Business

Colonial Pipeline has no plan to pay ransom to hackers -sources By Reuters

© Reuters. FILE PHOTO: A truck passes holding tanks at Colonial Pipeline’s Linden Junction Tank Farm in Woodbridge, New Jersey, U.S., May 10, 2021. REUTERS/Hussein Waaile

By Joseph Menn and Christopher Bing

WASHINGTON (Reuters) – Colonial Pipeline does not plan to pay the ransom demanded by hackers who have encrypted its data, according to sources familiar with the company’s response on Wednesday.

The hack prompted a pipeline shutdown that is now in its sixth day and has led to panic buying and gasoline shortages in the southeastern United States.

Colonial said it began reopening its line late Wednesdy afternoon, a process that may last days. It declined to comment on the ransom issue.

Colonial is working closely with law enforcement, the Department of Energy and U.S. cybersecurity firm FireEye (NASDAQ:) to mitigate the damage and restore operations.

The Colonial and government answer to the breach is being closely watched after one of the most direct hacking attacks on American critical infrastructure after years of warnings.

President Joe Biden said this week that Russia should bear some responsibility for the disruption, since the hacking came from inside its borders.

Ransomware attacks have increased in number and amount of demands, with hackers encrypting data and seeking payment in cryptocurrency to unlock it. They increasingly release stolen data as well, or threaten to unless they are paid more.

Investigators in the Colonial case say the attack software was distributed by a gang called DarkSide, which includes Russian speakers and avoids hacking targets in the former Soviet Union.

DarkSide previously said that it did not intend to medde in geopolitics and would be more careful about its affiliates in the future.

On Wednesday, the gorup said on its website that it was releasing data from three more victims, including a technology company in Chicago.

Officials so far have found no significant connection to the Russian government, instead concluding that the pipeline company delivering 45% of the U.S. East Coast’s oil was crippled by ransomware attack.

DarkSide lets “affiliates” hack into targets elsewhere, then handles the ransom negotiation and data release.

Two people involved with the Colonial investigation said the affiliate in this case was a Russian criminal with no special government ties.

Disclaimer: Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. All CFDs (stocks, indexes, futures) and Forex prices are not provided by exchanges but rather by market makers, and so prices may not be accurate and may differ from the actual market price, meaning prices are indicative and not appropriate for trading purposes. Therefore Fusion Media doesn`t bear any responsibility for any trading losses you might incur as a result of using this data.

Fusion Media or anyone involved with Fusion Media will not accept any liability for loss or damage as a result of reliance on the information including data, quotes, charts and buy/sell signals contained within this website. Please be fully informed regarding the risks and costs associated with trading the financial markets, it is one of the riskiest investment forms possible.



Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button