Tech●●●●●Difficulty 3 of 5

How did ransomware take hospitals and a fuel pipeline hostage?

In 2021 one compromised password for an old, inactive account led to the shutdown of the pipeline that carries about 45 percent of the East Coast's fuel.

▶ Start the story

Ransomware is malware that takes a victim's private data hostage until a ransom is paid. It can lock files with encryption, steal them and threaten to publish them, or both. The ransom is usually demanded in cryptocurrency, which is harder to trace, and that is part of why the crime is hard to prosecute.

The idea is old. The first known case of malware extortion, the "AIDS Trojan" of 1989, was so badly designed that its decryption key could be extracted from the trojan itself, so paying was unnecessary. Modern versions use public-key cryptography, so only the attacker holds the key that unlocks the files.

In May 2017 WannaCry made the idea global. It spread on its own, as a worm, using an exploit called EternalBlue that the NSA had developed for Windows and that a group called The Shadow Brokers had stolen and leaked a month before. Microsoft had already released patches, but many organizations had not applied them. More than 300,000 computers in 150 countries were affected, including NHS hospitals in the UK, where some services turned away non-critical emergencies and some ambulances were diverted. The attack was halted within hours by the registration of a "kill switch" discovered by researcher Marcus Hutchins.

Ransomware milestones
  1. 1989

    The "AIDS trojan", the first documented ransomware

  2. 1996

    Young and Yung present file-encrypting ransomware

  3. 12 May 2017

    WannaCry spreads and is halted within hours by a kill switch

  4. 7 May 2021

    Colonial Pipeline halts all operations after a ransomware attack

In May 2021 the target was the Colonial Pipeline, which carries about 45 percent of the East Coast's fuel. The attackers got in with a compromised password for an inactive VPN account that had no multi-factor authentication. The company halted the whole pipeline and, according to reports, paid about $4.4 million in bitcoin. Experts later said such attacks were preventable with measures that were not in place.

Quiz me

0/3

  1. 1.Why was WannaCry able to spread to so many computers without anyone clicking a link?
  2. 2.How did attackers get into Colonial Pipeline?
  3. 3.Why do ransomware gangs usually demand cryptocurrency?

Recap

WannaCry spread through unpatched Windows, Colonial came in through an account without a second factor, and Colonial's own continuity plans beat the paid decryption tool.

💡 A trick to remember it · A padlock on your files, a ransom on the note: in 2017 the lock came in through a missed update, in 2021 through a forgotten door.

Surprising fact · WannaCry was halted within hours by registering a kill switch that one researcher had discovered.

Sources (3)

No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.

  1. [1]Ransomware · Wikipedia
  2. [2]WannaCry ransomware attack · Wikipedia
  3. [3]Colonial Pipeline ransomware attack · Wikipedia
More lessons in 💻 Tech (3) See all tech lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗