[ad_1]
Similarly, the U.S. government has made very little progress in pushing private industries, including pipeline companies, to strengthen cybersecurity defenses. Cybersecurity supervision is divided into institutional letter spelling, which hinders coordination. The Department of Homeland Security conducts a “vulnerability assessment” for critical infrastructure including pipelines.
It conducted a review of colonial pipelines around 2013 as part of a study of where cyber attacks could cause disaster. According to a former Department of Homeland Security official, the pipeline is considered resilient, which means it can be restored quickly. The department did not answer questions about any follow-up review.
Five years later, the U.S. Department of Homeland Security (DHS) created a pipeline network security solution initiative Identify the weaknesses in the pipeline computer system and propose strategies to solve these problems. Participation is voluntary, and a person familiar with the program said that for small companies with limited internal IT expertise, it is more useful than large companies such as Colonial.The National Risk Management Center, which oversees the plan, is also struggling to deal with other thorny issues problem For example, election security.
Ransomware has proliferated since 2012At that time, the advent of Bitcoin made it difficult to track or block payments. Criminal strategies have evolved from the undifferentiated “spray and pray” movement (seeking hundreds of dollars at a time) to targeting specific businesses, government agencies, and non-profit organizations with multi-million dollar needs.
During the pandemic, attacks on energy businesses have especially increased, not only in the United States, but also in Canada, Latin America, and Europe. McLeod said that because the company allows employees to work from home, they have relaxed some security controls.
DarkSide uses the so-called “ransomware as a service” model. In this mode, it cooperates with the branch that launched the attack. The branch received 75% to 90% of the ransom, and DarkSide kept the rest.
Since 2019, many gangs have used a technique called “double blackmail” to increase pressure. After entering the system, they steal sensitive data before launching the ransomware, and then encode the files, making it impossible for hospitals, universities, and cities to carry out their daily work. If losing computer access is not enough to be daunting, they risk leaking confidential information and often release samples as leverage. For example, when the Washington DC Police Department failed to pay the $4 million ransom demanded by a gang called Babuk last month, Babuk issued an intelligence briefing with the names of suspects and witnesses and personnel files, ranging from medical information to polygraph test officials. And the job applicant’s grades.
[ad_2]
Source link






