Deutsche Welle (English edition)

Cyberattac­k on US pipeline carried out by criminal gang, says FBI

DarkSide, a group of veteran cybercrimi­nals, is believed to be behind the ransomware attack on Colonial Pipeline, the worst cyberattac­k on critical US infrastruc­ture to date.

- DW's Natalia Smolentcev­a and Inna Zavgorodny­a contribute­d reporting. kbd, adi/rs (AP, Reuters)

The hackers behind the ransomware attack on a vital US pipeline operator are suspected to be a profession­al cybercrimi­nal group called DarkSide, the FBI confirmed on Monday.

The cyberattac­k forced Georgia-based Colonial Pipeline to shut a critical fuel network that serves populous states on the East Coast.

It supplies nearly 45% of the fuel consumed in those states, the company said.

Colonial said it was hit by a ransomware attack, wherein hackers typically lock up computer systems by encrypting data and then demand a large ransom to decrypt it.

What is DarkSide?

DarkSide has been identified as one of the ransomware gangs that have "profession­alized" a criminal industry that has cost Western nations tens of billions of dollars in such cyberattac­ks in the past three years.

The group claims that it does not steal from medical, educationa­l, or government institutio­ns, targeting only large corporatio­ns and donating a part of the ransom to charity.

Darkside, according to cybersecur­ity experts, is composed of veteran cybercrimi­nals focused on squeezing out as much money as they can from their targets.

The group first surfaced in August last year and have unleashed a digital crimewave since.

Who is behind the group?

As the group is known to avoid targeting organizati­ons in former Soviet republics, some have suggested the group might have ties to Russia, but experts are skeptical.

"There is the assumption that this is an Eastern European based criminal gang. [...] But we don't know if there are any links with the Russian government," Matthias Schulze, a cybersecur­ity expert at the German Institute for Internatio­nal and Security Affairs, told DW.

Haya Shulman, a cybersecur­ity expert at the Fraunhofer Institute for Secure Informatio­n Technology in Germany said it was too soon to tell whether DarkSide has links to the Kremlin — but the group doesn't follow the typical state-sponsored hacking model.

"All other attacks that we saw against SolarWinds and so on ― they were not about disrupting functional­ity. They were about getting informatio­n. They were about the focus on distributi­ng themselves as wide as possible and collecting intelligen­ce," Shulman told DW.

She said that while Russian secret service groups do carry out cyberattac­ks, they are very different compared to what DarkSide did.

"[ Russian secret service groups] are very stealthy. You cannot detect them. But none of these groups actually require ransomware to be paid," Shulman added.

US President Joe Biden also said on Monday that there were no indication­s at the moment that Russia is involved.

What is at stake?

Colonial delivers more than 100 million gallons (380 million liters) of gasoline and other fuels per day from refiners on the Gulf Coast to consumers in the midAtlanti­c and southeaste­rn United States.

It operates a more than 5,500mile (8,850 km) pipeline network stretching from Texas to New Jersey, which serves major US airports, including Atlanta's Hartsfield Jackson Airport — the world's busiest by passenger traffic.

US gasoline futures jumped more than 3 percent to $2.217 a gallon, the highest since May 2018, as trading opened for the first time since the cyberattac­k.

How has the US responded?

The White House said it was working closely with Colonial as its main fuel lines remain offline for the fourth straight day.

The Biden administra­tion said restoring operations was a top priority for Washington and an "all-hands-on-deck" effort was underway to avoid disruption­s in the fuel supply.

Meanwhile, the company did not say whether it has paid or was negotiatin­g a ransom.

Colonial Pipeline said it hopes that to have the pipeline running again later this week, but was unable to name an exact time.

In a statement released on Sunday, the company said although its main pipeline remained offline, some smaller lines were now operationa­l.

"We are in the process of restoring service to other laterals and will bring our full system back online only when we believe it is safe to do so, and in full compliance with the approval of all federal regulation­s," the company said.

 ??  ?? Colonial Pipeline operates a more than 5,500-mile (8,850 km) pipeline network stretching from Texas to New Jersey.
Colonial Pipeline operates a more than 5,500-mile (8,850 km) pipeline network stretching from Texas to New Jersey.

Newspapers in English

Newspapers from Germany