/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

DarkSide, the group behind the pipeline attack, claims it wants to make money, not cause “problems for society”, and it'll add “moderation” to picking targets

- A hacker group called DarkSide is behind the cyberattack on Colonial Pipeline that shut down a major oil pipeline over the weekend.

CNBC Eamon Javers

Context & Ripple Effects

Reports tied the Colonial disruption to a ransomware operation that stole and encrypted roughly 100GB of data before demanding payment. DarkSide's proposed target moderation is therefore an attempted constraint on a model that combines data theft with operational disruption.

The group’s stated limits also sit uneasily with the later account that Colonial restarted after five days of shutdown. Subsequent reports that DarkSide lost access to its servers and funds further show how quickly a criminal operation’s public posture can be overtaken by pressure on its infrastructure.

First-order effects

  • Colonial Pipeline faces the immediate operational consequences of the attack, while DarkSide publicly commits to screening targets more selectively.
  • DarkSide’s moderation pledge changes its stated target-selection policy, but not the extortion model described in reports of stolen and encrypted data.

Second-order effects

  • For Colonial and other operators, the episode makes service continuity a central ransomware exposure alongside data loss, because the attack interrupted operations as well as exfiltrated information.
  • DarkSide’s claim of self-restraint becomes less credible as a risk control after its own reported loss of servers and funds, leaving victims unable to treat attacker assurances as dependable.

Third-order effects

  • Ransomware groups are increasingly forced to manage the political and operational fallout of attacks on essential services, even when their stated objective is financial gain.
  • If attacks continue to pair data theft with disruption of critical operators, cyber defense will be judged more by resilience and recovery than by preventing data loss alone.

The trend: Ransomware is moving from a data-extortion problem toward a critical-services resilience problem, with criminal groups attempting—unreliably—to police their own target boundaries.

Discussion

  • @ddd1ms @ddd1ms on x
    DarkSide #ransomware Leaks Press Center: https://twitter.com/...
  • @thestalwart Joe Weisenthal on x
    The hackers that shut down the gasoline pipeline have apologized. They say they never wanted to cause all this disruption and that they just wanted to make money. They've promised to do better going forward. https://www.bloomberg.com/... https://twitter.com/...
  • @nicoleperlroth Nicole Perlroth on x
    The assumption is that Darkside is not nation state affiliated, but like oh-so-many ransomware groups it uses tools like “GetUserDefaultLangID” to perform language checks. If the victim uses any languages below, DarkSide moves on. https://twitter.com/... https://twitter.com/...
  • @alexstamos Alex Stamos on x
    People discussing the relationship between ransomware teams and the Russian government should probably keep @Jason_Healey's “Spectrum of National Responsibility” in mind. Right now, it looks like the Darkside group that attacked Colonial is at least “State-Encouraged”. https://tw…
  • @josephfcox Joseph Cox on x
    New: in a statement published to their dark web site, the ransomware group behind the Colonial Pipeline incident says they're “apolitical” and will choose their targets more carefully next time (whoopsie my bad my bad) https://www.vice.com/...
  • @nicoleperlroth Nicole Perlroth on x
    The criminals responsible, Darkside, are a relative newcomer to ransomware, but have an intriguing “code of conduct.” They will not extort hospitals, funeral homes, non profits. They do target large corps and sometimes donate some proceeds to charities (that return the $).
  • @hacks4pancakes Lesley Carhart on x
    I don't think people appreciate how effectively Darkside has been ramping up operations mostly under the radar for the last year. This was a very big “oops”. They were doing a really good job of decimating businesses, including infrastructure - and everyone has been really quiet.
  • @nicoleperlroth Nicole Perlroth on x
    The ransomware attack on Colonial Pipeline has prompted emergency meetings as the White House finalizes its cybersecurity Executive Order. With new details on the attack and the EO w/ @SangerNYT https://www.nytimes.com/...
  • @hacks4pancakes Lesley Carhart on x
    I keep seeing tweet after tweet lately from my fellow incident responders about preparing for and deterring ransomware attacks, and they are *not* kidding. Things are escalating fast - including the brazenness, cruelty, and quantity. Insurers will only pay out when they must.
  • @alexstamos Alex Stamos on x
    @klonkitchen @riskybusiness @C_C_Krebs @thegrugq I think you can believe both “this wasn't centrally coordinated” as well as “the Russian state has enough responsibility for this to justify a punishing response”. https://twitter.com/...
  • @meyerweb @meyerweb on x
    This is the cyberpunk future I was promised. https://twitter.com/...
  • @rubengallego Ruben Gallego on x
    If there are no consequences, then there is no deterrence. If there is no deterrence, all transnational cyber terrorist organizations can prey on the US. Either the hackers have to pay or the Russians who protect them have to pay. https://twitter.com/...
  • @repscottpeters Rep. Scott Peters on x
    This is exactly why we need to modernize and secure our energy grid. Our outdated infrastructure will no longer hold up to the challenge of cyber threats. For our national protection, we need to build a more resilient, fortified energy system. https://www.nytimes.com/...
  • @peterwsinger Peter W. Singer on x
    Lesson of Colonial gas cyberattack: We all need to prepare for a future world where physical systems are frequently attacked and held hostage https://www.nytimes.com/... #BurnInBook moment, coming true
  • @hacks4pancakes Lesley Carhart on x
    A lot of firms are going to be out there shilling magic boxes to fix “everything” in the coming weeks, but while the malware and anti-forensics in these cases are often quite sophisticated, we see the same lack of security hygiene and basic defense in depth exploited repeatedly.
  • @thestalwart Joe Weisenthal on x
    Please read my latest Medium piece: What Social Media Companies Can Learn About Moderation From Ransomware Hackers
  • @hacks4pancakes Lesley Carhart on x
    But it's happening like, all the time - IR firms can't hire analysts fast enough. That also means there are a lot of predatory and unqualified IR firms at the top of Google searches right now.
  • @_sidverma Sid Verma on x
    Pipeline hackers sounding like they just sent out a problematic tweet is more confirmation that Twitter = real life https://twitter.com/...
  • @thebriandonohue Brian Donohue on x
    We take on hundreds of ransomware-related short term IR engagements every year. Lately we've seen a few different ransomware families renaming utilities that adversaries use to upload stolen files to the Mega file sharing service. https://twitter.com/...
  • @vice @vice on x
    “We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for other our motives,” the group responsible for the hack said. https://www.vice.com/...
  • @nicoleperlroth Nicole Perlroth on x
    FBI now confirming DarkSide. https://twitter.com/...
  • @markwarner Mark Warner on x
    It's been clear for years that our nation's cybersecurity hasn't kept pace with our ever-increasing reliance on digital systems and internet connectivity across all sectors. The result has left us vulnerable to foreign adversaries & cyber-criminals, alike. https://www.nytimes.com…
  • @peoples_histpdx @peoples_histpdx on x
    friday 5/7, a ransomware group halted 5500 miles of a gasoline and jet fuel pipeline in texas. this 5500 mile stretch of pipeline carries 45% of the east coast's fuel supplies. https://www.nytimes.com/...
  • @rvawonk Caroline Orr Bueno, Ph.D on x
    This seems like it should be getting more attention: A Russian criminal group may be responsible for the ransomware attack that shut down Colonial Pipeline, the largest fuel pipeline on the East Coast. https://www.nbcnews.com/...
  • @armandondk Armando on x
    I like the “we just do it for money” defense. https://twitter.com/...
  • @ericgeller Eric Geller on x
    A strange statement from a group that experts describe as highly professional, organized, and careful. Perhaps all the attention around their hack of Colonial Pipeline has given them cold feet. https://twitter.com/...
  • @stevekovach Steve Kovach on x
    New statement from DarkSide, the hacking group likely responsible for Colonial Pipeline attack, via @EamonJavers: “We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for our motives...” https://www.cnbc.com/...
  • @josephfcox Joseph Cox on x
    DarkSide says its motive is to make money, but more interestingly says it will “introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future.” Causing a fuel line shutdown not a great look. https://www.vice.com/... https…
  • @iblametom Thomas Brewster on x
    This is an interesting post from the DarkSide group linked to the Colonial Pipeline hack - seems they're trying to put the blame on a customer. Recall they offer ransomware-as-a-service. They may also be loose with the truth. https://twitter.com/...
  • Vox Sara Morrison on x
    How a major oil pipeline got held for ransom
  • @zackwhittaker Zack Whittaker on x
    New statement from Colonial Pipeline at 12:25pm ET, says its goal of substantially restoring operational service “by the end of the week” following ransomware attack.
  • @senatormenendez Senator Bob Menendez on x
    To be clear, cybersecurity IS infrastructure. The potential damage that these attacks present to our country are a matter of national security that we simply cannot afford to ignore. We must do more to mitigate its impact and defend against future attacks. https://www.wsj.com/...
  • @malwarejake Jake Williams on x
    Products don't stop cyberattacks, process does. https://twitter.com/...
  • @julianbarnes Julian E. Barnes on x
    Biden admin is preparing a EO on cyber defense and @SangerNYT has the details. It won't really address the SolarWinds type vulnerability but could boost cyber hygiene which could prevent hacks like the Pipeline ransomware incident. W/ @nicoleperlroth https://www.nytimes.com/...
  • @tonyt2thomas Tony Thomas on x
    This a huge deal. Imagine anything and everything based on a “grid” (power, banking, internet links, etc.) being switched off/held for ransom. Yet we still have many companies and much of the USG just making the big hand wave for cyber security. https://www.bbc.com/...
  • @samjmintz Sam Mintz on x
    New: In response to Colonial Pipeline shutdown, DOT eases hours of service rules for truck drivers transporting gasoline, diesel, jet fuel and other refined petroleum products to 18 states https://www.fmcsa.dot.gov/...
  • @osinttechnical @osinttechnical on x
    DarkSide is definitely one of the more professional hacker groups, and they show it. They have a mailing list, a press center, and a victim hotline. One of the weird things is that they popped up out of nowhere and began hitting targets hard and fast. https://twitter.com/...
  • @ngleicher Nathaniel Gleicher on x
    The most striking thing about this incident is how many times it has been predicted by so many security experts. We are fascinated with sudden, genius hacks ("zero-days"), but most serious threats are more like long-observed trains crashing in slow motion. https://www.wired.com/.…
  • @digieconomist Digiconomist on x
    In before “Bitcoin is great for the environment because it enables ransomware that takes down fossil fuels” https://twitter.com/...
  • @kimzetter Kim Zetter on x
    Ransomware infection at Colonial Pipeline only infected its IT network; but according to source I spoke to it had potential to spread to operational network and even to upstream oil suppliers whose control systems connect directly to Colonial's systems https://zetter.substack.com…
  • @rvawonk Caroline Orr Bueno, Ph.D on x
    This comes just a month after the DOJ launched a “ransomware task force” amid a surge in ransomware attacks targeting critical infrastructure and government systems. https://twitter.com/...
  • @carlquintanilla Carl Quintanilla on x
    (FT) - The US government declared a state of emergency on Sunday in a bid to keep fuel supply lines open as fears of shortages rose following the shutdown of a major pipeline. ⁦@FT⁩ ⁦@LiveSquawk⁩ https://www.ft.com/...
  • @martinsfp Martin Sfp Bryant on x
    Wow. Ransomware really is a blight on the modern world that needs stamping out. US declares state of emergency to keep fuel flowing after cyber attack https://giftarticle.ft.com/...
  • @shaneharris Shane Harris on x
    So if shutting down a pipeline (or causing it to shut down) is a hostile act justifying the use of state force in response (as plenty of experts would argue), what happens when the offender is a stateless criminal group, presuming the state where it resides is not supporting it? …
  • @emptywheel @emptywheel on x
    It was wrong to treat Solar Winds as something other than normal espionage. But this is going to pose some really uncomfortable questions. https://twitter.com/...
  • @peterzeihan Peter Zeihan on x
    These cyber groups are a bit like mercenaries. Formally, they are not affiliated with governments. Informally, they have a truce with the Kremlin. So long as they don't target Russians, they have free rein. And sometimes, the Kremlin asks for...a favor. https://www.wsj.com/...
  • @dnvolz Dustin Volz on x
    Biden just now on pipeline hack: “So far there is no evidence from our intelligence people that Russia is involved. Although there is some evidence that the actors' ransomware is in Russia. They have some responsibility to deal with this.” https://www.wsj.com/...
  • @thestalwart Joe Weisenthal on x
    Colonial says that the pipeline will be reopened within days and that parts of it are already getting opened up. https://www.bloomberg.com/... https://twitter.com/...
  • @iansherr Ian Sherr on x
    But how much will east coast gas prices jump in the interim, and how much will they fall after? https://twitter.com/...
  • @dnvolz Dustin Volz on x
    FBI says DarkSide is behind Colonial Pipeline hack. FBI sent out an internal bulletin Friday asking for any info on the criminal gang, which has eastern European ties. Meanwhile Colonial says they hope to substantially restore operations by end of week. https://www.wsj.com/...