News: 1707852009

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

ALPHV blackmails Canadian pipeline after 'stealing 190GB of vital info'

(2024/02/13)


Updated Canada's Trans-Northern Pipelines has allegedly been infiltrated by the ALPHV/BlackCat ransomware crew, which claims to have stolen 190 GB of data from the oil distributor.

ALPHV [1]added Trans-Northern to its blackmail site on Tuesday and said the purloined files include "all important information." Presumably the crew wants money or it'll leak that data.

The oil and gas concern, which operates about 528 miles (850 kilometers) of pipeline in Ontario and Quebec, and nearly 200 miles (320 kilometers) of pipeline in Alberta, had no immediate response to The Register 's inquiries.

[2]

We can't help but be reminded of the 2021 Colonial Pipeline ransomware infection. In that particular case, in which backend IT systems were attacked, oil execs decided to [3]shut off the pipeline , leading to fuel shortages, and long queues and some fisticuffs at the pumps, on the US East Coast.

[4]

[5]

Plus, as Emsisoft threat analyst Brett Callow [6]noted on social media, "ALPHV is linked to BlackMatter which was linked to Darkside which was the #ransomware operation responsible for the attack on Colonial Pipeline."

Trans-Northern is the fourth critical infrastructure org that Alphv has in the past few days claimed to have compromised over the past few months.

[7]Is critical infrastructure prepared for OT ransomware?

[8]Uncle Sam sweetens the pot with $15M bounty on Hive ransomware gang members

[9]Volt Typhoon not the only Chinese crew lurking in US energy, critical networks

[10]Fidelity National now says 1.3M customers had data stolen by cyber-crooks

The ransomware gang said it was responsible for the [11]Lower Valley Energy " [12]cybersecurity incident " in late December. The US utility cooperative in northwest Wyoming and southeastern Idaho provides energy services to Yellowstone National Park.

ALPHV also claimed it broke into Spanish [13]electricity provider SerCide in December and [14]Canada's Rush Energy .

[15]

"Governments need to quickly come up with ways to better secure critical infrastructure as, if they do not, it's only a matter of time before a significant, if not catastrophic, attack takes place," Callow said.

ALPHV's extortion claims come as governments are warning about the potential of destructive cyber attacks on critical infrastructure.

This includes [16]China's Volt Typhoon , which compromised "multiple" IT environments across communications, energy, transportation, water, and wastewater processing sectors in the United States, according to American government agencies.

[17]

The Beijing-backed cyberspies, however, also pose a risk to the UK as well as Canadian, Australian and New Zealand energy systems, according to last week's [18]Five Eyes' warning . ®

Updated to add

A spokesperson for Trans-Northern got back to us shortly after publication to confirm the biz "experienced a cybersecurity incident in November 2023 impacting a limited number of internal computer systems," and it's probing the latest boasts by the ransomware gang.

"We have worked with third-party, cybersecurity experts and the incident was quickly contained. We continue to safely operate our pipeline systems. We are aware of posts on the dark web claiming to contain company information, and we are investigating those claims," the rep told The Register .

Get our [19]Tech Resources



[1] https://twitter.com/H4ckManac/status/1757383007348850832

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zcv0mekNA7D89yBABjv4MwAAAM4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2021/06/09/old_vpn_colonial_pipeline/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zcv0mekNA7D89yBABjv4MwAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zcv0mekNA7D89yBABjv4MwAAAM4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://twitter.com/BrettCallow/status/1757439621582201299

[7] https://www.theregister.com/2024/02/02/critical_infrastructure_ot_ransomware/

[8] https://www.theregister.com/2024/02/09/hive_leaders_bounty/

[9] https://www.theregister.com/2024/02/07/its_not_just_volt_typhoon/

[10] https://www.theregister.com/2024/01/10/fidelity_data_disclosure/

[11] https://twitter.com/AlvieriD/status/1757051601456422937

[12] https://www.lvenergy.com/2023/12/28/cybersecurity-incident-update/

[13] https://twitter.com/AlvieriD/status/1757070350653808986

[14] https://twitter.com/DarkWebDispatch/status/1757430713878495295

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zcv0mekNA7D89yBABjv4MwAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[16] https://www.theregister.com/2024/02/07/its_not_just_volt_typhoon/

[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zcv0mekNA7D89yBABjv4MwAAAM4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[18] https://www.theregister.com/2024/02/07/us_chinas_volt_typhoon_attacks/

[19] https://whitepapers.theregister.com/



Curious...

Woodnag

How can the security measures not notice 190 GB being pulled?

Re: Curious...

Phil O'Sophical

You're assuming there were security measures...

Re: Curious...

Bendacious

How can huge social media companies, or companies storing very private data (23andme), not notice credential stuffing attacks? That’s probably easier to spot than large amounts of data leaving your network but you have to be watching for it. Until companies are made to pay for obvious security failures, they will only add basic monitoring after a successful attack. My employer invested the time and money to enable 2FA for domain access two weeks after ransomware destroyed our network. Prior to that it was too expensive and inconvenient. If there were financial penalties (or even CEO jail time - never happen) for poor security then maybe every IT department would have a security professional (who is invited to project meetings and listened to).

What

Snowy

What data would a company that runs a pipeline have that it adds up to over 190GB? Assuming they did not steal all their data.

If a thing's worth having, it's worth cheating for.
-- W. C. Fields