'That horse has left the barn': Secret Service official says ransom payments have fueled hacking sprees
Full article990 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
“I think it’s a very small number of cases we actually hear about,” Secret Service official Stephen Nix said.
After the multimillion-dollar extortions of Colonial Pipeline and meat processor JBS, a Secret Service official is urging organizations not to pay off hackers and underscoring that more victims need to come forward in order to help U.S. officials get a handle on the problem.
“We’re in this boat we’re in now because over the last several years, people have paid the ransom,” Stephen Nix, assistant to the Special Agent in Charge at the U.S. Secret Service, said at CyberTalks, a summit presented by CyberScoop. “This is the monetization of security flaws. That’s what we’re looking at. That horse has left the barn.”
Nix asked ransomware victims to tell law enforcement agencies details such as the cryptocurrency wallet, or account, used by the attackers in order to track them down. “I think it’s a very small number of cases we actually hear about,” he added. “If we don’t hear about it, we can’t help you and we can’t help the next person.”
In 2020, ransomware payments from victims surged by 311% to reach nearly $350 million in cryptocurrency, according to Chainalysis, a company that tracks virtual payments. Two recent incidents have brought the issue into the national spotlight, while sparking concern among lawmakers that corporations are fueling a criminal economy.
Colonial Pipeline, which transports some 45% of fuel consumed on the East Coast, paid $4.4 million to recover its data from hackers. JBS, which accounts for an estimated one-fifth of U.S. beef production, paid its extortionists $11 million.
The CEOs of both companies said paying off criminals made them squeamish, while defending their ultimate decisions. In the case of the Colonial Pipeline, the FBI was able to recover about $2.3 million of the ransom by tracking the bitcoin ledger linked with the hackers, the Wall Street Journal reported.
In other cases, Nix said, knowing which ransomware group is behind a given hack can lead law enforcement to advise victims to low-ball extortionists who are known to accept payments below their asking price.
The Treasury announced last fall that U.S. companies could be fined for paying ransoms to sanctioned entities. Nix said communication with law enforcement can keep organizations from running afoul of those regulations.
“Most of the time, you have no clue where that wallet … that you’re paying [is],” he said.
By alerting law enforcement of ransomware attacks, victims can also get threat information such as the likelihood that they will recover their data from hackers, said Daniel Donahue, program manager at Homeland Security Investigations, a division of the Department of Homeland Security.
“The more people know and the harder that we make targets … it might actually increase the cost of doing business” for ransomware gangs, Donahue said during the CyberTalks panel.
The FBI last year announced a cybersecurity strategy to impose more costs on foreign hackers threatening U.S. interests — an approach that officials are doubling down on in the wake of the temporary disruption of key arteries of the American economy.
Nix, the Secret Service official, said his team was keen on taking a closer look at the numerous players in the cryptocurrency market.
“There are over 500 money service businesses in the United States alone that handle cryptocurrency,” Nix said at CyberTalks. “At any one point, some of these ransom funds could be mixed or tumbled through some of these money exchangers.”
“This is shared criminal infrastructure,” he added. “We have to attack all of it — the customer service aspect, the money laundering aspect.”
More Scoops
Ex-White House cyber official says ransomware payment ban is a ways off
Kemba Walden, the former acting national cyber director, said that a ransom payment ban is the ultimate goal.
The long, bumpy road to cyber incident reporting legislation — and the one still ahead
FBI shifting cybercrime focus from arrests, indictments to payment seizures, incident response
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ransomware-secret-service-cyber-talks/