One password allowed hackers to disrupt Colonial Pipeline, CEO tells senators

  • 📰 Reuters
  • ⏱ Reading Time:
  • 31 sec. here
  • 2 min. at publisher
  • 📊 Quality Score:
  • News: 16%
  • Publisher: 97%

United States Headlines News

United States Latest News,United States Headlines

The head of Colonial Pipeline told U.S. senators on Tuesday that hackers who launched last month's cyber attack against the company and disrupted fuel supplies to the U.S. Southeast were able to get into the system by stealing a single password.

Colonial Pipeline Chief Executive Joseph Blount told a U.S. Senate committee that the attack occurred using a legacy Virtual Private Network system that did not have multifactor authentication in place. That means it could be accessed through a password without a second step such as a text message, a common security safeguard in more recent software.

Security experts call the use of a single-factor login system a sign of poor cybersecurity "hygiene." They recommend two-factor authentication, which requires a secondary measure like a mobile text or hardware token, and most major companies require this across all internal applications. "It was our understanding that the decision was solely ours to make about whether to pay the ransom," he said.

On Friday, U.S. Deputy Attorney General Lisa Monaco urged companies to tell federal authorities whether they paid ransom to cyberattackers, information that can help investigators.

 

Thank you for your comment. Your comment will be published after being reviewed.
Please try again later.

yuga_khan

FBI had the private keys to the crypto account ? 🧐🤔

Ooh... Let me guess... Was it MAGA2020 ?

Video game companies ask you to have 2 factor authentication these days but a massive pipeline is one password away from oblivion? facepalm

We have summarized this news so that you can read it quickly. If you are interested in the news, you can read the full text here. Read more:

 /  🏆 2. in US

United States Latest News, United States Headlines

Similar News:You can also read news stories similar to this one that we have collected from other news sources.

Colonial Pipeline CEO says no one 'wants to know' results if ransom wasn't paid to hackers'That's an unknown we probably don't want to know. And it's an unknown we probably don't want to play out in a public forum,' Colonial Pipeline CEO Joseph Blount said about the attack. Come on people, wake up....
Source: Newsweek - 🏆 468. / 52 Read more »

U.S. Reportedly Recoups ‘Millions’ In Cryptocurrency Ransom Paid To Colonial Pipeline HackersI cover national politics for Forbes. Previously, I've written for TIME, Newsweek, the New York Daily News and VICE News. I also launched my own startup, Newsreel, a politics news platform for a young audience.
Source: Forbes - 🏆 394. / 53 Read more »

U.S. seizes $2.3 mln in bitcoin paid to Colonial Pipeline hackersThe Justice Department on Monday recovered some $2.3 million in cryptocurrency ransom paid by Colonial Pipeline Co, cracking down on hackers who launched the most disruptive U.S. cyberattack on record.
Source: Reuters - 🏆 2. / 97 Read more »

DOJ recovered $2.3 million of ransom paid in Colonial Pipeline attackThe Department of Justice recovered a majority of the ransom paid to the hacker group DarkSide in the Colonial Pipeline ransomware attack. Got to be more to this. Great timing! Now the meeting with Putin might have a decidedly different 'tone'? When Biden (when asked if Putin was testing him) said 'No!' (with a smirk) he knew! Love it! 🎉🎊🎉
Source: MSNBC - 🏆 469. / 51 Read more »

U.S. government recovered millions of dollars paid in Colonial Pipeline hack ransomThe U.S. government recovered millions of dollars in Bitcoin paid by Colonial Pipeline to ransomware hackers who locked up its computer system last month. 🕵️‍♂️🕵️ but would they give citizens at the pumps a break? NO!!!
Source: latimes - 🏆 11. / 82 Read more »

U.S. recovers $2.3 million in bitcoin paid in the Colonial Pipeline ransomU.S. officials said they were able to retrieve some of the money paid to criminal hackers involved in a crippling ransomware attack on Colonial Pipeline.
Source: CNBC - 🏆 12. / 72 Read more »