Garmin obtains decryption key after ransomware attack
news.sky.com
news.sky.com
I accidentally took a phone call for a job that basically involved using Bitcoin to launder money to send ransom payments to terrorists. They told me that although it's technically illegal, the U.S. government has never prosecuted anyone for paying a ransom. I noped out after the first phone call for obvious reasons, but it was pretty interesting just to learn about the industry.
Anyway when Garmin says they didn't pay the ransom themselves, they are telling the truth, instead they would have used this company or one of their competitors. You can't just open a Coinbase Pro account and buy 10 million BTC and transfer it your first day. No bank is going to allow you to do that, since they would then be liable for facilitating that transaction. Instead you need to contract with a company that specializes in ransom payments and has already accumulated the crypto in advance. Then you pay them a percentage for their services.
There are thousands of things that are illegal, but in practice are rarely or ever prosecuted, even in cases where people are violating those laws at pretty significant scales.
In my case that's not a risk I'd be willing to take, but I can see why other people would. The reason it's not prosecuted though isn't because of companies, it's because there are lots of wealthy people who travel overseas and then get kidnapped, and the government isn't going to prosecute their families for paying to not have their kids dismembered and the videos posted on YouTube. The reason companies aren't prosecuted is mainly because once you decide not to prosecute families for doing this, then anyone else can make an equal protection argument.
Just saying, there's plenty of laws here that aren't prosecuted either.
In Germany, the barrier to getting a drivers' license is much higher. More training, more stringent tests. But the effect of that is that drivers are (mostly) assumed to be able to adapt their driving to road conditions; as a consequence, you get unlimited legal driving speeds on part of the German road system. In good weather, traffic permitting.
Of course, there are confounding facts: in my experience the average physical state of a car is much better in Germany than the US, and highways are better maintained. But still, the contrast is interesting. In the US, lifting speed limits on even straight roads through the desert would have poor outcomes.
> "Maybe in places where code law is mostly binding, there’s a lot more pressure on the legislature to keep the law books up to date with the current norms of society."
In the US, where everything is so entwined with politics, there's a lot unenforceable laws still on the books.
For example, the US Supreme Court struck down sodomy laws in 2003. Last I checked, Texas still has a law on the books criminalizing sodomy. Sure Texas can't enforce it, but the conservative majority in the legislature won't actually repeal the law because politics. Similarly, when the US Supreme Court ruled that banning same-sex marriage was unconstitutional, Texas had to recognize same-sex marriage. But there was no law allowing same-sex couples to divorce. So there was this weird limbo wherein you couldn't get divorced if you were in a same-sex marriage.
America is weird.
For all intents and purposes sodomy was made legal by the 2003 precedent; that those laws are still technically in black-and-white doesn't mean they're in force.
But there are lots of laws that are still in force but aren't actually picked up and used much. They're still there, though. For instance, hardly anyone was prosecuted for Espionage Act violations for decades, but nobody disputes that the DoJ can dust that law off and start using it again, subject to the current jurisprudence on free speech etc.
Also there are laws that reference other country's laws. An example is that is (or was) illegal to buy/posses a type of meat in the US that is illegal in other jurisdictions. This was made to protect endangered animals but can easily apply to everything as there are lot of jurisdictions and who really knows if any one of them currently doesn't allow pork or beef for whatever reason.
More details here a few minutes in: https://www.youtube.com/watch?v=d-7o9xYp7eE
It's definitely my perception in Berlin. There is almost no police, prosecutors and courts are completely understaffed.
Federally. The states have made this all higgledy-piggledy. And since there's money (legit retail income and state sales tax) involved, I'm surprised we don't have more federal troops kicking down more retail establishment doors.
Perhaps things like your age, gender, and wealth may be insulating you, allowing you to think, "these laws don't actually apply to me", and if they did, you could most likely hire a lawyer and fight it.
Many people in this world cannot. Think about how many people are incarcerated for weed-related "crimes". Just because no one is going to go after YOU for them, doesn't mean that these laws don't serve a purpose to screw over others not so fortunate.
Anyways, not to pick on you specifically - I obviously don't know a whole lot about you, but your reply irked me a bit. Cheers.
The rest seemed spot on: This law is almost exclusively broken by rich folks, so it will never be an enforcement priority.
Objectively neither activity is probably super high risk, but I still wouldn't be willing to take on either of those risks myself.
There are thousands of things that are illegal, but in practice are rarely or ever prosecuted, even in cases where people are violating those laws at pretty significant scales.
"rarely or ever prosecuted" for you. You are on the advantageous side of a system that isn't that way on happenstance. Let's take your startup. How easy would it be for a black-owned startup in the US to raise VC funds in comparison to a white-owned startup? How easy is it to get... well any sort of loan if you're a black person, compared to a white person? How many black-owned banks are there that cater specifically to black businesses of any size?
Name three black CEOs.
Now, why is that?
A company I worked at once had a meeting with such a firm, and it all sounded pretty reasonable to me. Obviously, one would hope the company has backups (which are stored in a place that can't itself become encrypted), but if they don't, sometimes the cost of paying the ransom is far, far lower than the cost of staying down. These middle-man firms have probably saved companies from enormous amounts of damage. Another commenter claimed these companies are often in cahoots with the ransomers, which maybe is sometimes true, but I highly doubt it in the case of the company we dealt with, or other US-based companies with physical locations that meet on-site.
Of course in an ideal world no one wants to reward criminals, but just to give an extreme example, if someone kidnapped one of your children and held them hostage, you'd probably pay anything to get them back, and that's not far off from the situation some ransomware-affected companies end up in.
That's an appeal to emotion though while a company can do a cost-benefit analysis. Also, if you pay for your children that means you signal that the kidnapping business model is viable and thus endanger more children. If the government keeps you at gunpoint from paying for your children then yes, in the worst case a bunch of children might die, but the business model would die with them.
And yes, paying the ransom signals that hostage-taking can be profitable, but not paying it signals that you value crime prevention over the lives of your children, which isn't necessarily a reputation or circumstance you want, especially when they'll very likely end up brutally murdered.
A company that decided principle-based crime deterrence was more important than granting customers access to any of their funds for 6 months would probably go out of business quickly. Also, try using that argument when talking to people who live in areas largely run by organized crime.
Ransom works when the target is capable and has sufficient incentive to pay out, if you make it so that you’ll face jail time as a CEO who orders a ransom to be paid out it’s quite likely might reduce acts of ransom.
I know that there is grey area that is common in the energy and global construction sectors where companies might not be able to pay ransom legally essentially have a ransom insurance so when 3 of your workers get kidnapped in Djibouti you have your “insurance company” which also often facilitates negotiations, extraction and repatriation handle the case.
(This is also common for other reasons, especially liability reduction if something goes wrong the company can wash their hands of the case and send the families after the “insurance provider”.)
There is also the grey area of “private emergency services” which range from private medevac on standby to assault teams capable of executing asset recovery missions some even take pride of being able and willing to perform prison breaks.
The TLDR is that these middleman companies allow ransomware victims to both pay the fine and save face, by acting as if they didn't pay the fine. The perpetrators prefer to deal with the middlemen as they know how to pay in crypto, and are predictable - the middleman and the hackers are closer to partners than adversaries.
https://features.propublica.org/ransomware/ransomware-attack...
Edit: Or were the ransomware payments at hand not even malware related, but more "traditional" ransoms?
Then again, the acceptability of a gotcha seems to correlate more with the amount of money spent on lawyers than on the rationality of the gotcha, so as long as they have a large enough legal department the worse they'll have is a fine that they likely already included in the cost of the attack.
Now, if Garmin obtained the decryption keys, as is alleged in the article, it is clear that they paid. Note that the 'anonymous sources' cited did not even deny payment but only used a weasel turn of phrase 'did not directly make a payment', which is quite different from 'did not pay'. My best guess, if a payment was made, is that they hired people experts in dealing with these situations who arranged everything and who will bill for 'consulting services'...
I mean I’m pretty sure you’re not allowed to go wire money to Al Qaeda, or to conspire to evade anti money laundering controls in order to do so.
Money laundering is another issue. In general I think people are still free to spend their legitimate money (it's not money laundering to begin with).
If I was going to take a job doing something that is illegal, I think I might prefer one where the government has prosecuted people. Then I could look at those cases and see what people got off with just probation, which got light sentences, which got harsh sentences, what kind of plea deals were offered. Then I could at least have a decent chance of figuring out if the pay and benefits are worth the risk.
If they haven't prosecuted anyone (and this is not a line of work that has been around for a very long time), I'd worry that they just haven't gotten around to it yet, and I could end up being the first. Being first could be very bad, because they might be pushing for a harsh sentence to discourage others or encourage people prosecuted later to take plea bargains.
Funny enough, back when ransomware was simpler and used the same encryption key, we managed to recover one place by using Memory Forensics on a fucked machine.
I wonder if extracting the key, decrypting the files to not pay $100,000 in BTC would be illegal in some way.
It also took Garmin quite awhile to acknowledge the ongoing situation formally (their outage page has been accurate with red lights across the board). Could it be that Garmin just started to spin up more hardware and began a migration of their last backups? (I'm so far removed from how their service operates so apologies if this sounds impractical)
It says they "did not directly make a payment to the hackers". You can't just take 10mil and convert it to bitcoin. My best guess is that a 3rd party made the payment and garmin will be reimbursing
I think it's also possible that Garmin proactively pulled the plug on their public-facing services in order to mitigate the spread of the attack. It would be _really_ bad if the attackers could make the hop from Garmin's web services to consumer devices.
By the time the encryption begins they have explored every way possible into critical systems.
Preventing the second stage attack is what Symantec has been successful in preventing, this video gives an insight into how that works
Maybe this only affected their corporate infrastructure or manufacturing infrastructure. Looking through my connect account I don't see any missing data that would point to a backup old enough to not be encrypted. My watch does store some information offline so it could be that any gaps have already been filled in or it could be that connect was encrypted and has since been decrypted.
They might be good but they aren't good enough to randomly crack AES.
If they could, I'm sure they wouldn't even offer.
It's possible they paid, but it's also possible they are just restoring backups.
Probably because that would be securities fraud? You'd be essentially duping investors into thinking the company is better than it is. eg. if there was a fire in your widget factory and the whole place got destroyed, you can't turn around and tell investors "everything's fine, the fire suppression system worked as intended", because you'd be lying to investors about the state of the company.
This should make them a direct target now, they will pay you off. Among many many reasons allowing payments like this will just encourage these criminals to keep doing this bullshit.
Who is the victim in prostitution (where no one was trafficed), how about if I buy pot, who is the victim where it's illegal? That theoretical vision of how you want society to work is not matched by the reality of the US.
My guess is this: two separate attacks occurred. The first attack involved compromising production, and installed a scheduled job that, at a certain time, would delete all database backups and code repositories, deschedule all workloads, delete all DNS records, etc. The next attack involves the fact that all source code is on managed workstations, so they compromised the IT management system to push malware to every machine globally at the exact same time that would destroy all git repositories (etc.) on the workstations. The result was that when the scheduled time occurred, production would crash and there would be no backups. (They must have wiped all the tapes at their offsite backup facility, too. I guess anything can be done for a price!)
To me, this sounds too complicated to even be feasible. I am still impressed when I edit some manifest with a new version number that 90% of the time that code eventually starts running. Being able to orchestrate a multiday outage just seems amazing to me, and that you'd make a lot more money being a cloud provider than a cybercriminal.
The other thought I had was that maybe they just kept thinking "we're so close to getting it back" for three days, rather than saying "everything is lost, revert to backups".
Can't guess at specifics, but if it's a Windows network, I would be utterly unsurprised if all users had excess permissions to shared drives
Many Windows networks just have a giant X: everyone can write to, and it's been like that forever, and it's so deeply baked into everyone's workflow that it never gets fixed
The one of these that I got called-in to clean up after literally had a batch file on Domain Controllers w/ a text file of computer names for a FOR loop launching the malware on computer-after-computer with "psexec". It was decidedly non-sophisticated. The attacker compromised a Domain Admin account and then they were set.
It just seems like an unfathomable level of incompetence required to go from compromising some random Windows workstation all across the hardware that runs your app services. And lest we forget: a ransomware attack is always also a massive data loss attack. Garmin better get to work complying with the law and notifying impacted customers (all of them?).
I've seen this too, and you need to be vigilant with what accesses these kinds of resources (basically anybody with write access to these shares also has execute access to any accounts executing from that share).
Taking all our services down this hard would require enormous efforts in coordination, potentially months of preparation to make sure it would execute satisfactory.
I think occam must be at work here. There must be some simpler reason why this attack is such a disaster.
The attack happened about a week after the FAA’s last update went into force. And I believe they’re distributed a week before that.
So the only groundings would’ve been those that have been parked for a while (I guess. I don’t know how they do updates).
https://www.faa.gov/air_traffic/flight_info/aeronav/aero_dat...
—armchair aviator
I'm against fueling ransoms, but this isn't black and white when it hits home.
If their financial records were all toast too I wonder what the fines would have been ...
It still puzzles me greatly how this ransomware has such a huge impact. How Does it allow hacking and encrypting the db servers?
I was happy that basic functions of my Garmin Venu continued to work. But some stuff should be cached, or stuff that hasn't been sync'd should be available locally.
The present version of Garmin connect does nothing if you are not connected to Garmin servers. E.g. you can't see your activities, your data or anything else.
When this change occurred, I remember that it annoyed me greatly. Why not have some local data cached on your phone? Other apps seem to manage that no problem. If you'd have no internet access, you could at least still use the app to see your activities and sync them later. This seems so obvious to me that I have trouble understanding why they chose the current route.
Of course, it's still not a total disaster. Garmin devices still work and track, you can still view the data on them, and they usually plug in as a USB drive anywhere so you can upload the data manually.
Still, for smartwatch users, this could have been a really minor inconvenience rather than what it is now.
1. Why was there lateral spread across low-criticality devices fitness devices and avionics devices?
2. Why was there lateral spread across manufacturing, customer support, and PII regions?
3. What assurances are there that health information wasn't leaked?
4. What's the general security position around avionics, marine, and health data at Garmin?
I'd expect the avionics and marine stuff to be a little better due to compliance requirements.
Is this really the aspect of their business that they're most known for now? I still think of them as a GPS/Geolocation device company.
I'm pretty sure the 200$ model has features that Apple doesn't have. One is primarily a lifestyle product and the other is primarily focused towards athletes. Both brands overlap with some products but I wouldn't say they found a way to really get their foot into others' market.
What I've found most surprising is I have young children, and having a Garmin activity tracker watch (seems to be not much more than a step counter) has become the thing every 6yo is expected to have these days. We've avoided it so far, but from speaking to parents with children at neighboring schools they're nearly ubiquitous in the youngest year levels now.
Could an independent party buy the decryption keys from the ransomware party for their asking price then attempt to resell this to Garmin (or other party) for more money?
Of course it's a bit game theory because you're depending on the target to pay and the ransomware attacker to not relinquish and resell the key to anyone else including the target.
Ignore the legality of it all else it's not very interesting to think about.