AAA warns on gas prices, North Carolina invokes emergency as hackers apologize
68k.news
68k.news
We truly do live in a simulation.
>1. The deliberate commission of an act of violence to create public fear through the suffering of the victims in the furtherance of a political or social agenda.
>2. The use of unlawful violence against people or property to achieve political objectives.
>3. A form of psychological manipulation through warfare to the purpose of political or religious gains, by means of deliberately creating a climate of fear amongst the inhabitants of a specific geographical region
If you don't have an agenda behind it, it's not terrorism.
It can't be that easy - if some government is going to charge you, they'll do it based on what you achieved, not what you say.
But that's not what's happening? It's not like we have IRA setting off bombs and then saying "it's us but it's accidental wink wink". Terrorists are interested in creating fear, hence why they take attributions in the first place.
>It can't be that easy - if some government is going to charge you, they'll do it based on what you achieved, not what you say.
You do realize something can be a crime and still not be terrorism, right?
But their loudly and public disclaiming all intent to harm puts them a huge step away from being terrorists in the public’s eyes. Even if the government designates them so, they still have to make a case as to why money should be spent in going after them instead of criminals the population actually cares about.
1. who's calling them terrorists? Some shmuck off the street? Some writer for a tabloid? People on wallstreetbets think that hedge funds are "financial terrorists", doesn't mean they are.
2. drug lords can absolutely engage in actual terrorist activities, eg. "we will attack innocent civilians unless you stop arresting us".
So seems my example was wrong. Whoops.
That's one possible way, but not always needed. The message for fear may be "us gas infrastructure can be broken for days by internet exploits" - that's been done. Adding "by Russian groups" at the end does change the message and creates a lot of issues as we've seen - so the preference may be to deny it.
Until we can shift our assets and upgrade our chimney, we promise to refrain from poking large-ish toes. Nevertheless, we do poke toes, so we must continue to poke small ones.
We are sure that everyone understands the nuanced and unexpected realities of our predicament, especially those voters who can't get to work today."
The degree to which US can craft an internationally persuasive story of Russia's culpability is the degree to which Russia will have to launch an internal investigation, and like, treat the matter Very Seriously and Stuff.
It won't work as well for the hackers, of course, as they aren't paying for lobbyists, crisis PR, and political donations, however much they're trying to be more "professional". [1] I expect this ransomware crew just got a 10x bump in the number of federal agents going after them.
[1] https://www.wired.com/story/ransomware-gone-corporate-darksi...
Before this hack, you had insurance companies wanting to stop these guys. They were comfortable with that level of heat. Having the NSA and CIA trying to track them down is a totally different level. Even if they don't get caught, they have to spend a lot more time worrying about opsec, which leaves them less for actually making money.
Wouldn’t this add to their “liability” given that now are they not only selling hacking tools but greelighting specific illegal activity?
"don't let me detain you."
No, we truly live in a world where human beings have decided that it is ok to exploit others for their own gain. These criminals use corporate-speak because that's the language of exploitation.
https://www.newsweek.com/aaa-warns-gas-prices-north-carolina...
You see, they just want to make money by extorting people with malwares, and not create problems for society. It's all forgiven.
That is an incredible understatement. Disrupting key infrastructure would be considered an act of war if it was done by a state actor. I'm not sure what the equivalent characterization would be for a non-state actor.
I do realize that in this case, as reported, the hack involved the IT systems and not the operational systems but I think my point still stands.
Not an easy place to be.
If they also prove they donated to charity via Bitcoin I would assume some legal rights for the victims to claim this money back off the charities. (And it looks like they've given $20k USD to date which is probably a paltry amount for what they've been extracting https://www.bbc.co.uk/news/technology-54591761)
Why would they need positive PR? Exactly how does that help them?
They are attacking large profitable corporations and sharing some money with charities. They're helping solve inequality.
I bet charities take money from disreputable sources all the time.
They deserve to be hunted down and punished accordingly. When your need to scam people out of money hurts many people and an economy, I say, "Screw You!!."
Was this confirmed as a Russian hacker group? The article only states that:
> Biden also said that although U.S. intelligence had found no evidence to link the attack with the Russian government, he believed the country had "some responsibility to deal with" the issue since some evidence did indicate that the ransomware may have originated in Russia.
So basically the US authorities have no proof but their leader "believes" that the Russians are behind it.
And the law enforcement actions against Russian ransomware groups are... pretty weak. Could have something to do with a few campaigns actually disabling the malware if Russian language is detected.
> Biden also said that although U.S. intelligence had found no evidence to link the attack with the Russian government, he believed the country had "some responsibility to deal with" the issue since some evidence did indicate that the ransomware may have originated in Russia. Ransomware is software that hackers use to take control of data before demanding money in exchange for its return.
If you wanna try and tell it that, don't start from me - I'm just along for the ride. Same as all the commenters who have no loved one in either hospital but are quick to propose clever solutions to spherical problems in vacuum
Don't get me wrong, being prepared is important but insufficient prep should never be communicated as a way mitigate the culpability of the attackers.
> The attackers reportedly withdrew the extortion demand and provided a decryption key to unlock the servers. The justice minister report said that the attackers are no longer reachable.
https://www.wired.com/story/a-patient-dies-after-a-ransomwar...
It makes sense from a pure self-serving rational perspective. They don't want to become target of a well-funded investigation or be held responsible for damages above and beyond some unimportant business network. They want to blend in with the background of 1000 other ransomware attacks per day and make money.
Do these guys offer hosting services? I'm looking to switch from Google Cloud
As opposed to companies where the support is normally a pure cost center, talking to you after you already spent the money.
>Leo Rosten in The Joys of Yiddish defines chutzpah as "gall, brazen nerve, effrontery, incredible 'guts', presumption plus arrogance such as no other word and no other language can do justice to". In this sense, chutzpah expresses both strong disapproval and condemnation. In the same work, Rosten also defines the term as "that quality enshrined in a man who, having killed his mother and father, throws himself on the mercy of the court because he is an orphan."
Chutzpah amounts to a total denial of personal responsibility, which renders others speechless and incredulous ... one cannot quite believe that another person totally lacks common human traits like remorse, regret, guilt, sympathy and insight. The implication is at least some degree of psychopathy in the subject, as well as the awestruck amazement of the observer at the display
Honestly, it feels like there may be an international game of terrible idea chicken going on.
Sounds like kids who got in way over their heads.
Fair enough. Off to jail with the lot of you then.
Making money has nothing to do with what these guys do they are stealing money.
By hacking the way they do, they are creating problems for society. It doesn't matter if it's a fuel pipeline or a bottling plant.
.. for more information about our organization please visit www....click downl9ad and choose run, the site can only be viewed after agreeing to these terms."
I wonder if it was Warez, Pr0n, or phishing that fooled the employee into loading the malware.
(imho it depends on how sophisticated the attack... given the typical lameness of SCADA defenses, one can't assume...)
hackers dont traditionally think that way..
The skillset to compromise large enterprise networks is more readily available and more profitable than the skillset to compromise SCADA systems, and for all the flak they get, the culture at most large engineering firms in the West is extremely safety conscious. If it's not provably operating safely, it isn't. So it gets shut down.
So you all need to do is deny the link between the actual control system and lines of engineering reporting.