/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Sources: Colonial paid ~$5M ransom in cryptocurrency within hours of the attack, but the hackers' decrypting tool was so slow that it had to use its own backups

this should significantly escalate the political pressure to finally counter the ransomware ecosystem https://www.bloomberg.com/... Barbara Malmet / @b52malmet : Maybe it was a four hundred pound eighth grader in a basement in Russia? https://twitter.com/... @blackvaultcom : “Colonial Pipeline Co. paid nearly $5 million to Eastern European hackers on Friday, contradicting reports earlier this week that the company had no intention of paying an extortion fee...” — Heh. Watch them do it again tomorrow. 🙄 https://finance.yahoo.com/... Paolo Gregoletto / @triviumpaolo : Cyber bullying works https://twitter.com/... Dr. Carol M. Swain / @carolmswain : Welcome to Biden's world. Colonial Pipeline Paid Hackers Nearly $5 Million in Ransom https://finance.yahoo.com/... War Medic / @foxholemedicine : Great, now terrorists will be demanding a cool $50 Mil for a power grid. Was this a test run? Nice job, enablers. #WeDontNegotiate https://www.cnbc.com/... @reuters : 'So far there is no evidence based on, from our intelligence people, that Russia is involved, although there's evidence that the actors' ransomware is in Russia,' President Biden on the Colonial Pipeline hack https://www.reuters.com/... https://twitter.com/... Kim Zetter / @kimzetter : .@cnn has now confirmed what I wrote 4 days ago, that CP shut down pipeline because they couldn't bill customers. Per CNN: “The company halted operations because its billing system was compromised...and they were concerned they wouldn't be able to figure out how much to bill” https://twitter.com/... Kim Zetter / @kimzetter : .@nicoleperlroth has also confirmed that CP shut down pipeline in part because it couldn't bill customers, and in part to prevent ransomware from spreading. Big thanks to Nicole for the shoutout in this piece to my prior stories on billing issue. 🙏 https://www.nytimes.com/... Joe Concha / @joeconchatv : This sets a wonderful precedent... https://twitter.com/... BDW / @bryandeanwright : When you incentivize illegal behavior — to cross the border, to hack infrastructure — more will try. This was a disastrous decision. https://twitter.com/... Mitch Kapor / @mkapor : Sometimes it IS a pipeline problem. https://twitter.com/... Max Burns / @themaxburns : The lesson here, which our government has been slow to acknowledge for years, is that our critical civil infrastructure is so vulnerable to cyberattack that even non-state free agents can seize and ransom our own infrastructure back to us. https://finance.yahoo.com/... Denilson N. / @dnastacio : They should have paid extra for the professional edition of the decrypting tool. https://twitter.com/... Corey Quinn / @quinnypig : The real story here is that an enterprise was able to pay $5 million without six weeks of dickering with Procurement beforehand. https://twitter.com/... Kevin Collier / @kevincollier : Wild reporting from @WilliamTurton here. Very key point is that Colonial did not restore their operations by paying tha ransom, though. They paid, realized DarkSide's decryptor sucks (which we already knew), then restored from backups anyway. https://www.bloomberg.com/... @briankrebs : Bloomberg says Colonial Pipeline paid ~$5M to the DarkSide ransomware extortionists, 6 days after the company shut down 5,500 miles of fuel pipe in response to attack. https://www.bloomberg.com/... That's less than 1/2 what a similarly sized recent victim paid https://krebsonsecurity.com/ ... Thomas Brewster / @iblametom : So Colonial paid up, decrypting tool didn't work, they used their own backups to restore... and yet they still shut the pipeline down for five days? https://twitter.com/... Southpaw / @nycsouthpaw : Colonial paid the cost of approx five avg homes in Brooklyn as ransom for its pipeline data https://www.bloomberg.com/... Chuck Wendig / @chuckwendig : well that won't encourage more of the same to be sure https://twitter.com/... Robert Burgess / @bobonmarkets : Nah, crypto isn't the domain of criminals and hackers https://www.bloomberg.com/... via @business Thaddeus E. Grugq / @thegrugq : Colonial Pipeline paid $5million, according to the grain of rice backdoor people. https://www.bloomberg.com/... Keith Olbermann / @keitholbermann : But don't worry. They'll immediately share those costs with YOU, Joe Driver https://twitter.com/... Glen Gilmore / @glengilmore : Contradicting Earlier Reports, #ColonialPipeline Paid Hackers Nearly $5M in Ransom #Ransomware costs increased by 311% in 2020, reaching $350M in #cryptocurrency Average ransom paid by organizations in 2020 was $312,493 https://www.bloomberg.com/... #IoT #infrastructure https://twitter.com/... Alex Hern / @alexhern : I wonder what would happen to ransomware if the US government declared interacting with a bitcoin exchange a prima facie AML violation Joseph Cox / @josephfcox : This is bad for ransomware operators. If your tool is so crappy that even when people pay they still then have to go use their backups, why pay at all https://www.bloomberg.com/... https://twitter.com/... Brad Stone / @bradstone : incredible and terrifying. https://twitter.com/... Matthew Green / @matthew_d_green : I'm definitely in the wrong job. https://www.bloomberg.com/... Hamza Shaban / @hshaban : Once the hackers received the $5 million in crypto, they gave Colonial Pipeline a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system https://www.bloomberg.com/... Secretary Jennifer Granholm / @secgranholm : We just got off the phone with #ColonialPipeline CEO. They are restarting pipeline operations today at ~5pm. More soon. Frank Bajak / @fbajak : Audit of Colonial Pipeline three years ago found “atrocious” info management. “I mean an eighth-grader could have hacked into that system,” the author told @AP https://apnews.com/...

Bloomberg

Context & Ripple Effects

Colonial had already halted operations after DarkSide reportedly stole and encrypted about 100GB of data, turning a cyberattack into an operational disruption. The reported payment adds a concrete cost to that earlier shutdown and data-extortion attack.

The failed decryptor is the critical detail: Colonial’s own backups, rather than the paid-for tool, reportedly supported recovery. Later coverage frames the payment as an executive decision made amid uncertainty over the attack’s scope.

First-order effects

  • Colonial absorbed both a roughly $5 million cryptocurrency payment and the operational work of restoring from backups, because DarkSide’s decryption tool reportedly could not restore systems fast enough.
  • DarkSide received a rapid payment, while its ineffective tool weakened the practical value of the service ransomware operators claim to provide victims.

Second-order effects

  • For operators facing ransomware, tested backups become a more credible recovery path than relying on an attacker’s decryption process, shifting attention toward recoverability in procurement.
  • The disruption and payment intensify the political pressure described in the coverage to target the ransomware ecosystem, not only the affected company’s restoration process.

Third-order effects

  • If ineffective decryptors are a recurring feature of ransomware incidents, resilience spending will increasingly be judged by how quickly organizations can operate from independent backups rather than by their ability to negotiate a ransom.
  • The later seizure of part of Colonial’s ransom payment indicates that ransomware response is extending from incident recovery into tracing and recovering cryptocurrency proceeds.

The trend: Ransomware is pushing critical operators toward recoverability as a core operating requirement while authorities pursue the financial infrastructure behind attacks.

Discussion

  • @nicoleperlroth Nicole Perlroth on x
    Can confirm that Colonial Pipeline paid its extortionists 75 Bitcoin on Monday- nearly $5 million- to recover stolen data.
  • @kimzetter Kim Zetter on x
    Source also tells me one reason Colonial might have taken operational network down - aside from being cautious - is because they may not be able to invoice customers who receive fuel if their IT network is locked with ransomware, preventing them from being paid for fuel.
  • @secgranholm Secretary Jennifer Granholm on x
    Colonial Pipeline reports this morning that the restart of the pipeline went well overnight. This should mean things will return to normal by the end of the weekend. Will keep you posted.
  • @ridt Thomas Rid on x
    Wow, Colonial reportedly paid close to $5M in cryptocurrency to a criminal group likely based in Russia (or Eastern Europe), already on Friday last week—this should significantly escalate the political pressure to finally counter the ransomware ecosystem https://www.bloomberg.com…
  • @kimzetter Kim Zetter on x
    .@cnn has now confirmed what I wrote 4 days ago, that CP shut down pipeline because they couldn't bill customers. Per CNN: “The company halted operations because its billing system was compromised...and they were concerned they wouldn't be able to figure out how much to bill” htt…
  • @b52malmet Barbara Malmet on x
    Maybe it was a four hundred pound eighth grader in a basement in Russia? https://twitter.com/...
  • @blackvaultcom @blackvaultcom on x
    “Colonial Pipeline Co. paid nearly $5 million to Eastern European hackers on Friday, contradicting reports earlier this week that the company had no intention of paying an extortion fee...” — Heh. Watch them do it again tomorrow. 🙄 https://finance.yahoo.com/...
  • @kimzetter Kim Zetter on x
    .@nicoleperlroth has also confirmed that CP shut down pipeline in part because it couldn't bill customers, and in part to prevent ransomware from spreading. Big thanks to Nicole for the shoutout in this piece to my prior stories on billing issue. 🙏 https://www.nytimes.com/...
  • @triviumpaolo Paolo Gregoletto on x
    Cyber bullying works https://twitter.com/...
  • @joeconchatv Joe Concha on x
    This sets a wonderful precedent... https://twitter.com/...
  • @carolmswain Dr. Carol M. Swain on x
    Welcome to Biden's world. Colonial Pipeline Paid Hackers Nearly $5 Million in Ransom https://finance.yahoo.com/...
  • @bryandeanwright BDW on x
    When you incentivize illegal behavior — to cross the border, to hack infrastructure — more will try. This was a disastrous decision. https://twitter.com/...
  • @foxholemedicine War Medic on x
    Great, now terrorists will be demanding a cool $50 Mil for a power grid. Was this a test run? Nice job, enablers. #WeDontNegotiate https://www.cnbc.com/...
  • @reuters @reuters on x
    'So far there is no evidence based on, from our intelligence people, that Russia is involved, although there's evidence that the actors' ransomware is in Russia,' President Biden on the Colonial Pipeline hack https://www.reuters.com/... https://twitter.com/...
  • @mkapor Mitch Kapor on x
    Sometimes it IS a pipeline problem. https://twitter.com/...
  • @themaxburns Max Burns on x
    The lesson here, which our government has been slow to acknowledge for years, is that our critical civil infrastructure is so vulnerable to cyberattack that even non-state free agents can seize and ransom our own infrastructure back to us. https://finance.yahoo.com/...
  • @dnastacio Denilson N. on x
    They should have paid extra for the professional edition of the decrypting tool. https://twitter.com/...
  • @quinnypig Corey Quinn on x
    The real story here is that an enterprise was able to pay $5 million without six weeks of dickering with Procurement beforehand. https://twitter.com/...
  • @kevincollier Kevin Collier on x
    Wild reporting from @WilliamTurton here. Very key point is that Colonial did not restore their operations by paying tha ransom, though. They paid, realized DarkSide's decryptor sucks (which we already knew), then restored from backups anyway. https://www.bloomberg.com/...
  • @secgranholm Secretary Jennifer Granholm on x
    We just got off the phone with #ColonialPipeline CEO. They are restarting pipeline operations today at ~5pm. More soon.
  • @briankrebs @briankrebs on x
    Bloomberg says Colonial Pipeline paid ~$5M to the DarkSide ransomware extortionists, 6 days after the company shut down 5,500 miles of fuel pipe in response to attack. https://www.bloomberg.com/... That's less than 1/2 what a similarly sized recent victim paid https://krebsonsecu…
  • @iblametom Thomas Brewster on x
    So Colonial paid up, decrypting tool didn't work, they used their own backups to restore... and yet they still shut the pipeline down for five days? https://twitter.com/...
  • @nycsouthpaw Southpaw on x
    Colonial paid the cost of approx five avg homes in Brooklyn as ransom for its pipeline data https://www.bloomberg.com/...
  • @chuckwendig Chuck Wendig on x
    well that won't encourage more of the same to be sure https://twitter.com/...
  • @bobonmarkets Robert Burgess on x
    Nah, crypto isn't the domain of criminals and hackers https://www.bloomberg.com/... via @business
  • @thegrugq Thaddeus E. Grugq on x
    Colonial Pipeline paid $5million, according to the grain of rice backdoor people. https://www.bloomberg.com/...
  • @keitholbermann Keith Olbermann on x
    But don't worry. They'll immediately share those costs with YOU, Joe Driver https://twitter.com/...
  • @glengilmore Glen Gilmore on x
    Bloomberg: Contradicting Earlier Reports, #ColonialPipeline Paid Hackers Nearly $5M in Ransom #Ransomware costs increased by 311% in 2020, reaching $350M in #cryptocurrency Average ransom paid by organizations in 2020 was $312,493 https://www.bloomberg.com/... #IoT #infrastructur…
  • @alexhern Alex Hern on x
    I wonder what would happen to ransomware if the US government declared interacting with a bitcoin exchange a prima facie AML violation
  • @josephfcox Joseph Cox on x
    This is bad for ransomware operators. If your tool is so crappy that even when people pay they still then have to go use their backups, why pay at all https://www.bloomberg.com/... https://twitter.com/...
  • @bradstone Brad Stone on x
    incredible and terrifying. https://twitter.com/...
  • @matthew_d_green Matthew Green on x
    I'm definitely in the wrong job. https://www.bloomberg.com/...
  • @hshaban Hamza Shaban on x
    Bloomberg: Once the hackers received the $5 million in crypto, they gave Colonial Pipeline a decrypting tool to restore its disabled computer network. The tool was so slow that the company continued using its own backups to help restore the system https://www.bloomberg.com/...
  • @fbajak Frank Bajak on x
    Audit of Colonial Pipeline three years ago found “atrocious” info management. “I mean an eighth-grader could have hacked into that system,” the author told @AP https://apnews.com/...