THREAD: The story of the last few weeks in business has been the ransomwear attack that took down the Colonial Pipeline.

On ransomwear-as-a-service, DarkSide, and what happens when publicity becomes really bad for business:
1/ First, a few definitions...

What is ransomwear?

Ransomware is a type of malware - a software designed to cause harm to a computer, server, or network.

Ransomwear is used to encrypt the files on your system and hold it “hostage” until the demanded ransom is paid.
2/ Ransomwear is not new, but ransomwear attacks are most definitely on the rise.

With the world increasingly moving online, the cyber-attackers have experienced a windfall.

Both the frequency of attacks and the size of the average ransom payments have increased dramatically.
3/ The way a ransomwear attack works is really quite simple (even if the underlying technology is complicated).

A would-be attacker scans for vulnerable companies.

They often look for dated systems or weak infrastructure - like an animal looking for injured prey.
4/ When a target is acquired, the cyber-attacker looks for an entry point.

This could be using a phishing scam or other method to gain access to the network or company data and servers.

Once inside, the cyber-attacker launches a program that encrypts all of the company’s data.
5/ Once encrypted, the data and systems become completely unusable without a decryption key.

The company is immobilized.

While this sounds complex, given the range of cybersecurity sophistication at companies, hackers say breaching some companies is “so easy a kid could do it.”
6/ After the encryption is complete, the ransom negotiation begins.

The cyber-attackers reach out to the company, offering to provide a decryption key that will return access to the hostage data.

In exchange, the company has to pay a ransom (usually in the form of Bitcoin).
7/ If ransom isn’t paid, the data may continue to be held (leaving the company immobilized) or sensitive data (credit cards, health records, etc.) may be leaked.

Generally speaking, the company negotiates and pays the ransom, with its cyber insurance footing the bill.
8/ The ransomwear market has operated in the shadows for a long time...until recently.

The story of a high profile attack on the Colonial Pipeline - and the fascinating “ransomwear-as-a-service” entity that enabled it - has shined a light on the industry.

Let’s dive in...
9/ Colonial Pipeline is the largest gas pipeline in the U.S.

On May 7, it announced it had been hit by a ransomwear attack and had shut down operations.

This ransomwear attack was different.

It wasn’t an attack on a medium-sized business.

It was much, much bigger than that.
10/ With the pipeline out of commission, gas prices spiked, impacting millions and drawing the immediate, full attention of the press (and the FBI).

Suddenly, ransomwear attacks were in the spotlight.

And the services group enabling the attacks - DarkSide - was at center stage.
11/ DarkSide is a so-called “ransomwear-as-a-service” company.

It doesn’t engage in the actual cyberattacks.

Instead, it provides a suite of tools and services that enable would-be cyber-attackers to conduct their business.
12/ DarkSide provides the malware that encrypts the data, but also much more.

A communication service - making calls to the victim companies for negotiations.

A hosting site for stolen data.

Customer service.

It can even sell inside info to stock traders for extra profit.
13/ Think of DarkSide as a cloud services provider for the modern ransomwear era.

It appears to be the market leader in providing such services!

And it has an impressive economic model: DarkSide takes a 10-25% cut of the proceeds from the ransom payment.
14/ Normally, startups with strong market traction love publicity.

It helps with new customer acquisition and growth!

But the difference here is that when you are a ransomwear-as-a-service market leader, publicity can be really, really bad for business.
15/ With the authorities now focused on them, DarkSide issued a statement:

“Our goal is to make money and not create problems for society. From today, we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future.”
16/ DarkSide learned the hard way what banks learned long ago: you have to know your customer!

The Colonial Pipeline shutdown lasted about a week.

Operations were restored after a rumored ransom payment of ~$5m (75-100 BTC).

DarkSide’s cut was hefty - but it came at a cost.
17/ In the months to come, with the spotlight shined on the sophistication of the ransomwear market - as well as the devastating nature of the attacks - companies will step up their cybersecurity infrastructure to defend themselves.

This may be bad for ransomwear profits...
18/ So is this just a classic market cycle?

The ransomwear market had predictable, large profits.

This led to a rush of activity to exploit them.

Now the market gets squeezed, making it less attractive to do ransomwear attacks.

Free markets at work...?
19/ That is the story of DarkSide, the Colonial Pipeline hack, and the fascinating ransomwear-as-a-service business model.

For more, check out the below resources:

bloomberg.com/news/articles/…

bloomberg.com/news/articles/…
20/ Follow me for more threads demystifying the world of business and finance. You can find all of my threads in the meta-thread below.
21/ And subscribe to my newsletter, to receive my threads, audio versions, and other weekly curated content directly to your inbox! sahilbloom.substack.com
Please insert *ransomware* in place of ransomwear.

Cannot wait for Twitter Blue...

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Sahil Bloom

Sahil Bloom Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @SahilBloom

15 May
Intellectual curiosity is a competitive advantage.

But contrary to what you’ve been told, it has nothing to do with intelligence.

10 ways to start developing your intellectual curiosity today:
Scrub Your Windows

“Your assumptions are your windows on the world. Scrub them off every once in a while, or the light won't come in.” - Isaac Asimov

Curiosity is a light that can only enter when your mental windows are clean.

Scrub them off now and then.

Let the light in.
Embrace “I Don’t Know”

“The only true wisdom is in knowing you know nothing.” - Socrates

Avoid false confidence (and the people that display it!).

Embracing what you do not know is a superpower.

Recognize your gaps and blind spots.

Slowly, methodically fill them in.
Read 13 tweets
8 May
1 year ago, I wrote my first Twitter thread.

100 threads and 70,000+ words later, I’m just getting started.

10 favorites (on business, finance, mental models, and life):
Competitive Advantages

10 competitive advantages that don’t require talent.

(Note: This may be the subject of a future book...)
The Feynman Technique

A method for learning through teaching.

Complexity and jargon are often used to mask a lack of deep understanding.

Find beauty in simplicity.
Read 13 tweets
1 May
Warren Buffett is a treasure trove of wisdom.

But contrary to what you have been told, most of it has nothing to do with investing.

10 powerful lessons for life from the Oracle of Omaha:
Wait For A Juicy Pitch

“You don't have to swing at everything - you can wait for your pitch."

Life doesn’t reward you for the number of swings you take.

Focus on identifying the juiciest pitch.

When it comes, swing hard and don’t miss it.
Just Stop Digging

“The most important thing to do if you find yourself in a hole is to stop digging."

When things aren’t working, change course and try something different.

Be nimble. Be agile.

When you find yourself at the bottom of a hole, stop digging and climb out of it.
Read 14 tweets
28 Apr
Transformative innovation begins with a variant perception.

A belief or view that differs from the consensus.

4 variant perceptions that are changing the world:
TSMC - Morris Chang

Variant Perception: The status quo (integrated chip design and manufacturing) was constraining innovation in the semiconductor industry.

Solution: Pure play chip manufacturer.

Outcome: Rapidly accelerating chip innovation that has propelled society forward.
Stripe - @patrickc & @collision

Variant Perception: Existing internet payments infrastructure created friction and limited economic growth.

Solution: Developer-friendly tools for the online economy.

Outcome: Infrastructure solutions that are increasing the GDP of the internet.
Read 9 tweets
24 Apr
In his final Amazon shareholder letter, Jeff Bezos shared a powerful mental model on maintaining your distinctiveness.

A thread on the fight against normalcy (in your career, startup, writing, or life):
Jeff Bezos founded Amazon in 1994.

In 27 years at the helm, he grew it into one of the largest and most influential companies in the world.

Today, it is worth almost $1.7 trillion.

Each year since its 1997 IPO, Bezos has written an annual letter to Amazon shareholders.
In February, Jeff Bezos announced he would step down as CEO.

In his final annual shareholder letter, he covered his “create more than you consume” mantra and hit on climate and employee issues.

But its closing - on the fight against normalcy - held the most powerful lessons.
Read 15 tweets
18 Apr
To grow, you need to be relentlessly consistent.

Because growth - in your career, startup, writing, or life - comes gradually and then suddenly.

10 threads to help you on your growth journey:
Competitive Advantages

10 competitive advantages that don’t require talent.
The Feynman Technique

A learning framework for growth:
(1) Identify
(2) Explain It To Me Like I’m 5
(3) Reflect & Study
(4) Organize, Convey & Review
Read 13 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!

:(