[ad_1]
The president of Colonial Pipeline told US senators Tuesday that hackers who launched a cyberattack last month against the company and disrupted fuel supplies to the southeastern United States gained access to the system by stealing a single password.
Joseph Blount, CEO of Colonial Pipeline, told a US Senate committee that the attack took place using an outdated virtual private network (VPN) system that did not have multi-factor authentication. This means it can be accessed with a password without a second step like a text message, which is a common security protection in newer software.
“In the case of this old VPN, it only had one-factor authentication,” Blount said. “It was a complex password, I want to make it clear. It wasn’t a Colonial123 password.”
The commission met to examine threats to critical infrastructure to the United States and the colonial offensive, which had shut down key channels that transport fuel from Gulf Coast refineries to key East Coast markets. Cyber attacks have also hit US meatpacking plants owned by JBS Corporation (JBSS3.SA), demonstrating the breadth of infrastructure facing cyber threats.
Senators said during the hearing that the Colonial pipeline hack showed that much of the company’s infrastructure is still very weak and government and companies must work even harder to prevent the breach in the future.
Security experts describe the use of a single-factor login system as a sign of poor “cleanliness” cybersecurity. They recommend two-factor authentication, which requires a secondary action such as a mobile text or hardware token, and most major companies require this across all internal applications.
Senators asked Blount about the company’s preparations and timetable for responding to the ransomware attack, which shut down the line for days and led to soaring gasoline prices, panic buying and local fuel shortages. Read more
“I am disturbed that this breach occurred in the first place,” said Senator Gary Peters, chair of the committee. “Make no mistake: If we do not increase our cybersecurity preparedness, the consequences will be dire.”
The FBI attributed the hack to a gang called DarkSide. Some senators noted that Colonial did not adequately consult with the US government before paying the ransom against federal guidelines.
Joseph Blount, Jr., President and CEO of Colonial Pipeline is sworn in while attending a hearing examining threats to critical infrastructure, focusing on the examination of the cyber attack on Colonial Pipeline at the U.S. Capitol in Washington, U.S., June 8, 2021. Andrew Caballero Reynolds/Paul via Reuters
Read more
Blount said he made the decision to pay the ransom and keep the payments as confidential as possible out of security concerns.
“Our understanding was that it was ours alone to pay the ransom,” he said.
Blount said Colonial does not have a plan to prevent a ransomware attack, but it does have an emergency response plan. The company notified the FBI within hours.
Blount said Colonial has invested more than $200 million over the past five years in its IT systems. Pressed to answer how much Colonial had spent to maintain the security of its electronic pipeline, Blount repeated that amount. A company spokesperson later clarified that $200 million was earmarked for information technology in general, which includes cybersecurity.
On Friday, Deputy US Attorney Lisa Monaco urged companies to tell federal authorities whether they have paid a ransom to cyber attackers, information that could help investigators.
Blount said that even after getting the key from hackers, the company is still recovering from the attack and is bringing back seven financial systems that have been offline since May 7. read more
On Monday, the Department of Justice said it has recovered about $2.3 million in crypto ransom paid by Colonial Pipeline.
Colonial Pipeline previously said it paid hackers nearly $5 million to regain access. The value of the cryptocurrency bitcoin has fallen below $35,000 in recent weeks after hitting $63,000 in April.
As a result, the government has recovered about 60 of the 75 bitcoins paid, but the value has gone down, less than the total dollar amount the colonel paid.
Bitcoin seizures are rare, but authorities have beefed up their expertise in tracking the flow of digital money as ransomware becomes a growing threat to national security and further strains relations between the United States and Russia, where many gangs are based.
Our Standards: Thomson Reuters Trust Principles.
.
[ad_2]
Picture Credit!