President Biden promised a US response to DarkSide yesterday and right now something very bad appears to be happening to DarkSide, which hacked the Colonial Pipeline.
Cybersecurity firm Mandiant says it sees dark web posts claiming DarkSide lost access to its infrastructure, including blog, payment, and servers and will be closing its criminal service service.
Mandiant says the Posts claim decrypters will be provided for companies who have not paid- that is, DarkSide is allegedly telling its affiliates to let its victims off the hook.
Intel471 reports that dark web posts claim DarkSide has promised to compensate outstanding financial obligations to its criminal associates by May 23.
Intel 471 also says posts claim funds from DarkSide cryptocurrency wallets allegedly were exfiltrated- not clear who cleared them out, though.
And Intel 471 also reports the Cryptocurrency mixing service BitMix is reportedly inaccessible this week- that’s important because it’s one way hackers allegedly launder the proceeds of their criminal activity.
No confirmation that the US government is responsible for this.
Couple notes of caution - this could be the result of government action, private sector Cybersecurity action or rival gangs sensing weakness and piling on.
Also - bear in mind that DarkSide may very well want the world to *think* they have gone away, even as they scramble to reconstitute in another format.
Asked if the US government is responsible for this apparent DarkSide takedown, a National Security Council spokesperson tells me now: "unfortunately don’t have anything for you here."
The @NSAGov just responded to my request for comment on all this ... and referred me to the National Security Council, which has already declined to comment.
• • •
Missing some Tweet in this thread? You can try to
force a refresh
NEW: Colonial Pipeline has already begun restarting the pipeline. Here’s their statement: “Colonial Pipeline initiated the restart of pipeline operations today at approximately 5 p.m. ET.”
“Following this restart, it will take several days for the product delivery supply chain to return to normal.”
“Some markets served by Colonial Pipeline may experience, or continue to experience, intermittent service interruptions during the start-up period.”
NEW: Despite a global outcry about the Colonial Pipeline attack, DarkSide has not stopped its hacking activity. The hackers have posted to the dark web names of three new companies it claims to have attacked. One is in the US, in Illinois, one in Brazil and one in the UK.
The 3 new names were posted over the past 24 hours. CNBC has reached out to the companies reportedly affected and will report more as we have it.
Victim #1: technology services reseller. DarkSide claims to have encrypted more than 600 GBs of data.
Victim #2: Brazilian reseller of renewable energy products. DarkSide claims more than 400 GBs of data encrypted.
Victim #3: UK construction company. More than 900 GBs encrypted.
Energy secretary Granholm: the CEO of Colonial Pipeline says the company will be able to make full restart decision by close of business tomorrow, but it will take a few days to get up and running.
Granholm: We expect that has station owners are and will be acting appropriately. We don’t want to see price gouging.
Granholm: much as there was no cause for hoarding toilet paper at the beginning of the pandemic, there is no cause for hoarding gas now.
Holy (Fake) Cow: DOJ says man pleaded guilty to defrauding Tyson Foods and another company out of more than $244 million by charging them for purchasing and feeding hundreds of thousands of cattle that did not actually exist.
DOJ: False and fraudulent invoices sought and obtained reimbursement from victim companies for purported costs of purchasing and growing hundreds of thousands of cattle that neither Cody Allen Easterday, 49, nor his Easterday Ranches ever purchased, and did not actually exist.
DOJ says Easterday used the fraud proceeds for his personal use and benefit, and for the benefit of Easterday Ranches, including to cover approximately $200 million in commodity futures contracts trading losses that Easterday had incurred.
The best April Fool’s gag I ever fell for came early in the life of @politico, where we had been gaining traction with the relentless philosophy: “win the morning.”
@harrispolitico sent an all staff memo telling us we were going to double down on the early news cycle: now he wanted us to win the pre-dawn.
The gist was he wanted everyone to make a round of calls to sources in the four and five am hours, to get a jump on the competition, who were lazier, and probably wouldn’t get started until around six.