• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Articles
  • News
  • Events
  • Advertize
  • Jobs
  • Courses
  • Contact
  • (0)
  • LoginRegister
    • Facebook
    • LinkedIn
    • RSS
      Articles
      News
      Events
      Job Posts
    • Twitter
Datafloq

Datafloq

Data and Technology Insights

  • Categories
    • Big Data
    • Blockchain
    • Cloud
    • Internet Of Things
    • Metaverse
    • Robotics
    • Cybersecurity
    • Startups
    • Strategy
    • Technical
  • Big Data
  • Blockchain
  • Cloud
  • Metaverse
  • Internet Of Things
  • Robotics
  • Cybersecurity
  • Startups
  • Strategy
  • Technical

Ransomware hits near pre-Colonial Pipeline levels, data suggests

Reuters / 3 min read.
May 19, 2021
floq.to/OCLjO

By Raphael Satter

WASHINGTON (Reuters) –Digital extortion attempts are returning to their pre-Colonial Pipeline levels, according to data and interviews with some incident responders, suggesting that the upheaval around the hack that paralyzed a major U.S. fuel conduit has yet to curb cybercriminals’ appetite for ransoms.

Ransomware incidents are usually shrouded in secrecy, with victim companies and criminals alike eager to prevent the eye-watering extortion payments from becoming public. But indirect data suggests that the global publicity around the hack of Colonial Pipeline, which paralyzed the company for nearly a week and led to fuel shortages on the U.S. East Coast, did little or nothing to puncture the thriving industry.

There was a dip in the number of companies whose data was uploaded to ransomware operators’ name-and-shame sites in the days following the Colonial intrusion, said Allan Liska, a researcher with cybersecurity firm Recorded Future.

But the sites, which the hackers use to pressure their victims into paying up by leaking reams of sensitive data, are now “back to normal,” he said, with 10-15 victims posted daily.

Data privately tracked by ID Ransomware https://id-ransomware.malwarehunterteam.com – a ransomware identification site run by Emsisoft researcher Michael Gillespie – shows that submissions of extortion software dropped sharply in the days following news of the Colonial hack, only to rise higher than before.

Gillespie’s colleague Brett Callow said that one possible explanation for the dip is that some hackers put their operations on pause amid the pipeline chaos and are now clearing the backlog.

“I think the groups got back to business as usual,” Callow said.

Another possible explanation is that there was a period of confusion as underground forums banned the advertisement of ransomware partnerships, said David Nides of consultancy KPMG.

“The threat actors quickly adjusted,” he said.

Other analysts saw no change whatsoever.

“We didn’t really notice any uptick or downtick,” said Mark Manglicmot of cybersecurity firm Arctic Wolf.

Some ransomware operators, including DarkSide, the group blamed for the intrusion at Colonial, have either disappeared from the web or announced new restrictions, statements that have been met with skepticism from experts.

Manglicmot said he too doubted the disappearances had any real impact.

“There’s a big enough market for it that if one provider goes down there are others they can go to pretty quickly,” he said. “The attackers remain undeterred by the publicity.”

That may in part be due to the extraordinary amounts of money involved. In a blog post published https://www.elliptic.co/blog/darkside-ransomware-has-netted-over-90-million-in-bitcoin on Tuesday, digital currency-tracking firm Elliptic said that DarkSide had extracted $90 million worth of bitcoin in ransoms from 47 victims.

Whether Colonial itself paid a ransom has not yet been publicly disclosed. Last week Reuters and other media reported that Colonial was not planning to pay a ransom. But Bloomberg and some other news outlets later reported it had paid nearly $5 million. The reporting was corroborated by Elliptic, which said it had identified the payment itself on the publicly visible ledger of bitcoin transactions.

Repeated attempts by Reuters to reach the hackers have been unsuccessful and Colonial itself has declined comment on whether it paid.

U.S. Representatives Carolyn Maloney and Bennie Thompson, the chairs of the House Committees on Oversight and Reform and Homeland Security respectively, said on Tuesday they were disappointed by Colonial’s refusal to discuss the reported ransom.

“In order for Congress to legislate effectively on ransomware, we need this information,” the pair said in a joint statement https://homeland.house.gov/news/press-releases/maloney-thompson-statement-on-staff-briefing-with-colonial-pipeline.

(Reporting by Raphael Satter; editing by Grant McCool and Richard Pullin)

Categories: News
Tags: Data, future, news, research, security

About Reuters

Primary Sidebar

E-mail Newsletter

Sign up to receive email updates daily and to hear what's going on with us!

Publish
AN Article
Submit
a press release
List
AN Event
Create
A Job Post

Jobs

  • Software Engineer | South Yorkshire, GB - February 07, 2023
  • Software Engineer with C# .net Investment House | London, GB - February 07, 2023
  • Senior Java Developer | London, GB - February 07, 2023
  • Software Engineer – Growing Digital Media Company | London, GB - February 07, 2023
  • LBG Returners – Senior Data Analyst | Chester Moor, GB - February 07, 2023
More Jobs

Tags

AI Amazon analysis analytics application applications Artificial Intelligence BI Big Data business China Cloud Companies company costs crypto Data design development digital engineer environment experience finance financial future Google+ government Group health information machine learning mobile news public research security services share skills social social media software strategy technology

News

  • Spanish competition watchdog opens disciplinary case against Google
  • Who is Binance billionaire Changpeng Zhao?
  • Envestnet names three new directors, ends board fight with Impactive Capital
  • Apple launches buy now, pay later service in U.S
  • Infineon raises 2023 outlook on automotive and industrial strength
More News

Related Online Courses

  • Managing Up
  • Recommender Systems
  • FL Studio Basics
More courses

Footer


Datafloq is the one-stop source for big data, blockchain and artificial intelligence. We offer information, insights and opportunities to drive innovation with emerging technologies.

  • Facebook
  • LinkedIn
  • RSS
  • Twitter

Recent

  • Personalization Vs. Hyper-Personalization: Benefits, Limitations and Potential
  • Explaining data products lifecycle and their scope in management
  • Microsoft Power BI -The Future of Healthcare’s Most Important Breakthrough
  • The Big Crunch of 2025: Is Your Data Safe from Quantum Computing?
  • From Data to Reality: Leveraging the Metaverse for Business Growth

Search

Tags

AI Amazon analysis analytics application applications Artificial Intelligence BI Big Data business China Cloud Companies company costs crypto Data design development digital engineer environment experience finance financial future Google+ government Group health information machine learning mobile news public research security services share skills social social media software strategy technology

Copyright © 2023 Datafloq
HTML Sitemap| Privacy| Terms| Cookies

  • Facebook
  • Twitter
  • LinkedIn
  • WhatsApp

In order to optimize the website and to continuously improve Datafloq, we use cookies. For more information click here.

settings

Dear visitor,
Thank you for visiting Datafloq. If you find our content interesting, please subscribe to our weekly newsletter:

Did you know that you can publish job posts for free on Datafloq? You can start immediately and find the best candidates for free! Click here to get started.

Not Now Subscribe

Thanks for visiting Datafloq
If you enjoyed our content on emerging technologies, why not subscribe to our weekly newsletter to receive the latest news straight into your mailbox?

Subscribe

No thanks

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

If you disable this cookie, we will not be able to save your preferences. This means that every time you visit this website you will need to enable or disable cookies again.

Marketing cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.

Please enable Strictly Necessary Cookies first so that we can save your preferences!