DarkSide, the group behind the pipeline attack, claims it wants to make money, not cause “problems for society”, and it'll add “moderation” to picking targets
- A hacker group called DarkSide is behind the cyberattack on Colonial Pipeline that shut down a major oil pipeline over the weekend.
CNBC Eamon Javers
Context & Ripple Effects
Reports tied the Colonial disruption to a ransomware operation that stole and encrypted roughly 100GB of data before demanding payment. DarkSide's proposed target moderation is therefore an attempted constraint on a model that combines data theft with operational disruption.
The group’s stated limits also sit uneasily with the later account that Colonial restarted after five days of shutdown. Subsequent reports that DarkSide lost access to its servers and funds further show how quickly a criminal operation’s public posture can be overtaken by pressure on its infrastructure.
First-order effects
- Colonial Pipeline faces the immediate operational consequences of the attack, while DarkSide publicly commits to screening targets more selectively.
- DarkSide’s moderation pledge changes its stated target-selection policy, but not the extortion model described in reports of stolen and encrypted data.
Second-order effects
- For Colonial and other operators, the episode makes service continuity a central ransomware exposure alongside data loss, because the attack interrupted operations as well as exfiltrated information.
- DarkSide’s claim of self-restraint becomes less credible as a risk control after its own reported loss of servers and funds, leaving victims unable to treat attacker assurances as dependable.
Third-order effects
- Ransomware groups are increasingly forced to manage the political and operational fallout of attacks on essential services, even when their stated objective is financial gain.
- If attacks continue to pair data theft with disruption of critical operators, cyber defense will be judged more by resilience and recovery than by preventing data loss alone.
The trend: Ransomware is moving from a data-extortion problem toward a critical-services resilience problem, with criminal groups attempting—unreliably—to police their own target boundaries.
Related: Security-to-policy pipeline · Ecosystem cyber defense · Colonial Pipeline · DarkSide stole and encrypted data before demanding ransom · DarkSide reportedly lost control of servers and funds
Related Coverage
- FBI Statement on Compromise of Colonial Pipeline Networks FBI
- View article Threatpost
- Gas Stations Run Dry as Pipeline Hack Will Take Days to Fix Bloomberg
- Pipeline Hackers Say They're ‘Apolitical,’ Will Choose Targets More Carefully Next Time VICE · Joseph Cox
- View article New York Times
- View article Protos
- Hackers who shut down pipeline: We don't want to cause “problems for society” Ars Technica · Jim Salter
- DarkSide strives for “ethical hacking” after hitting a vital fuel pipeline in the US CyberNews · Chris Stokel-Walker
- US Questions Whether Businesses Should Pay Cyberattack Ransom PYMNTS.com
- As Colonial Pipeline scrambles to restore services, ransomware gang vows to be more careful SiliconANGLE · Duncan Riley
- Ransomware: Survive by outrunning the guy next to you ZDNet
- Hackers Threatening East Coast's Fuel Supply Claim They're Not Trying to Cause Anybody Trouble Gizmodo · Lucas Ropek
- Biden: No evidence Russian government is involved in Colonial ransomware attack The Record · Catalin Cimpanu
- DarkSide was responsible for Colonial Pipeline ransomware attack, promises to pick targets more carefully in the future TechSpot · Adrian Potoroaca
- Ransomware Hack Forces Shutdown of Largest US Oil Pipeline Tech.co · Adam Rowe
- Colonial Pipeline hack: Gas woes loom as feds take emergency steps SlashGear · Chris Davies
- DarkSide ransomware will now vet targets after pipeline cyberattack BleepingComputer · Lawrence Abrams
- Colonial Pipeline aims to be “substantially” back online by end of week Axios · Zachary Basu
- As Colonial Pipeline scrambles to restore services, ransomware gang promises to be more careful in future SiliconANGLE · Duncan Riley
- Cyberattack prompts major pipeline operator to halt operations CBS News · Grace Segers
- Colonial Pipeline hackers apologize, promise to ransom less controversial targets in future The Verge · Mitchell Clark
- What you need to know about the Colonial Pipeline hack Politico · Eric Geller
- Colonial Pipeline Cyberattack: What Security Pros Need to Know Dark Reading · Kelly Sheridan
- What to know about the Colonial Pipeline cyberattack Axios · Ben Geman
- Gas stations along Southeast Coast suffer fuel shortage amid pipeline shutdown New York Post · Will Feuer
- Media Statement Update: Colonial Pipeline System Disruption Colonial Pipeline
- Everything you need to know about the Colonial Pipeline ransomware attack ZDNet · Charlie Osborne
- FBI Statement on Network Disruption at Colonial Pipeline Federal Bureau of Investigation
- FBI Blames DarkSide on Colonial Pipeline Cyberattack Softpedia News · George Dascalu
- US fuel pipeline hackers 'didn't mean to create problems' BBC · Mary-Ann Russon
- Colonial pipeline hackers say they're ‘apolitical’ and only out to make money Engadget
- The DarkSide ransomware gang must be shitting itself right now Graham Cluley
- F.B.I. Identifies Group Behind Pipeline Hack New York Times
- US opens debate over cyber ransom payments after pipeline hack Financial Times
- Attackers wanted cash from the Colonial Pipeline cyberattack, not chaos VentureBeat
- What We Know About The Ransomware Attack On A Critical U.S. Pipeline NPR · Scott Neuman
- Colonial Pipeline's Ransomware Attack Sparks Emergency Declaration Threatpost · Lisa Vaas
- Colonial Pipeline ransomware attack has grave consequences ComputerWeekly.com · Alex Scroxton
- U.S. Declares Emergency in 17 States Over Fuel Pipeline Cyber Attack The Hacker News · Ravie Lakshmanan
- US passes emergency waiver over fuel pipeline cyber-attack BBC · Mary-Ann Russon
- Ransomware Attack That Halted US Fuel Pipeline a ‘Criminal Act,’ Biden Says Voice of America · Steve Herman
- Gasoline futures rise slightly following earlier spike as pipeline set to be restored by week's end CNBC · Pippa Stevens
- DarkSide Ransomware Hit Colonial Pipeline—and Created an Unholy Mess Wired · Lily Hay Newman
- The cybersecurity ‘pandemic’ that led to the Colonial Pipeline disaster The Verge · Justine Calma
- FBI confirmed that Darkside ransomware gang hit Colonial Pipeline Security Affairs · Pierluigi Paganini
- Fascinating details emerge about the Russian hackers who attacked a major US fuel pipeline BGR · Andy Meek
- Inside the DarkSide Ransomware Attack on Colonial Pipeline Security Boulevard · David Bisson
- FBI Confirms DarkSide Russian Hacking Gang Tied To Colonial Pipeline Ransomware Attack HotHardware.com News · Nathan Ord
- Colonial Pipeline Cyberattack: Restoration Expected This Week CRN · Michael Novinson
- Russian hacking group DarkSide shuts down largest U.S. fuel pipeline Input · Andrew Paul
- FBI blames DarkSide ransomware operators for Colonial Pipeline incident CyberScoop · Sean Lyngaas
- Biden says no evidence Russian government was involved in pipeline hack NBC News · Lauren Egan
- Colonial Pipeline attack ratchets up ransomware game TechRepublic · Lance Whitney
- FBI: Colonial Pipeline Hacked By ‘Apolitical’ Group DarkSide Forbes · Christopher Helman
- Ransomware attack takes down US' largest fuel pipeline RCR Wireless News · Kelly Hill
- Ransomware Finally Came for the One Thing Americans Care About: Gas Prices VICE · Aaron Gordon
- What's happening with Colonial Pipeline? Outage continues after ransomware attack Fast Company · Steven Melendez
- Criminal group originating from Russia believed to be behind pipeline cyberattack CNN
- Colonial Pipeline attack: What government can do to deter critical infrastructure cybercriminals SC Media · Joe Uchill
- FBI Confirms Colonial Pipeline Hit by DarkSide Ransomware PCMag · Chloe Albanesius
- FBI Identifies Suspects In Colonial Pipeline Hack PYMNTS.com
Discussion
-
@ddd1ms
@ddd1ms
on x
DarkSide #ransomware Leaks Press Center: https://twitter.com/...
-
@thestalwart
Joe Weisenthal
on x
The hackers that shut down the gasoline pipeline have apologized. They say they never wanted to cause all this disruption and that they just wanted to make money. They've promised to do better going forward. https://www.bloomberg.com/... https://twitter.com/...
-
@nicoleperlroth
Nicole Perlroth
on x
The assumption is that Darkside is not nation state affiliated, but like oh-so-many ransomware groups it uses tools like “GetUserDefaultLangID” to perform language checks. If the victim uses any languages below, DarkSide moves on. https://twitter.com/... https://twitter.com/...
-
@alexstamos
Alex Stamos
on x
People discussing the relationship between ransomware teams and the Russian government should probably keep @Jason_Healey's “Spectrum of National Responsibility” in mind. Right now, it looks like the Darkside group that attacked Colonial is at least “State-Encouraged”. https://tw…
-
@josephfcox
Joseph Cox
on x
New: in a statement published to their dark web site, the ransomware group behind the Colonial Pipeline incident says they're “apolitical” and will choose their targets more carefully next time (whoopsie my bad my bad) https://www.vice.com/...
-
@nicoleperlroth
Nicole Perlroth
on x
The criminals responsible, Darkside, are a relative newcomer to ransomware, but have an intriguing “code of conduct.” They will not extort hospitals, funeral homes, non profits. They do target large corps and sometimes donate some proceeds to charities (that return the $).
-
@hacks4pancakes
Lesley Carhart
on x
I don't think people appreciate how effectively Darkside has been ramping up operations mostly under the radar for the last year. This was a very big “oops”. They were doing a really good job of decimating businesses, including infrastructure - and everyone has been really quiet.
-
@nicoleperlroth
Nicole Perlroth
on x
The ransomware attack on Colonial Pipeline has prompted emergency meetings as the White House finalizes its cybersecurity Executive Order. With new details on the attack and the EO w/ @SangerNYT https://www.nytimes.com/...
-
@hacks4pancakes
Lesley Carhart
on x
I keep seeing tweet after tweet lately from my fellow incident responders about preparing for and deterring ransomware attacks, and they are *not* kidding. Things are escalating fast - including the brazenness, cruelty, and quantity. Insurers will only pay out when they must.
-
@alexstamos
Alex Stamos
on x
@klonkitchen @riskybusiness @C_C_Krebs @thegrugq I think you can believe both “this wasn't centrally coordinated” as well as “the Russian state has enough responsibility for this to justify a punishing response”. https://twitter.com/...
-
@meyerweb
@meyerweb
on x
This is the cyberpunk future I was promised. https://twitter.com/...
-
@rubengallego
Ruben Gallego
on x
If there are no consequences, then there is no deterrence. If there is no deterrence, all transnational cyber terrorist organizations can prey on the US. Either the hackers have to pay or the Russians who protect them have to pay. https://twitter.com/...
-
@repscottpeters
Rep. Scott Peters
on x
This is exactly why we need to modernize and secure our energy grid. Our outdated infrastructure will no longer hold up to the challenge of cyber threats. For our national protection, we need to build a more resilient, fortified energy system. https://www.nytimes.com/...
-
@peterwsinger
Peter W. Singer
on x
Lesson of Colonial gas cyberattack: We all need to prepare for a future world where physical systems are frequently attacked and held hostage https://www.nytimes.com/... #BurnInBook moment, coming true
-
@hacks4pancakes
Lesley Carhart
on x
A lot of firms are going to be out there shilling magic boxes to fix “everything” in the coming weeks, but while the malware and anti-forensics in these cases are often quite sophisticated, we see the same lack of security hygiene and basic defense in depth exploited repeatedly.
-
@thestalwart
Joe Weisenthal
on x
Please read my latest Medium piece: What Social Media Companies Can Learn About Moderation From Ransomware Hackers
-
@hacks4pancakes
Lesley Carhart
on x
But it's happening like, all the time - IR firms can't hire analysts fast enough. That also means there are a lot of predatory and unqualified IR firms at the top of Google searches right now.
-
@_sidverma
Sid Verma
on x
Pipeline hackers sounding like they just sent out a problematic tweet is more confirmation that Twitter = real life https://twitter.com/...
-
@thebriandonohue
Brian Donohue
on x
We take on hundreds of ransomware-related short term IR engagements every year. Lately we've seen a few different ransomware families renaming utilities that adversaries use to upload stolen files to the Mega file sharing service. https://twitter.com/...
-
@vice
@vice
on x
“We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for other our motives,” the group responsible for the hack said. https://www.vice.com/...
-
@nicoleperlroth
Nicole Perlroth
on x
FBI now confirming DarkSide. https://twitter.com/...
-
@markwarner
Mark Warner
on x
It's been clear for years that our nation's cybersecurity hasn't kept pace with our ever-increasing reliance on digital systems and internet connectivity across all sectors. The result has left us vulnerable to foreign adversaries & cyber-criminals, alike. https://www.nytimes.com…
-
@peoples_histpdx
@peoples_histpdx
on x
friday 5/7, a ransomware group halted 5500 miles of a gasoline and jet fuel pipeline in texas. this 5500 mile stretch of pipeline carries 45% of the east coast's fuel supplies. https://www.nytimes.com/...
-
@rvawonk
Caroline Orr Bueno, Ph.D
on x
This seems like it should be getting more attention: A Russian criminal group may be responsible for the ransomware attack that shut down Colonial Pipeline, the largest fuel pipeline on the East Coast. https://www.nbcnews.com/...
-
@armandondk
Armando
on x
I like the “we just do it for money” defense. https://twitter.com/...
-
@ericgeller
Eric Geller
on x
A strange statement from a group that experts describe as highly professional, organized, and careful. Perhaps all the attention around their hack of Colonial Pipeline has given them cold feet. https://twitter.com/...
-
@stevekovach
Steve Kovach
on x
New statement from DarkSide, the hacking group likely responsible for Colonial Pipeline attack, via @EamonJavers: “We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for our motives...” https://www.cnbc.com/...
-
@josephfcox
Joseph Cox
on x
DarkSide says its motive is to make money, but more interestingly says it will “introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future.” Causing a fuel line shutdown not a great look. https://www.vice.com/... https…
-
@iblametom
Thomas Brewster
on x
This is an interesting post from the DarkSide group linked to the Colonial Pipeline hack - seems they're trying to put the blame on a customer. Recall they offer ransomware-as-a-service. They may also be loose with the truth. https://twitter.com/...
-
Vox
Sara Morrison
on x
How a major oil pipeline got held for ransom
-
@zackwhittaker
Zack Whittaker
on x
New statement from Colonial Pipeline at 12:25pm ET, says its goal of substantially restoring operational service “by the end of the week” following ransomware attack.
-
@senatormenendez
Senator Bob Menendez
on x
To be clear, cybersecurity IS infrastructure. The potential damage that these attacks present to our country are a matter of national security that we simply cannot afford to ignore. We must do more to mitigate its impact and defend against future attacks. https://www.wsj.com/...
-
@malwarejake
Jake Williams
on x
Products don't stop cyberattacks, process does. https://twitter.com/...
-
@julianbarnes
Julian E. Barnes
on x
Biden admin is preparing a EO on cyber defense and @SangerNYT has the details. It won't really address the SolarWinds type vulnerability but could boost cyber hygiene which could prevent hacks like the Pipeline ransomware incident. W/ @nicoleperlroth https://www.nytimes.com/...
-
@tonyt2thomas
Tony Thomas
on x
This a huge deal. Imagine anything and everything based on a “grid” (power, banking, internet links, etc.) being switched off/held for ransom. Yet we still have many companies and much of the USG just making the big hand wave for cyber security. https://www.bbc.com/...
-
@samjmintz
Sam Mintz
on x
New: In response to Colonial Pipeline shutdown, DOT eases hours of service rules for truck drivers transporting gasoline, diesel, jet fuel and other refined petroleum products to 18 states https://www.fmcsa.dot.gov/...
-
@osinttechnical
@osinttechnical
on x
DarkSide is definitely one of the more professional hacker groups, and they show it. They have a mailing list, a press center, and a victim hotline. One of the weird things is that they popped up out of nowhere and began hitting targets hard and fast. https://twitter.com/...
-
@ngleicher
Nathaniel Gleicher
on x
The most striking thing about this incident is how many times it has been predicted by so many security experts. We are fascinated with sudden, genius hacks ("zero-days"), but most serious threats are more like long-observed trains crashing in slow motion. https://www.wired.com/.…
-
@digieconomist
Digiconomist
on x
In before “Bitcoin is great for the environment because it enables ransomware that takes down fossil fuels” https://twitter.com/...
-
@kimzetter
Kim Zetter
on x
Ransomware infection at Colonial Pipeline only infected its IT network; but according to source I spoke to it had potential to spread to operational network and even to upstream oil suppliers whose control systems connect directly to Colonial's systems https://zetter.substack.com…
-
@rvawonk
Caroline Orr Bueno, Ph.D
on x
This comes just a month after the DOJ launched a “ransomware task force” amid a surge in ransomware attacks targeting critical infrastructure and government systems. https://twitter.com/...
-
@carlquintanilla
Carl Quintanilla
on x
(FT) - The US government declared a state of emergency on Sunday in a bid to keep fuel supply lines open as fears of shortages rose following the shutdown of a major pipeline. @FT @LiveSquawk https://www.ft.com/...
-
@martinsfp
Martin Sfp Bryant
on x
Wow. Ransomware really is a blight on the modern world that needs stamping out. US declares state of emergency to keep fuel flowing after cyber attack https://giftarticle.ft.com/...
-
@shaneharris
Shane Harris
on x
So if shutting down a pipeline (or causing it to shut down) is a hostile act justifying the use of state force in response (as plenty of experts would argue), what happens when the offender is a stateless criminal group, presuming the state where it resides is not supporting it? …
-
@emptywheel
@emptywheel
on x
It was wrong to treat Solar Winds as something other than normal espionage. But this is going to pose some really uncomfortable questions. https://twitter.com/...
-
@peterzeihan
Peter Zeihan
on x
These cyber groups are a bit like mercenaries. Formally, they are not affiliated with governments. Informally, they have a truce with the Kremlin. So long as they don't target Russians, they have free rein. And sometimes, the Kremlin asks for...a favor. https://www.wsj.com/...
-
@dnvolz
Dustin Volz
on x
Biden just now on pipeline hack: “So far there is no evidence from our intelligence people that Russia is involved. Although there is some evidence that the actors' ransomware is in Russia. They have some responsibility to deal with this.” https://www.wsj.com/...
-
@thestalwart
Joe Weisenthal
on x
Colonial says that the pipeline will be reopened within days and that parts of it are already getting opened up. https://www.bloomberg.com/... https://twitter.com/...
-
@iansherr
Ian Sherr
on x
But how much will east coast gas prices jump in the interim, and how much will they fall after? https://twitter.com/...
-
@dnvolz
Dustin Volz
on x
FBI says DarkSide is behind Colonial Pipeline hack. FBI sent out an internal bulletin Friday asking for any info on the criminal gang, which has eastern European ties. Meanwhile Colonial says they hope to substantially restore operations by end of week. https://www.wsj.com/...