Would you pay a cyber ransom?

Would you pay a cyber ransom?
Paige Fusco

A few days ago, cyber criminals hacked into one of the largest oil pipelines in the US, which halted operations after its corporate IT network was knocked offline. If the engineers don't fix the system on their own or the owners cough up the ransom that the hackers are demanding, millions of Americans will soon feel the heat of cybercrime in their daily lives, through higher prices at the gas pump.

Who pulled off this attack, and what does it tell us about the vulnerability of critical infrastructure and the rules (or lack thereof) in cyber conflict today?

The culprit. The US government has blamed the Colonial Pipeline cyberattack on DarkSide, a relatively new group of veteran hackers from Eastern Europe famous for bragging about its exploits online, and leaking data dumps from victims who don't pay up. The DarkSiders style themselves as Robin Hoods of the hacker world, donating (a minuscule) part of their profits to global NGOs such as Children International and The Water Project. But this time they may have bitten off a bit more than they can chew.

DarkSide issued on Monday a rare apology for creating "problems" to society, insisting they only want money and are not at all interested in politics, although they do seem to avoid former Soviet bloc nations. That's common for cyber criminals based in these countries, whose governments will look the other way as long as hackers target victims outside their borders.

One of those governments is that of Russia, with a long history of outsourcing its dirty cyber work to unscrupulous hackers. Joe Biden says there's no evidence that the Kremlin was involved this time, but does have "some responsibility."

The problem. The fact that a bunch of geeks armed with laptops shut down a pipeline that serves 45 percent of America's oil refineries shows that US critical infrastructure is a lot more vulnerable to cyber-extortion than we'd like to think. And the Biden administration's $2 trillion plan to upgrade US infrastructure across the board turns cybersecurity into an even more urgent concern.

As always, the pandemic has made everything worse. Ransomware attacks — and cybercrime in general — have boomed in COVID times, largely as a result of IT systems that became more vulnerable when companies rushed to adapt them for remote access. Moreover, hackers are now targeting bigger firms for a lot more money thanks to the rise of cryptocurrencies, which make it easier for them to get paid and harder to trace.

Ransomware attacks are particularly problematic for companies and countries because they are forced to make a tough choice: pay off hackers and risk encouraging further such attacks, or hold out and take the economic or social disruption on the chin.

The response. The Colonial Pipeline hack shows how cyberattacks can do severe damage to a country by disrupting critical infrastructure. But as we've written before, these types of operations are hard to prevent, and even harder to attribute and respond to.

So far, the US government has declared a state of emergency to keep the oil flowing to the Eastern Seaboard. But at this point it can't do much more to stop the hackers, or hold them responsible for a brazen attack that would otherwise be considered an act of war against America. It can't even prevent the corporation from paying the cryptocurrency ransom.

What it can do mostly depends on whether a foreign government was involved, or aware of what DarkSide was cooking. If that's confirmed later on, the US may want to hit that country harder than with the usual economic sanctions. There could even be political pressure to respond proportionately in cyberspace — perhaps with a similarly damaging attack. And when the cyber gloves are off, things could get very bad, very fast.

More from GZERO Media

- YouTube

What does Putin mean when he says Europe "will stand at the feet of the master"? What's next for Panama after deciding to exit China's Belt and Road Initiative? How would a potential Turkey defense pact with Syria reshape power dynamics in the Middle East? Ian Bremmer shares his insights on global politics this week on World In :60.

Walmart is fueling American jobs and strengthening communities by investing in local businesses. Athletic Brewing landed a deal with Walmart in 2021. Since then, co-founders Bill Shufelt and John Walker have hired more than 200 employees and built a150,000-square-foot brewery in Milford, CT. Athletic Brewing is one of many US-based suppliers working with Walmart. By 2030, the retailer is estimated to support the creation of over 750,000 US jobs by investing an additional $350 billion in products made, grown, or assembled in America. Learn more about Walmart’s commitment to US manufacturing.

In this new episode of Tools and Weapons, Microsoft's Vice Chair and President Brad Smith and Dr. Fei-Fei Li reflect on poignant moments from her memoir, "The Worlds I See: Curiosity, Exploration, and Discovery at the Dawn of AI," highlighting the crucial role of keeping humanity at the center of AI development. They also explore how government-funded academic research, driven by curiosity rather than profits, can lead to unexpected and profound discoveries that propel innovation and economic opportunities. Dr. Li is a pioneering AI scientist breaking new ground in computer vision, and she is a Stanford professor who is currently leading the innovative start-up World Labs. While her career is deeply rooted in technical expertise, Dr. Li's journey is driven by an insatiable curiosity. Subscribe and find new episodes monthly, wherever you listen to podcasts.

Syria's newly appointed President for a transitional phase Ahmed al-Sharaa meets with Turkey's President Tayyip Erdogan at the Presidential Palace in Ankara, Turkey, February 4, 2025.
Murat Cetinmuhurdar/PPO/Handout

Ankara is first outside player to fill the power vacuum left by the collapse of the Assad regime last December.

Deported migrants are guarded by elements of the National Institute of Migration at the entrance of the Paso del Norte International Bridge in Ciudad Juarez, Mexico, on February 1, 2025, where North American authorities carry out these mass deportations and hand them over to personnel of said institute.
(Photo by Gerardo Vieyra/NurPhoto)

US President Donald Trump plans to invoke the 1798 Alien Enemies Act to deport alleged gang members without due process. The statute was used in 1812 against British nationals, during World War I against nationals of the German Empire and Austria-Hungary, and in World War II against Americans of Japanese descent.

Cabs drive along Westminster Bridge in front of the British Parliament with the Elizabeth Tower and the famous Big Ben bell.

Julia Kilian/dpa via Reuters Connect

The United Kingdom is set to unveil the world’s first national law criminalizing the use of artificial intelligence tools for generating child sex abuse material, or CSAM.

Lettering on a logo of the European Union, AI-Act, the symbolic image for the laws and regulation of artificial intelligence in Europe.

IMAGO/Bihlmayerfotografie via Reuters Connect

The first restrictions under Europe’s landmark artificial intelligence law just took effect.