Would you pay a cyber ransom?

Would you pay a cyber ransom?
Paige Fusco

A few days ago, cyber criminals hacked into one of the largest oil pipelines in the US, which halted operations after its corporate IT network was knocked offline. If the engineers don't fix the system on their own or the owners cough up the ransom that the hackers are demanding, millions of Americans will soon feel the heat of cybercrime in their daily lives, through higher prices at the gas pump.

Who pulled off this attack, and what does it tell us about the vulnerability of critical infrastructure and the rules (or lack thereof) in cyber conflict today?

The culprit. The US government has blamed the Colonial Pipeline cyberattack on DarkSide, a relatively new group of veteran hackers from Eastern Europe famous for bragging about its exploits online, and leaking data dumps from victims who don't pay up. The DarkSiders style themselves as Robin Hoods of the hacker world, donating (a minuscule) part of their profits to global NGOs such as Children International and The Water Project. But this time they may have bitten off a bit more than they can chew.

DarkSide issued on Monday a rare apology for creating "problems" to society, insisting they only want money and are not at all interested in politics, although they do seem to avoid former Soviet bloc nations. That's common for cyber criminals based in these countries, whose governments will look the other way as long as hackers target victims outside their borders.

One of those governments is that of Russia, with a long history of outsourcing its dirty cyber work to unscrupulous hackers. Joe Biden says there's no evidence that the Kremlin was involved this time, but does have "some responsibility."

The problem. The fact that a bunch of geeks armed with laptops shut down a pipeline that serves 45 percent of America's oil refineries shows that US critical infrastructure is a lot more vulnerable to cyber-extortion than we'd like to think. And the Biden administration's $2 trillion plan to upgrade US infrastructure across the board turns cybersecurity into an even more urgent concern.

As always, the pandemic has made everything worse. Ransomware attacks — and cybercrime in general — have boomed in COVID times, largely as a result of IT systems that became more vulnerable when companies rushed to adapt them for remote access. Moreover, hackers are now targeting bigger firms for a lot more money thanks to the rise of cryptocurrencies, which make it easier for them to get paid and harder to trace.

Ransomware attacks are particularly problematic for companies and countries because they are forced to make a tough choice: pay off hackers and risk encouraging further such attacks, or hold out and take the economic or social disruption on the chin.

The response. The Colonial Pipeline hack shows how cyberattacks can do severe damage to a country by disrupting critical infrastructure. But as we've written before, these types of operations are hard to prevent, and even harder to attribute and respond to.

So far, the US government has declared a state of emergency to keep the oil flowing to the Eastern Seaboard. But at this point it can't do much more to stop the hackers, or hold them responsible for a brazen attack that would otherwise be considered an act of war against America. It can't even prevent the corporation from paying the cryptocurrency ransom.

What it can do mostly depends on whether a foreign government was involved, or aware of what DarkSide was cooking. If that's confirmed later on, the US may want to hit that country harder than with the usual economic sanctions. There could even be political pressure to respond proportionately in cyberspace — perhaps with a similarly damaging attack. And when the cyber gloves are off, things could get very bad, very fast.

More from GZERO Media

- YouTube

The Trump administration’s approach to foreign policy is clear: allies and alliances are expendable, and America is stronger alone. With support for Ukraine waning and European allies sidelined, long-term damage to transatlantic relationships may be inevitable. On Quick Take, Ian Bremmer unpacks this shift and its likely consequences.

Former Bank of Canada and Bank of England Governor Mark Carney listens to outgoing Prime Minister Justin Trudeau's speech just before being elected to succeed Trudeau as Liberal Party leader on Sunday, March 9, in Ottawa, Canada.

REUTERS/Amber Bracken/Pool

Mark Carney, former governor of the Bank of Canada and the Bank of England, won the leadership of Canada’s Liberal Party on Sunday, succeeding outgoing Prime Minister Justin Trudeau.

Syrian fighters and civilians carry the coffin of a member of the Syrian security forces during his funeral in Hama province after he and 11 other colleagues were killed in an ambush by groups loyal to the ousted President Bashar al-Assad in Latakia.

Moawia Atrash/dpa via Reuters Connect

It seems that the 14-year-long civil war isn’t quite over in Syria. Since Thursday, violent clashes between deposed dictator Bashar Assad’s Alawite loyalists and supporters of the new Sunni regime in the coastal regions have left over 1,000 dead, according to the Syrian Observatory for Human Rights.

US House Speaker Mike Johnson speaks to reporters at the Capitol in Washington, U.S., in February 2025.

REUTERS/Nathan Howard

With a government shutdown deadline looming on Friday, US House Speaker Mike Johnson on Saturday introduced a continuing resolution that, if passed, would effectively fund the government through September. US President Donald Trump has backed the bill. The budget battle comes as fears rise over the impact of Trump's tariff policies, and the flip-flopping nature of their implementation. On Sunday, Trump refused to rule out that his aggressive economic policies could cause a recession.

People stand at the site of an apartment building hit by a Russian missile strike, amid Russia's attack on Ukraine, in the town of Dobropillia, Donetsk region, Ukraine, on March 8, 2025.
REUTERS/Nadia Karpova

Russian forces bombarded Ukraine for two consecutive nights this weekend, killing over 25 people in Donetsk and Kharkiv. Moscow also retook three towns in Kursk after troops crawled for miles through a gas pipeline and staged a surprise attack.

North Korea's leader Kim Jong Un visits a shipyard, in this photo released by North Korea's official Korean Central News Agency on March 8, 2025.

KCNA via REUTERS

Cigarette in hand, and with the toothiest of grins, North Korean leader Kim Jong Un posed for photographs at a shipyard next to the makings of a “nuclear-powered strategic guided missile submarine.” The vessel appears to be a 6,000-ton-class or 7,000-ton-class one, with a payload of 10 missiles, in line with plans unveiled at the Hermit Kingdom’s 2021 party congress.

President of Turkey, Recep Tayyip Erdogan, photographed at the Presidential palace in Athens, Greece, on December 7, 2023.
Aris Oikonomou / Hans Lucas via Reuters

With so much of the world in geopolitical flux these days, it’s hard to pick clear winners or losers. But one leader who could be pretty happy about how things are going at the moment is Recep Tayyip Erdogan.

Syrian forces head to Latakia after fighters linked to Syria's ousted leader Bashar Assad mounted a deadly attack on government forces on Thursday, March 6, 2025.

REUTERS/Mahmoud Hassano

Nearly 50 people were killed on Thursday in the deadliest clashes Syria has seen since the overthrow of Bashar Assad. Pro-Assad militants attacked security checkpoints around the western coastal town of Jableh, a stronghold of the former regime.

The Liberian-flagged tanker Ice Energy, chartered by the US government, takes Iranian oil from Iranian-flagged Lana (formerly Pegas) as part of a civil forfeiture action off the shore of Karystos, on the Island of Evia, Greece, in May 2022.
REUTERS/Costas Baltas/File Photo

The Trump administration is reportedly considering a strategy to disrupt Iran’s oil exports by stopping and inspecting Iranian oil tankers at sea. The US would use the Proliferation Security Initiative, established in 2003 to prevent the trafficking of weapons of mass destruction, as a legal justification for the inspections.