Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

BumRushDaShow

(128,905 posts)
Wed May 12, 2021, 03:27 PM May 2021

Colonial Pipeline said to have no plan pay hackers ransom

Source: Washington Post

Colonial Pipeline has no plan at this point to pay a ransom to decrypt data files, said two people familiar with the matter. Rather, they are working with the cybersecurity firm Mandiant to restore the data from backup systems where possible and rebuild systems where backups are unavailable, said the people, who spoke on the condition of anonymity because the matter is still under investigation.

Colonial had no comment. A spokeswoman for Mandiant, which is a division of the cyber firm FireEye, also declined to comment.

The hackers, a criminal group thought to operate mostly out of Russia, also appeared to be readying to extort Colonial by stealing data that it could later threaten to release unless a fee were paid. But Mandiant quickly traced the stolen data to a server owned by a New York hosting firm, which over the weekend shut the server down, preventing any data to flow to the hackers, according to several people familiar with the matter.

With that extortion avenue sealed off and with Mandiant helping to restore data and rebuild systems, “there’s no reason to make the payment,” one of the people said. DarkSide ransom demands can range from $500,000 to more than $5 million, according to Mandiant.

Read more: https://www.washingtonpost.com/business/2021/05/12/gas-shortage-colonial-pipeline-live-updates/#link-NFBKS44NJRCGDNDBIMOLJJMK2Q

51 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Colonial Pipeline said to have no plan pay hackers ransom (Original Post) BumRushDaShow May 2021 OP
Yeah, they need to - OhZone May 2021 #1
And disconnected, offsite ones for something as critical to the infrastructure of a huge part of the Hugh_Lebowski May 2021 #3
Here on the east coast, all the gas stations are out of gas. We cancelled our trip to see our BComplex May 2021 #9
Just a matter of time til the reports of car fires, house fires, and horrible burns pour in Hugh_Lebowski May 2021 #12
True that! BComplex May 2021 #13
Amen! It galls me to no end how lax this company (and likely others) are with regard to security. n/ iluvtennis May 2021 #23
Replicate to remote system lilymidnite May 2021 #15
Exactly! OhZone May 2021 #18
True about mainframes jmowreader May 2021 #32
It is a cheap and reliable system Miguelito Loveless May 2021 #20
I'm an SQL Developer with some DBA-like responsibilities ... much less since the shop went to AWS Hugh_Lebowski May 2021 #27
This stinks to high Heaven. ZZenith May 2021 #2
Yeah, their IT staff either freaking sucks to a level that beggars belief ... Hugh_Lebowski May 2021 #4
Mind you, I'm not saying that a Koch-owned oil company is incapable of hiring a substandard ZZenith May 2021 #8
I'm onboard with your thesis ZZ my man (nt) Hugh_Lebowski May 2021 #10
The problem is that Miguelito Loveless May 2021 #21
"I drive an EV and am not the least bit inconvenienced by this." mahatmakanejeeves May 2021 #22
My point wasn't that I was unconcerned about this Miguelito Loveless May 2021 #24
This message was self-deleted by its author mahatmakanejeeves May 2021 #25
It could be poor management too GregariousGroundhog May 2021 #14
Fair point! (nt) Hugh_Lebowski May 2021 #16
Very true. Worked for a major tv affiliate where the engineers miyazaki May 2021 #46
Ha! Traced it to a server... at trump tower perhaps? soothsayer May 2021 #5
I hope they can do this and quickly. Paying these cretins is hurting us all. hlthe2b May 2021 #6
This is why you don't privatize critical systems. CrispyQ May 2021 #7
Do you really believe the government ... reACTIONary May 2021 #30
Ransom hacking common? spike jones May 2021 #11
I was a mainframe operator in South Florida. marie999 May 2021 #17
I hear you Marie Skittles May 2021 #29
Apparently, these people never watched Battlestar Galactica. Dave Starsky May 2021 #19
So say we all rictofen May 2021 #26
That is a reference I will be storing for future use. Thank you. Sapient Donkey May 2021 #28
Well, duh dot com (if you'll pardon the expression) Rocknation May 2021 #31
My carpool friend who I just spoke with - OhZone May 2021 #33
In most cases it's something the end user downloaded. Yo_Mama_Been_Loggin May 2021 #35
I'm under the impression - OhZone May 2021 #39
Colonial Pipeline paid hackers nearly $5 million in ransom, sources say Yo_Mama_Been_Loggin May 2021 #34
!!!! BumRushDaShow May 2021 #37
NJ FTW! ha OhZone May 2021 #40
But only Jersey, dunna shore BumRushDaShow May 2021 #41
Ha! Get outta here with your - OhZone May 2021 #42
Youse guys are gonna have to deal wit BumRushDaShow May 2021 #43
Oh, if you're from Philly, then you're a Shoobie - OhZone May 2021 #44
.... BumRushDaShow May 2021 #45
That's Central Jersey West OhZone May 2021 #47
"Most of the main roads here are north-south-centric" BumRushDaShow May 2021 #48
IKR - Tower Records was great! OhZone May 2021 #49
Some days I wish for this when I'm over in your state BumRushDaShow May 2021 #50
You got that right - OhZone May 2021 #51
And according to two OTHER sources Rocknation May 2021 #36
Yup BumRushDaShow May 2021 #38
 

Hugh_Lebowski

(33,643 posts)
3. And disconnected, offsite ones for something as critical to the infrastructure of a huge part of the
Wed May 12, 2021, 03:34 PM
May 2021

country as the operation of this pipeline is.

Honestly something like this should've taken a few hours at most to fix if their IT folks were doing their job right.

BComplex

(8,049 posts)
9. Here on the east coast, all the gas stations are out of gas. We cancelled our trip to see our
Wed May 12, 2021, 03:53 PM
May 2021

daughter because we wouldn't be able to buy gas on the route. Everyone is in long lines at every station that has gas...until that station runs out, too. Word gets around quickly when there's a station that has gas.

It's like the toilet paper mess...folks are filling up their gas cans and milk jugs.

 

Hugh_Lebowski

(33,643 posts)
12. Just a matter of time til the reports of car fires, house fires, and horrible burns pour in
Wed May 12, 2021, 03:59 PM
May 2021

The large majority of citizens pump it into their gas tanks and that's it, they don't really know how to handle it.

And there's a reason there's laws about only pumping it into licensed containers.

lilymidnite

(358 posts)
15. Replicate to remote system
Wed May 12, 2021, 04:28 PM
May 2021

Idiots. Why weren't they at the *very* least taking backups, say, hourly. And, real-time replication technology is not that expensive.
It takes skill to set up, but is bulletproof, encryptable.

My job as a database administrator was (I just retired) to keep this stuff from happening. I had hourly encrypted backups to tape, nightly full backups, real-time replication to 5 systems, dataguard (another replication) to 3 systems in 3 cities. And I was a single DBA shop. The sysadmin and I could've had this back up and running in 90 minutes.

OhZone

(3,212 posts)
18. Exactly!
Wed May 12, 2021, 04:55 PM
May 2021

I have coworkers who do stuff like that.

And I know of mainframes where everything is mirrored and audited so if one side fails the other side picks things up.

I know some mainframes use their own special OS too, right?

So windows compatible encrypting software wouldn't work.

jmowreader

(50,557 posts)
32. True about mainframes
Wed May 12, 2021, 10:56 PM
May 2021

I LOVE big iron! Especially big iron running proprietary OS like VM. Not super happy that the new IBM Z/Systems are running Linux.

Among my millions of jobs in Berlin was being sysop on a Navy mainframe running Aegis Tactical Executive Program. We did our backups very simply: once every three days we dropped all the users off the system and did a complete copy of each disc pack to another disc pack. There were two disc packs in the system and we had three working drives, so the drill was to copy the system pack to another system pack, the text pack to another text pack, mount the new copies (so we knew they worked) and put the old ones on a shelf.

If this backup scheme would have been operative at Colonial Pipeline, they could have had the whole system back in operation in an hour - the length of time it would have taken to shut down, pull the old hard drives, install ones from Staples where the infected ones were, and restored from backups. IT these days makes me cringe...people are not backing up and eventually they’re gonna get fucked.

Miguelito Loveless

(4,465 posts)
20. It is a cheap and reliable system
Wed May 12, 2021, 05:01 PM
May 2021

that takes skilled people to run and maintain. They do not want to pay for the people.

 

Hugh_Lebowski

(33,643 posts)
27. I'm an SQL Developer with some DBA-like responsibilities ... much less since the shop went to AWS
Wed May 12, 2021, 07:31 PM
May 2021

and we have an Ops guy that handles a lot of the DBA stuff.

Just saying Hi

Also, replication doesn't help if someone f***s up your data ... you just have copies of wrong stuff

Backups though ... helps for sure. But the data they've encrypted was likely regular files as opposed to db data tables, right?

 

Hugh_Lebowski

(33,643 posts)
4. Yeah, their IT staff either freaking sucks to a level that beggars belief ...
Wed May 12, 2021, 03:36 PM
May 2021

Or ... what you're saying.

ZZenith

(4,122 posts)
8. Mind you, I'm not saying that a Koch-owned oil company is incapable of hiring a substandard
Wed May 12, 2021, 03:41 PM
May 2021

IT crew, but as Malaise adroitly pointed out earlier, gas shortages are a time-tested method of manipulating a population.

Desperate men employing desperate measures as their empires crumble around them.

Miguelito Loveless

(4,465 posts)
21. The problem is that
Wed May 12, 2021, 05:05 PM
May 2021

creating a false shortage is a very short term gain, and seriously makes the case against oil long term. I drive an EV and am not the least bit inconvenienced by this. More people are going to realize this just as many Californians are realizing that solar with a battery backup up means never losing power.

mahatmakanejeeves

(57,425 posts)
22. "I drive an EV and am not the least bit inconvenienced by this."
Wed May 12, 2021, 05:11 PM
May 2021

Last edited Wed May 12, 2021, 06:31 PM - Edit history (4)

Sure, of course not. I mean, as long as you don't eat food:



Source: https://fleetnewsdaily.com/truck-driver-shortage-fuel-rising-grocery-store-prices/

Or live in an economy that depends on the delivery of commodities in bulk:



Big Loaded CSX Grain Train
220 views•Apr 20, 2018

StAr's YT Hub
945 subscribers

Grain train G801 goes east with three locos and 91 cars.

Seen 4/20/18 in Gaithersburg, MD.

The lead unit, 811, runs on diesel. So do the next two. The cars are grain cars. Loaded, they carry 110 tons each; the smaller ones, 100 tons each.

Count the cars. If they were loaded, how many tons of grain would that be? It could be soybeans, it could be corn; I don't know. It gets turned into bread, it gets turned into cooking oil; beats me.

Or depend on the ability of people to travel from one place to another.



GRAVELLY POINT
(HD) Watching Airplanes - Gravelly Point Plane Spotting - Washington National Airport KDCA/DCA
34,852 views•Jul 5, 2017

Jay’s O'Hare Aviation
76.8K subscribers

This video is forever dedicated to the memory of one of the finest planespotters ever... Steve Bezman a.k.a. 99carnot. His kindness and encouragement to the planespotters and aviation enthusiasts of YouTube will always be remembered.

When the members of the air crew lay over between flights, how do they get from the airport to their lodgings?



Vegas Airport Transportation Tips
10,602 views•Sep 14, 2012

Very unOfficial Travel Guides
48.1K subscribers

Need help getting to your resort/hotel from the airport in Vegas? WATCH THIS VIDEO NOW!!!

When I was in Vegas, I stayed at a place where the air crews stayed, so I can personally attest that this is how they are transported.

When your electric car needs repair or new parts or new tires, how are those parts getting to the repair facility?

The power line workers who maintain the transmission lines that deliver the electricity to your abode: how do they get to those lines?



hinstalling marker ball 2012
4,661,645 views•Sep 18, 2012

helicopterlineman
9.14K subscribers

Installing aerial markers in West Virginia

Or maybe they're working from one of those boring old bucket trucks:



Source: https://www.tdworld.com/electric-utility-operations/article/20966170/take-a-look-inside-a-linemans-bucket-truck

I'm lucky I can find the power switch on my work-issue laptop. That's as much IT as I know, so I am unable to deliver my expertise on what I would have done.

But I do know this:

Yes, this affects you.

Miguelito Loveless

(4,465 posts)
24. My point wasn't that I was unconcerned about this
Wed May 12, 2021, 05:57 PM
May 2021

or believed myself immune from it, but was in the context of my remark that if oil interests were involved in creating a fake shortage as one poster was postulating, it would return short terms gains, but utterly destroy their business long term by showing people how vulnerable they are to this type of thing.

I started driving electric in 2014 with a used 2012 Leaf. During that time there have been about 4 supply disruptions in my area due to pipeline failures and storms. After each one, at least one friend or co-worker has switched to EV/solar to escape gasoline/power disruption. In the last few days I have been peppered with questions about my EV. Every time something like this happens, more people switch. The drops become a trickle, and trickles, become streams, then rivers.

The pandemic has taught people to stock up on food because we can't rely on a government run by the incompetent. At the moment my pantry can get me through 6-8 weeks, but I am set for water, power and transport indefinitely. The more people who realize how vulnerable we are because of oil, the faster the transition will speed up.

Response to Miguelito Loveless (Reply #24)

GregariousGroundhog

(7,521 posts)
14. It could be poor management too
Wed May 12, 2021, 04:25 PM
May 2021

Even with decent IT staff, disaster recovery plans are rarely effective unless they are practiced on a somewhat regular basis. DR plans don't get practiced and refined unless management allocates the necessary resources to make it happen.

miyazaki

(2,240 posts)
46. Very true. Worked for a major tv affiliate where the engineers
Thu May 13, 2021, 02:22 PM
May 2021

never bothered to test the stations half million dollar backup generator twice a year as prescribed.
Of course power was lost in a major storm, the generator never kicked in like it was supposed to,
and hilarity ensued as the assistant engineer was jumping the backup storage batteries to maintain our on air capability with a work truck, while the incompetent fuck chief engineer was hiding from the GM in a utility closet.

CrispyQ

(36,461 posts)
7. This is why you don't privatize critical systems.
Wed May 12, 2021, 03:41 PM
May 2021

People bought a load of shit when they signed on to the GOPs "private companies can do it better & cheaper." They might do it cheaper so the officers & board can suck off more profit, but better? No guarantee of that.

 

marie999

(3,334 posts)
17. I was a mainframe operator in South Florida.
Wed May 12, 2021, 04:53 PM
May 2021

Every night before running the nightly updates and reports I ran a backup of all the files. I worked for three different companies over a period of 20 years. They all ran backups every night.

Dave Starsky

(5,914 posts)
19. Apparently, these people never watched Battlestar Galactica.
Wed May 12, 2021, 04:55 PM
May 2021

I seem to recall that none of the Galactica's mission-critical systems were networked, explicitly to avoid similar fuckery by Cylons or other similar cybervarmints.

There's always an opportunity to learn from science fiction.

Rocknation

(44,576 posts)
31. Well, duh dot com (if you'll pardon the expression)
Wed May 12, 2021, 09:46 PM
May 2021

Last edited Mon Oct 4, 2021, 12:25 PM - Edit history (14)

I suspected that this was what was going on when I read that they expected to be back online no later than late next week.

There's no need to pay a ransom if you've taken the precaution of uploading an automatically updated and encrypted copy of your data and files to a different sever. I've done it myself when my daily blog outgrew the Web hosts I was using. I receive a copy of the blog's database every 24 hours, and back up its physical files offline as well as online!


Rocknation

OhZone

(3,212 posts)
33. My carpool friend who I just spoke with -
Thu May 13, 2021, 10:30 AM
May 2021

(we haven't carpooled in ages for a number of reasons including the pandemic)

reminded me of the things that secure his mainframe.

A prorprietary OS.

Multi-factor authentication for the firewalls that prevent you from even logging in.

Special security once you log in that prevents most from updating system files.

Some kind of transaction monotoring thing (I forgot what he called it) that backs out incomplete and suspicuous transaction.

Nightly backups.

Also, did I mention the proprietary non-windows, non-linux OS?

Yo_Mama_Been_Loggin

(107,956 posts)
35. In most cases it's something the end user downloaded.
Thu May 13, 2021, 12:26 PM
May 2021

That's why this malware is often called a Trojan Horse.

You can prevent a lot of people from logging into your system but that won't matter if you're not careful of what you're downloading.

However even a legitimate download might be infected. Remember the Solar Winds hack? I'm sure a lot of people using their software downloaded what they thought was an update.

OhZone

(3,212 posts)
39. I'm under the impression -
Thu May 13, 2021, 12:49 PM
May 2021

that there is no easily available common software for my friend's boxes. It's not windows, linux, or apple.

And you would specifically have to logon on through various hurdles, and upload the program and try to run it, when the mainframe security would just say, no. ha

One's email does not run through a mainframe, right?






Yo_Mama_Been_Loggin

(107,956 posts)
34. Colonial Pipeline paid hackers nearly $5 million in ransom, sources say
Thu May 13, 2021, 12:19 PM
May 2021

Colonial Pipeline Co. paid nearly $5 million to Eastern European hackers on Friday, contradicting reports earlier this week that the company had no intention of paying an extortion fee to help restore the country’s largest fuel pipeline, according to two people familiar with the transaction.

The company paid the hefty ransom in untraceable cryptocurrency within hours after the attack, underscoring the immense pressure faced by the Georgia-based operator to get gasoline and jet fuel flowing again to major cities along the East Coast, those people said. A third person familiar with the situation said U.S. government officials are aware that Colonial made the payment.

Once they received the payment, the hackers provided the operator with a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system, one of the people familiar with the company’s efforts said.

A representative from Colonial declined to comment, as did a spokesperson for the National Security Council.

https://www.msn.com/en-us/news/us/colonial-pipeline-paid-hackers-nearly-dollar5-million-in-ransom-sources-say/ar-BB1gHobz

BumRushDaShow

(128,905 posts)
37. !!!!
Thu May 13, 2021, 12:43 PM
May 2021

I know they were being pummeled to get that pipeline up and running by the end of the week, come hell or high water. The ones impacted the most are largely "red" and "red-turning-purple" states.

And as a note, when these articles talk about the "major cities along the east coast" the ones they seem to want to talk about are not up here in Philly and north. It appears that those north of VA generally have other pipe lines that provide similar fuel and hell, just outside of Philly, we have huge refineries that I expect feed into the system (although over the years some of them have closed down). They should say "cities along the SOUTHeast coast".





This is who is getting impacted at the moment (not counting the airlines as I believe kerosene flows in some of those pipes) -



Anyway (I know that was a bit much ) - thanks for that update!!!!

OhZone

(3,212 posts)
44. Oh, if you're from Philly, then you're a Shoobie -
Thu May 13, 2021, 01:57 PM
May 2021

not a Benny.




I'm from the Central Jersey shore not South Jersey.

We get more Bennies than Shoobies.

BumRushDaShow

(128,905 posts)
45. ....
Thu May 13, 2021, 02:22 PM
May 2021






Don't hear much about Central Jersey except for what's happening in Trenton or Princeton.

We cover the South Jersey market, (but also Trenton. Because. State Capital. And. Governor. Hell, I hear more on the news here about Murphy than my own damn governor Tom Wolf.

OhZone

(3,212 posts)
47. That's Central Jersey West
Thu May 13, 2021, 03:34 PM
May 2021

I'm on the shore - Central Jersey EAST near Seaside and Island Beach.

It's actually kinda hard for me to get to Princeton and Trenton - and I'm so sorry to hear you have to hear about our politics. Most of Jersey doesn't like Trenton either. Ha.


Most of the main roads here are north-south-centric unless you want to go between AC and Philly. (Atlantic City Expressway)

The road I take to Princeton and Trenton and Philly is two lanes for most of it, and it has - CIRCLES! OHNOES! (It's even a little bit of a pain to get a lot of places in NJ, since it's such a mix of rural areas, suburbs, wildlife areas, shore towns, and congested areas up north)

Road to Princeton/Philly 1 lane either way -


Road to NY - multiple lanes either way -
?width=640


But I did venture there to get to that Princeton record store when I was a teen. I used to love that place.

Is Jawn a recent slang. I don't remember it from my trips to Philly and South Street and Tower Records and Zipper head.


Or even more recently when I did my Rocky impression. ha

BumRushDaShow

(128,905 posts)
48. "Most of the main roads here are north-south-centric"
Thu May 13, 2021, 04:46 PM
May 2021

In other words, "what exit off the Turnpike(s) - NJ or Garden State?".

I have been up and down and across to and fro, and diagonally hither and yon, far too many times in New Jersey. I have an aunt and cousins and a niece living in Jersey (all in North Jersey though). My parents used to own a plot of land in N. Cape May but my mom sold it back in the '70s.

And yeah, the Jersey jughandles are awful.

But as a sidenote, I am glad they FINALLY fixed the "I-95 problem" and New Jersey. I.e., you would think that if you stayed on I-95 through Philly, you'd eventually go across some bridge and continue straight along "I-95" on the other side of the bridge in Jersey (the NJ Turnpike)... But NOOOOooooooo. You suddenly realize, previously unbeknownst to you, that the highway you were on had magically changed to I-295 (with no signs) and you would be heading over the Scudder-Falls bridge, finally confirming that you were on "I-295" and not "I-95" once you are on the Jersey side.



The re-signing has now been completed.

"Jawn" seems to be something that was suddenly "discovered" and "commercialized" recently, but it was slang that I remember using back in high school in the '70s. It was sortof a placeholder noun for "a thing" (e.g., "Yo, gimme that jawn.." ) or as a slang adjective for something that is really fantastic/incredible (e.g., "That party was the jawn" ). I think they have said it was a variation of the slang word "joint" (i.e. "That movie was the joint!" ) and I remember using that term too for the same reasons.

I miss miss miss Tower Records! It was one of the few places in the area that sold laserdisc movies!

OhZone

(3,212 posts)
49. IKR - Tower Records was great!
Thu May 13, 2021, 05:03 PM
May 2021

Funny how I missed "jawn."

Anyway, Yeah, it's "what's your Exit off the Garden State Parkway" for me.

Where I am there is no easy access to diagonal roads like the Turnpike and the AC expressway. It's North/South GSP OR slow roads everywhere else.

Yeah NJ signage is not great. Like my brother in Brick complains, there is a sign on one of his fav roads - to go to the parkway, labeled "Parkway North." So you think it's ONLY for the north, but there is a Parkway South exit just past it. Why not say that both directions are coming up?!

He says he wants to take a sharpie to it. ha!

Also, Princeton records appears to still be open for business! OHYEAH!







OhZone

(3,212 posts)
51. You got that right -
Thu May 13, 2021, 05:24 PM
May 2021

It can get wild.

Also the left lane hogs are often Bennies from NY.

Terrible drivers.

Rocknation

(44,576 posts)
36. And according to two OTHER sources
Thu May 13, 2021, 12:35 PM
May 2021
Colonial Pipeline Co. paid nearly $5 million to Eastern European hackers on Friday, contradicting reports earlier this week that the company had no intention of paying an extortion fee to help restore the country’s largest fuel pipeline, according to two people familiar with the transaction...

Well, it would be the perfect "excuse" for Colonial to keep their gas prices inflated...


rocktivity
Latest Discussions»Latest Breaking News»Colonial Pipeline said to...