The US Department of Justice on Monday announced that it had recovered more than half of the US4.4 million paid by Colonial Pipeline to Russia-based ransomware extortionists Darkside, which had forced the shutdown of a major fuel network.
“Today, we turned the tables on Darkside by going after the entire ecosystem that fuels ransomware and digital extortion attacks, including criminal proceeds in the form of digital currency,” US Deputy Attorney General Lisa Monaco said.
The seizure came one month after the group gave the US government a security scare by breaking into the computer systems of Colonial and forcing the shutdown of its 8,850km pipeline mainly serving the eastern US.
Photo: Bloomberg
The cyberattack caused short-term fuel shortages and drew attention to the broader threat that the burgeoning ransomware “industry” posed to essential infrastructure and services.
The justice department said the FBI was able to track the 75 bitcoin Colonial paid in ransom — US4.4 million at the time — as it moved through multiple anonymous transfers.
Eventually it was able to seize from a cryptocurrency wallet 63.7 bitcoin, which due to the digital currency’s fall over the past month, was only worth US$2.3 million on Monday.
Colonial CEO Joseph Blount thanked the FBI for its “swift work and professionalism,” saying the company had “quietly and quickly” contacted its agents when it detected the attack on May 7.
“Holding cybercriminals accountable and disrupting the ecosystem that allows them to operate is the best way to deter and defend against future attacks,” he said in a statement.
It was the first seizure of a paid ransom by the department’s new Ransomware and Digital Extortion Task Force, tasked to go after the so-called “ransomware as a service” industry that has extracted hundreds of millions of dollars from targets like schools, local governments and businesses over the past few years.
“Ransom payments are the fuel that propels the digital extortion engine, and today’s announcement demonstrates that the United States will use all available tools to make these attacks more costly and less profitable for criminal enterprises,” Monaco said.
She gave no details on how the money was recovered from Darkside, but analysts said it could have involved FBI investigators and possibly the US military’s offensive cyberwarfare operations.
One week after Colonial was forced to shut its operations on May 7, an online comment believed to be by Darkside operator “Darksupp” admitted that it had lost control of part of its operating infrastructure, including payment and other servers, and that ransom payments had been removed from its servers. Its dark Web site also went down.
Cybersecurity experts say many of the independent ransomware extortionists appear to be located in Russia or former Soviet satellites in eastern Europe. The attacks have grown so frequent that the issue has been elevated in seriousness in the justice department to the level of terror attacks.
‘IN A DIFFERENT PLACE’: The envoy first visited Shanghai, where he attended a Chinese basketball playoff match, and is to meet top officials in Beijing tomorrow US Secretary of State Antony Blinken yesterday arrived in China on his second visit in a year as the US ramps up pressure on its rival over its support for Russia while also seeking to manage tensions with Beijing. The US diplomat tomorrow is to meet China’s top brass in Beijing, where he is also expected to plead for restraint as Taiwan inaugurates president-elect William Lai (賴清德), and to raise US concerns on Chinese trade practices. However, Blinken is also seeking to stabilize ties, with tensions between the world’s two largest economies easing since his previous visit in June last year. At the
UNSETTLING IMAGES: The scene took place in front of TV crews covering the Trump trial, with a CNN anchor calling it an ‘emotional and unbelievably disturbing moment’ A man who doused himself in an accelerant and set himself on fire outside the courthouse where former US president Donald Trump is on trial has died, police said yesterday. The New York City Police Department (NYPD) said the man was declared dead by staff at an area hospital. The man was in Collect Pond Park at about 1:30pm on Friday when he took out pamphlets espousing conspiracy theories, tossed them around, then doused himself in an accelerant and set himself on fire, officials and witnesses said. A large number of police officers were nearby when it happened. Some officers and bystanders rushed
Beijing is continuing to commit genocide and crimes against humanity against Uyghurs and other Muslim minorities in its western Xinjiang province, U.S. Secretary of State Antony Blinken said in a report published on Monday, ahead of his planned visit to China this week. The State Department’s annual human rights report, which documents abuses recorded all over the world during the previous calendar year, repeated language from previous years on the treatment of Muslims in Xinjiang, but the publication raises the issue ahead of delicate talks, including on the war in Ukraine and global trade, between the top U.S. diplomat and Chinese
RIVER TRAGEDY: Local fishers and residents helped rescue people after the vessel capsized, while motorbike taxis evacuated some of the injured At least 58 people going to a funeral died after their overloaded river boat capsized in the Central African Republic’s (CAR) capital, Bangui, the head of civil protection said on Saturday. “We were able to extract 58 lifeless bodies,” Thomas Djimasse told Radio Guira. “We don’t know the total number of people who are underwater. According to witnesses and videos on social media, the wooden boat was carrying more than 300 people — some standing and others perched on wooden structures — when it sank on the Mpoko River on Friday. The vessel was heading to the funeral of a village chief in