Skip to content
Search

Latest Stories

News

Would you pay a cyber ransom?

Would you pay a cyber ransom?
Paige Fusco

A few days ago, cyber criminals hacked into one of the largest oil pipelines in the US, which halted operations after its corporate IT network was knocked offline. If the engineers don't fix the system on their own or the owners cough up the ransom that the hackers are demanding, millions of Americans will soon feel the heat of cybercrime in their daily lives, through higher prices at the gas pump.

Who pulled off this attack, and what does it tell us about the vulnerability of critical infrastructure and the rules (or lack thereof) in cyber conflict today?


The culprit. The US government has blamed the Colonial Pipeline cyberattack on DarkSide, a relatively new group of veteran hackers from Eastern Europe famous for bragging about its exploits online, and leaking data dumps from victims who don't pay up. The DarkSiders style themselves as Robin Hoods of the hacker world, donating (a minuscule) part of their profits to global NGOs such as Children International and The Water Project. But this time they may have bitten off a bit more than they can chew.

DarkSide issued on Monday a rare apology for creating "problems" to society, insisting they only want money and are not at all interested in politics, although they do seem to avoid former Soviet bloc nations. That's common for cyber criminals based in these countries, whose governments will look the other way as long as hackers target victims outside their borders.

One of those governments is that of Russia, with a long history of outsourcing its dirty cyber work to unscrupulous hackers. Joe Biden says there's no evidence that the Kremlin was involved this time, but does have "some responsibility."

The problem. The fact that a bunch of geeks armed with laptops shut down a pipeline that serves 45 percent of America's oil refineries shows that US critical infrastructure is a lot more vulnerable to cyber-extortion than we'd like to think. And the Biden administration's $2 trillion plan to upgrade US infrastructure across the board turns cybersecurity into an even more urgent concern.

As always, the pandemic has made everything worse. Ransomware attacks — and cybercrime in general — have boomed in COVID times, largely as a result of IT systems that became more vulnerable when companies rushed to adapt them for remote access. Moreover, hackers are now targeting bigger firms for a lot more money thanks to the rise of cryptocurrencies, which make it easier for them to get paid and harder to trace.

Ransomware attacks are particularly problematic for companies and countries because they are forced to make a tough choice: pay off hackers and risk encouraging further such attacks, or hold out and take the economic or social disruption on the chin.

The response. The Colonial Pipeline hack shows how cyberattacks can do severe damage to a country by disrupting critical infrastructure. But as we've written before, these types of operations are hard to prevent, and even harder to attribute and respond to.

So far, the US government has declared a state of emergency to keep the oil flowing to the Eastern Seaboard. But at this point it can't do much more to stop the hackers, or hold them responsible for a brazen attack that would otherwise be considered an act of war against America. It can't even prevent the corporation from paying the cryptocurrency ransom.

What it can do mostly depends on whether a foreign government was involved, or aware of what DarkSide was cooking. If that's confirmed later on, the US may want to hit that country harder than with the usual economic sanctions. There could even be political pressure to respond proportionately in cyberspace — perhaps with a similarly damaging attack. And when the cyber gloves are off, things could get very bad, very fast.

More For You

​Russian President Vladimir Putin meets with journalists to comment on new U.S. sanctions targeting two major Russia's oil producers, as well as other international issues, in Moscow, Russia, October 23, 2025.

Russian President Vladimir Putin meets with journalists to comment on new U.S. sanctions targeting two major Russia's oil producers, as well as other international issues, in Moscow, Russia, October 23, 2025.

Sputnik/Alexander Shcherbak/Pool via REUTERS
Trump relaxes Russian oil sanctionsThe US has paused Russian oil sanctions in a bid to stabilize energy markets rocked by the war with Iran. Administration officials stress that it’s a “tailored” measure, applying only to oil already loaded onto tankers, but it’s still a gift to Russia, which has already been clocking an extra $150 million daily [...]
​A Boeing C-135 Stratotanker / Stratolifter military aircraft known as KC-135 of the United States Air Force USAF configured as Air Tanker Transport for aerial refueling, powered by 4x CFMI jet engines and tail number 63-8003. The military plane spotted flying over the Netherlands in the blue sky from Mainland USA to Tel Aviv TLV to support the Israel USA - Iran war known as Operation Epic Fury by the US Department of Defense. Venlo, the Netherlands on March 2, 2026

A Boeing C-135 Stratotanker / Stratolifter military aircraft known as KC-135 of the United States Air Force USAF configured as Air Tanker Transport for aerial refueling, powered by 4x CFMI jet engines and tail number 63-8003. The military plane spotted flying over the Netherlands in the blue sky from Mainland USA to Tel Aviv TLV to support the Israel USA - Iran war known as Operation Epic Fury by the US Department of Defense. Venlo, the Netherlands on March 2, 2026

Photo by Nicolas Economou/NurPhoto
4: The number of crew members aboard a US refuelling plane – out of six total – who died after the aircraft crashed in neighboring Iraq on Thursday, US Central Command said this morning. CENTCOM said the cause of the crash is still under investigation, but noted it was neither due to friendly nor hostile fire. The plane was part of Operation Epic [...]
US ​President Donald Trump holds a Cabinet meeting at the White House in Washington, D.C., USA, on April 30, 2025.

US President Donald Trump listens to remarks during a Cabinet meeting in the Cabinet Room of the White House in Washington, D.C., USA, on April 30, 2025.

Ken Cedeno/Pool/Sipa USA
US President Donald Trump’s first term in office sometimes looked like an episode of “The Apprentice.” He fired or forced out eight Cabinet members, with 14 in total leaving – more than the preceding three presidents combined. Total turnover among his top officials was 92% across all four years, higher than that of his immediate predecessors. [...]
​Participants hold placards during a protest to condemn the U.S. and Israeli attacks on Iran and commemorate students killed in a strike on a girls' primary school in Minab in southern Iran on February 28, in front of the U.S. embassy in Seoul, South Korea, March 12, 2026.

Participants hold placards during a protest to condemn the U.S. and Israeli attacks on Iran and commemorate students killed in a strike on a girls' primary school in Minab in southern Iran on February 28, in front of the U.S. embassy in Seoul, South Korea, March 12, 2026.

REUTERS/Kim Soo-hyeon
175: The number of people killed at an Iranian girls’ school in a strike on Feb. 28. Initial intelligence reports suggest that the US was to blame for the strike, per the New York Times, after the military used a now-defunct set of coordinates to deploy the hit. The White House hasn’t claimed responsibility and said the investigation is ongoing. [...]