How did ransomware take hospitals and a fuel pipeline hostage?
In 2021 one compromised password for an old, inactive account led to the shutdown of the pipeline that carries about 45 percent of the East Coast's fuel.
▶ Start the storyRansomware is malware that takes a victim's private data hostage until a ransom is paid. It can lock files with encryption, steal them and threaten to publish them, or both. The ransom is usually demanded in cryptocurrency, which is harder to trace, and that is part of why the crime is hard to prosecute.
The idea is old. The first known case of malware extortion, the "AIDS Trojan" of 1989, was so badly designed that its decryption key could be extracted from the trojan itself, so paying was unnecessary. Modern versions use public-key cryptography, so only the attacker holds the key that unlocks the files.
In May 2017 WannaCry made the idea global. It spread on its own, as a worm, using an exploit called EternalBlue that the NSA had developed for Windows and that a group called The Shadow Brokers had stolen and leaked a month before. Microsoft had already released patches, but many organizations had not applied them. More than 300,000 computers in 150 countries were affected, including NHS hospitals in the UK, where some services turned away non-critical emergencies and some ambulances were diverted. The attack was halted within hours by the registration of a "kill switch" discovered by researcher Marcus Hutchins.
1989
The "AIDS trojan", the first documented ransomware
1996
Young and Yung present file-encrypting ransomware
12 May 2017
WannaCry spreads and is halted within hours by a kill switch
7 May 2021
Colonial Pipeline halts all operations after a ransomware attack
In May 2021 the target was the Colonial Pipeline, which carries about 45 percent of the East Coast's fuel. The attackers got in with a compromised password for an inactive VPN account that had no multi-factor authentication. The company halted the whole pipeline and, according to reports, paid about $4.4 million in bitcoin. Experts later said such attacks were preventable with measures that were not in place.
Quiz me
0/3
Recap
WannaCry spread through unpatched Windows, Colonial came in through an account without a second factor, and Colonial's own continuity plans beat the paid decryption tool.
💡 A trick to remember it · A padlock on your files, a ransom on the note: in 2017 the lock came in through a missed update, in 2021 through a forgotten door.
Surprising fact · WannaCry was halted within hours by registering a kill switch that one researcher had discovered.
Connects to
- 🪱 How did one student's experiment slow down the early internet?
- ⚖️ Should governments tell vendors about the flaws they find, or keep them for spying?
- 🕳️ What is a zero-day, and why do companies pay hackers to find bugs?
- 🔐 Why does a second login step make accounts so much harder to take over, and what comes after passwords?
- 🎣 Why does one convincing email fool even careful people?
- 🪙 How did an anonymous white paper turn into money nobody controls?
- 🔐 How can two strangers agree on a secret while everyone is listening?
- Cryptocurrency
Sources (3)
No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.