia's Vladimir Putin spent some of their time during a summit in Switzerland [5]discussing cybersecurity and the threats posed to critical national infrastructure including energy and water.

[6]REvil ransomware gang's websites vanish soon after Kaseya fiasco, Uncle Sam threatens retaliation

[7]Ransomware victim Colonial Pipeline paid $5m to get oil pumping again, restored from backups anyway – report

[8]Ransomware-skewered meat producer JBS confesses to paying $11m for its freedom

[9]Biden to Putin: Get your ransomware gangs under control and don’t you dare cyber-attack our infrastructure

According to [10]transcripts , Biden told Putin that "responsible countries need to take action against criminals who conduct ransomware activities on their territory."

Putin agreed before mentioning an unnamed US-based source that said America is the world's leading source of cyberattacks. Russia isn't on the list, Putin said.

[11]

This latest exchange of words underlines the importance of cybercrime to national security with the State Department's latest reward providing another insight into what keeps officials in Washington awake at night.

To ensure anonymity, the State Department has set up a Dark Web (Tor-based) tip-reporting channel to protect the safety and security of potential sources.

[12]

In a statement, officials said: "We encourage anyone with information on malicious cyber activity, carried out against US critical infrastructure in violation of the CFAA by actors at the direction of or under the control of a foreign government, to contact the Rewards for Justice office via our Tor-based tips-reporting channel." ®

Get our [13]Tech Resources



[1] https://www.state.gov/rewards-for-justice-reward-offer-for-information-on-foreign-malicious-cyber-activity-against-u-s-critical-infrastructure/#:~:text=The%20U.S.%20Department%20of%20State's,control%20of%20a%20foreign%20government%2C

[2] https://www.theregister.com/2021/05/13/colonial_pipeline_ransom/

[3] https://www.theregister.com/2021/06/10/jbs_foods_pays_ransom/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YPIBgFUPEcBgdyYCXK-GmQAAAEg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://www.theregister.com/2021/06/17/biden_putin_summit_cybersecurity_discussion/

[6] https://www.theregister.com/2021/07/13/revil_ransomware_shuts/

[7] https://www.theregister.com/2021/05/13/colonial_pipeline_ransom/

[8] https://www.theregister.com/2021/06/10/jbs_foods_pays_ransom/

[9] https://www.theregister.com/2021/06/17/biden_putin_summit_cybersecurity_discussion/

[10] https://www.whitehouse.gov/briefing-room/speeches-remarks/2021/06/16/remarks-by-president-biden-in-press-conference-4/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPIBgFUPEcBgdyYCXK-GmQAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPIBgFUPEcBgdyYCXK-GmQAAAEg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



Where's the biggest profit?

Version 1.0

Are malware companies making more money than the insurance companies?

A nice boost of malware attacks means that the insurance industry has a ton of free publicity to make buying insurance look like a good idea to any corporation with an internet connection. If the malware attacks are prevented then it's going to cost the insurance companies shareholders a lot of money.

Re: Where's the biggest profit?

Headley_Grange

@Version 1.0: that might have been the case up until a short while ago, but insurance companies are starting to back away from cyber security. AXA France recently stopped underwriting ransom payments. Other companies are now excluding ransom payments from their cover and the cost of premiums is rising. The security requirements for getting insured are increasing in some sectors, which can only be a good thing.

I think we'll soon see the end of organizations having poor security and relying on the insurance pay the ransom to get their data back.

I would have thought..

Anonymous Coward

.. that helping against obesity by messing up their meat packaging would have been cause for rewards.

But hey, who am I to argue?

:)

Re: I would have thought..

IGotOut

What?

Moebius always does it on the same side.