E-paper

Colonial Pipeline hackers say their aim is cash, not chaos

— The ransomware gang accused of crippling the leading U.S. fuel pipeline operator said on Monday that it never meant to create havoc, an unusual statement that experts saw as a sign the cybercriminals’ scheme had gone awry.

The FBI accused the group that calls itself DarkSide of a digital extortion attempt that prompted Colonial Pipeline to shut down its network, threatening extraordinary disruption as Colonial works to get America’s biggest gasoline pipeline back online by the end of the week.

A terse news release posted to DarkSide’s website did not directly mention Colonial Pipeline but, under the heading “About the latest news,” it noted that “our goal is to make money, and not creating problems for society.”

The statement did not say how much money the hackers were seeking. Colonial Pipeline did not offer any comment on the hackers’ statement and U.S. officials have said they have not been involved in ransom negotiations.

The hackers did not respond to Reuters requests for comment.

The FBI, Department of Energy and White House have all been involved in a rapid response to the hack, and a server used by the gang was shut down over the weekend.

A person familiar with the matter said on Monday that the server held Colonial data and also files stolen in other DarkSide ransomware operations in progress, and that some of the group’s other victims were in the process of being notified.

The FBI office in San Francisco, which had already been investigating DarkSide, was now involved in the law enforcement probe into the Colonial attack along with the FBI in Atlanta, near where the pipeline company is based. The FBI declined comment.

DarkSide’s statement went on to say that its hackers would launch checks on fellow cybercriminals “to avoid consequences in the future.” It added the group was “apolitical” and that observers “do not need to tie us” with any particular government.

The statement, which had several spelling and grammatical errors, appeared geared toward lowering the political temperature around one of the most disruptive digital extortion schemes ever reported.

World Business

en-kr

2021-05-12T07:00:00.0000000Z

2021-05-12T07:00:00.0000000Z

https://ktimes.pressreader.com/article/281818581711875

The Korea Times Co.