{"id":6525,"date":"2021-05-10T11:26:47","date_gmt":"2021-05-10T10:26:47","guid":{"rendered":"https:\/\/www.intelligentcio.com\/north-america\/?p=6525"},"modified":"2021-05-12T10:13:55","modified_gmt":"2021-05-12T09:13:55","slug":"cybercriminal-gang-hit-colonial-pipeline-with-ransomware-attack","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2021\/05\/10\/cybercriminal-gang-hit-colonial-pipeline-with-ransomware-attack\/","title":{"rendered":"Cybercriminal gang hit Colonial Pipeline with ransomware attack"},"content":{"rendered":"\n<p><strong><em>Colonial Pipeline, the largest fuel pipeline in the US, has been hit by a ransomware attack resulting in the US government issuing emergency legislation.<\/em><\/strong><\/p>\n\n\n\n<p>Colonial Pipeline, the largest fuel pipeline in the US, has been hit by a ransomware attack.<\/p>\n\n\n\n<p>The company was knocked offline on Friday by the activities of a cybercriminal gang with the result that the US Government issued emergency legislation on Sunday to relax rules on fuel being transported by road.<\/p>\n\n\n\n<p>A statement from Colonial said: \u201cThese actions temporarily halted all pipeline operations and affected some of our IT systems, which we are actively in the process of restoring.\u201d<\/p>\n\n\n\n<p>Colonial has engaged third-party cybersecurity experts and launched an investigation into the nature and scope of the attack thought to have been carried out by the DarkSide group.<\/p>\n\n\n\n<p>&#8220;We have remained in contact with law enforcement and other federal agencies, including the Department of Energy who is leading the federal government response,&#8221; the company said.<\/p>\n\n\n\n<p>&#8220;Maintaining the operational security of our pipeline, in addition to safely bringing our systems back online, remain our highest priorities. Over the past 48&nbsp;hours, Colonial Pipeline personnel have taken additional precautionary measures to help further monitor and protect the safety and security of its pipeline.&#8221;<\/p>\n\n\n\n<p>James Shank, <a href=\"https:\/\/urldefense.proofpoint.com\/v2\/url?u=https-3A__securityandtechnology.org_ransomwaretaskforce_&amp;d=DwMFaQ&amp;c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&amp;r=EfMGYBONq4GOU40r5lw3FZlyx0SWRp3WzbtC2K29pjo&amp;m=y_ZmMZaGzW0x5d-fS-_VTFSbc0fRK41TuBfN6K0phvQ&amp;s=Uij8qTJpZdMltMnJ4n3_7Kh0sVdn3KYay2NbzwS9PWw&amp;e=\" target=\"_blank\" rel=\"noreferrer noopener\">Ransomware Task Force (RTF)<\/a> committee lead for worst case scenarios and <a href=\"https:\/\/urldefense.proofpoint.com\/v2\/url?u=https-3A__team-2Dcymru.com_blog_author_jshankteamcymru_&amp;d=DwMFaQ&amp;c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&amp;r=EfMGYBONq4GOU40r5lw3FZlyx0SWRp3WzbtC2K29pjo&amp;m=y_ZmMZaGzW0x5d-fS-_VTFSbc0fRK41TuBfN6K0phvQ&amp;s=NPX6lgtSo6vhO8_fLhdnKyni0KepoWDipJMvssglnEg&amp;e=\" target=\"_blank\" rel=\"noreferrer noopener\">Chief Architect, Community Services for Team Cymru<\/a>, said: \u201cThis is troubling and shows the criticality of ransomware as a great threat to national security.<\/p>\n\n\n\n<p>\u201cTargeting pipelines and distribution channels like this attack on the Colonial Pipeline makes sense &#8211; ransomware is about extortion and extortion is about pressure. Impacting fuel distribution gets peoples\u2019 attention right away and means there is increased pressure on the responding teams to remediate the impact.<\/p>\n\n\n\n<p>\u201cDoing so during a time when the pandemic response has created other distribution and supply chain problems, many of which will require timely and efficient distribution of goods, adds to the pressure.<\/p>\n\n\n\n<p>\u201cThis emphasizes the need for a co-ordinated effort that bridges public and private sector capabilities to protect our national interests. We cannot think of these attacks as impacting private companies only &#8211; this is an attack on our country\u2019s infrastructure.\u201d&nbsp;&nbsp;<\/p>\n\n\n\n<p>Steve Forbes,&nbsp;Government Cybersecurity Expert at Nominet, emphasized the domino effect of the attack.<\/p>\n\n\n\n<p>\u201cThe declaration of a state of emergency due to cyberattack could become the new normal,\u201d he said. \u201cWith the largest fuel pipeline in the US grinding operations to a halt due to a ransomware attack, the attack on Colonial is likely to have a ripple effect across the globe.<\/p>\n\n\n\n<p>\u201cThe attack will be a stark reminder of how connected our world now is. While the demand for oil across the US East Coast is evident, the fact that this is already impacting the financial markets and traders, demonstrates that it really is the tip of the iceberg.<\/p>\n\n\n\n<p>\u201cThat\u2019s not to mention the fact that the severity of this breach will worsen if confidential information is leaked, as the group has threatened. Being able to take systems offline and begin a process of restoration is undeniably important, but there is an additional threat if this data is exposed. It underlines the importance of international collaboration to bring down these highly co-ordinated groups early in their development if we want to protect our critical services.<\/p>\n\n\n\n<p>\u201cAs we watch the domino effect of this cyberattack, it is very apparent that impact is not limited to systems and software &#8211; victims will come in all shapes and sizes, from industries to individuals.\u201d<\/p>\n\n\n\n<p>John Vestberg, Co-founder and CEO of Clavister, said: \u201cThe DarkSide ransomware attack on the Colonial Pipeline highlights the increasing risk cybercriminals pose to critical national infrastructure (CNI).<\/p>\n\n\n\n<p>\u201cCNI, such as oil and gas, is a prime target for these ransomware gangs \u2013 systems are underpinned by a myriad of complex information and operational technology devices and so the consequences if these are infiltrated can be devastating. Attacks on CNI risk become the norm if action is not taken.<\/p>\n\n\n\n<p>&nbsp;\u201cA proactive, rather than reactive approach is needed. Using predictive analytics and tools like AI or Machine Learning, for example, we can see malware morphing and behaving in certain ways and catch it sooner.<\/p>\n\n\n\n<p>\u201cThe DarkSide attack should serve as a warning; CNI systems are becoming more sophisticated and technical \u2013 especially as we enter the era of 5G which we will soon rely on. Going forward countries, cannot afford to have any weak spots and must step up their cybersecurity solutions to support the technology used.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Colonial Pipeline, the largest fuel pipeline in the US, has been hit by a ransomware attack resulting in the US government issuing emergency legislation. Colonial Pipeline, the largest fuel pipeline in the US, has been hit by a ransomware attack. The company was knocked offline on Friday by the activities of a cybercriminal gang with [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":6526,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[50,17,511,43,514],"tags":[1950,322,149],"class_list":["post-6525","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-east-coast","category-enterprise-security","category-intelligent-technology-newsletter","category-top-stories","category-used","tag-colonial-pipeline","tag-ransomware","tag-us"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/6525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=6525"}],"version-history":[{"count":6,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/6525\/revisions"}],"predecessor-version":[{"id":6590,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/6525\/revisions\/6590"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/6526"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=6525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=6525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=6525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}