Friday, March 14, 2025, 2:54AM |  60°
MENU
SECTIONS
OTHER
CLASSIFIEDS
CONTACT US / FAQ
Advertisement
In this May 12, 2021, file photo, the entrance of Colonial Pipeline Company in Charlotte, N.C.
1
MORE

U.S. recovers most of ransom paid after Colonial Pipeline hack

Chris Carlson/AP

U.S. recovers most of ransom paid after Colonial Pipeline hack

WASHINGTON — The Justice Department has recovered most of a multimillion-dollar ransom payment made to hackers after a cyberattack that caused the operator of the nation’s largest fuel pipeline to halt its operations last month, officials said Monday.

The operation to recover the cryptocurrency from the Russia-based hacker group is the first undertaken by a specialized ransomware task force created by the Biden administration Justice Department, and reflects a rare victory as U.S. officials scramble to confront a rapidly accelerating ransomware threat that has targeted critical industries around the world.

“The DOJ has found and recaptured the majority of the ransom” in the wake of last month’s attack, Deputy Attorney General Lisa Monaco said at a news conference announcing the operation. “By going after the entire ecosystem that fuels ransomware and digital currency, we will continue to use all of our tools and all of our resources to increase the costs and the consequences of ransomware attacks and other cyber-enabled attacks.”

Advertisement

Georgia-based Colonial Pipeline, which supplies roughly half the fuel consumed on the East Coast, temporarily shut down its operations on May 7 after a gang of cybercriminals using the DarkSide ransomware variant broke into its computer system. The ransomware variant used by DarkSide, which has been the subject of an FBI investigation for the last year, is one of more than 100 that law enforcement officials have identified, said FBI Deputy Director Paul Abbate.

In this file photo taken on April 25, 2020, the main entrance to one of Amazon's distribution centers is seen in Las Vegas.
Pittsburgh Post-Gazette
Global internet outage temporarily knocks Amazon, Reddit, major news websites offline

Colonial officials have said they took their pipeline system offline before the attack could spread to its operating systems, and decided soon after to pay ransom of 75 bitcoin — then valued at roughly $4.4 million — in hopes of bringing itself back online as soon as it could. The company’s president and chief executive, Joseph Blount, is set to testify before congressional panels this week.

In a statement, Mr. Blount said he was grateful for the FBI’s efforts and said holding hackers accountable and disrupting their activities “is the best way to deter and defend against future attacks of this nature.

“The private sector also has an equally important role to play and we must continue to take cyber threats seriously and invest accordingly to harden our defenses,” he added.

Advertisement

Cryptocurrency is favored by cybercriminals because it enables direct online payments regardless of geographical location, but in this case, the FBI was able to identify a virtual currency wallet used by the hackers and recovered the proceeds from there, said the FBI’s Mr. Abbate.

Though the FBI generally discourages the payment of ransom, fearing it could encourage additional hacks, Ms. Monaco said one takeaway for the private sector is that if companies come quickly to law enforcement after ransomware incidents, officials may be able to help them recover funds too.

The Bitcoin amount seized — 63.7, currently valued at $2.3 million after the price of Bitcoin tumbled— amounted to 85% of the total ransom paid, which is the exact amount that the cryptocurrency-tracking firm Elliptic says it believes was the take of the affiliate who carried out the attack. The ransomware software provider, DarkSide, would have gotten the other 15%.

“The extortionists will never see this money,” said Stephanie Hinds, the acting U.S. attorney for the Northern District of California, where a judge approved the seizure warrant earlier Monday.

Colonial Pipeline, operator of the nation's largest fuel pipeline, confirmed Wednesday it paid $4.4 million to a gang of hackers who broke into its computer systems. That's according to a report from the Wall Street Journal.
Cathy Bussewitz
Colonial Pipeline confirms it paid $4.4M to hackers

Ransomware attacks — in which hackers encrypt a victim organization’s data and demand a hefty sum for returning the information — have flourished. Last year was the costliest on record for such attacks. Hackers have targeted vital industries, as well as hospitals and police departments.

Weeks after the Colonial Pipeline attack, a ransomware attack attributed to REvil, a Russian-speaking gang that has made some of the largest ransomware demands on record in recent months, disrupted production at Brazil’s JBS SA, the world’s largest meat processing company.

The ransomware business has evolved into a highly compartmentalized racket, with labor divided among the provider of the software that locks data, ransom negotiators, hackers who break into targeted networks, hackers skilled at moving undetected through those systems and exfiltrating sensitive data — and even call centers in India employed to threaten people whose data was stolen to pressure for extortion payments.

Bloomberg News contributed.

First Published: June 7, 2021, 7:48 p.m.

RELATED
Tanker trucks are parked near the entrance of Colonial Pipeline Company Wednesday, May 12, 2021, in Charlotte, N.C.  The operator of the nation's largest fuel pipeline has confirmed it paid $4.4 million to a gang of hackers who broke into its computer systems.
Ellen Nakashima and Lori Aratani
DHS to issue first-ever cybersecurity regulations for pipelines after Colonial hack
This poster provided by the U.S. Department of Justice shows Maxsim Yukabets. Yakubets, 33, is best known as co-leader of a cybergang that calls itself Evil Corp. Foreign keyboard criminals with no fear of repercussions have paralyzed U.S. schools and hospitals, leaked highly sensitive police files, triggered US fuel shortages and, most recently, a now could be responsible for a disruption in global food supply chains.
ALAN SUDERMAN
Global war on ransomware? Hurdles hinder the US response
The JBS North American headquarters on June 1, 2021 in Greeley, Colo. JBS facilities around the globe were impacted by a ransomware attack, forcing many of their facilities to shut down.
ROD McGUIRK and DEE-ANN DURBIN
Largest meat producer JBS getting back online after cyberattack
FILE — A train pulls into a subway station in Manhattan’s Harlem neighborhood, May 17, 2021. Hackers with suspected ties to China penetrated the Metropolitan Transportation Authority’s computer systems in April, an MTA document shows. Transit officials say the intrusion did not pose a risk to riders. (Karsten Moran/The New York Times)
Christina Goldbaum and William K. Rashbaum
MTA releases outline of breach as cyberattacks surge
Signage outside SolarWinds Corp. headquarters in Austin, Texas on Tuesday, Dec. 22, 2020.
Frank Bajak and Eric Tucker
U.S. says agencies largely fended off latest Russian hack
Tanker trucks are parked near the entrance of Colonial Pipeline Company Wednesday, May 12, 2021, in Charlotte, N.C.
David R. Baker and Keith Laing
Three disasters show gaps in $1.7 trillion infrastructure plan
Comments Disabled For This Story
Partners
Advertisement
Pittsburgh Steelers head coach Mike Tomlin, left, reacts during the first half of an NFL football game against the Los Angeles Chargers, Sunday, Sept. 22, 2024, in Pittsburgh.
1
sports
Joe Starkey: Stories of freshly departed Steelers don’t reflect well on Mike Tomlin, Omar Khan
Pittsburgh Steelers head coach Mike Tomlin greets New York Jets quarterback Aaron Rodgers (8) after an NFL football game, Sunday, Oct. 20, 2024, in Pittsburgh.
2
sports
Gerry Dulac: Steelers have made offer to Aaron Rodgers, but holdup has nothing to do with money
After years of declining population, Allegheny County has experienced a rare turnaround due to a surge in immigration that began in the wake of the COVID-19 pandemic..
3
local
After years of decline, wave of new immigrants boosts Allegheny County's population
In this file photo, former Pittsburgh Steelers running back Le'Veon Bell watches from the sideline as he waits for the end of the AFC championship, Sunday, Jan. 22, 2017, in Foxborough, Mass. Bell was ordered to pay $25 million in damages to a relative who claimed in a civil lawsuit that Bell sexually abused her when she was a child.
4
news
Former Steelers RB Le'Veon Bell ordered to pay $25 million in sexual abuse case
Pittsburgh Steelers newly signed free agent wide receiver DK Metcalf meets with reporters in Pittsburgh, Thursday, March 13, 2025.
5
sports
Newly engaged DK Metcalf 'ecstatic' to be a Steeler, swap wisdom with George Pickens
In this May 12, 2021, file photo, the entrance of Colonial Pipeline Company in Charlotte, N.C.  (Chris Carlson/AP)
Chris Carlson/AP
Advertisement
LATEST news
Advertisement
TOP
Email a Story