Report: Colonial confirms it paid $4.4M to pipeline hackers

Report: Colonial confirms it paid $4.4M to pipeline hackers

SeattlePI.com

Published

The operator of the nation's largest fuel pipeline confirmed it paid $4.4 million to a gang of hackers who broke into its computer systems, according to a report Wednesday from The Wall Street Journal.

Colonial Pipeline's CEO, Joseph Blount, told the Journal he authorized the payment after the May 7 ransomware attack because the company didn't know the extent of the damage and wasn't sure how long it would take to bring the pipeline's systems back.

The FBI discourages making ransom payments to ransomware attackers, because paying encourages criminal networks around the globe who have hit thousands of businesses and health care systems in the U.S. in the past year alone. But many victims of ransomware attacks, where hackers demand large sums of money to decrypt stolen data or to prevent it from being leaked online, opt to pay.

“I know that’s a highly controversial decision,” Blount told the Journal. “I didn’t make it lightly. I will admit that I wasn’t comfortable seeing money go out the door to people like this.”

“But it was the right thing to do for the country,” he said.

Blount said Colonial paid the ransom in consultation with experts who previously dealt with the group behind the attacks, DarkSide, which rents out its ransomware to partners to carry out the actual attacks.

Multiple sources had confirmed to The Associated Press that Colonial Pipeline had paid the criminals who committed the cyberattack a ransom of nearly $5 million in cryptocurrency for the software decryption key required to unscramble their data network.

A ransom payment of 75 Bitcoin was paid the day after the criminals locked up Colonial’s corporate network, according to Tom Robinson, co-founder of the cryptocurrency-tracking firm Elliptic. Prior to Robinson’s blog post, two people briefed on...

Full Article