Content |
History
2021
Raising $90 million from hacking victims
On May 18, 2021, it became known that the hacker group DarkSide received from the victim companies of its cyber attacks a total ransom of about $90 million in cryptocurrency. Cybercriminals introduce viruses into the IT systems of organizations, block their work and extort money - this is what happened with the attack on the largest Colonial Pipeline in the United States.
The fact that DarkSide managed to lure $90 million was reported in the analytical company Elliptic, specializing in blockchain technologies. Elliptic co-founder and chief scientist Tom Robinson said that the analysis includes only payments already made. He added that "further transactions can still be disclosed, and the numbers here should be considered as a lower bound." According to experts, the Bitcoin wallet DarkSide contained a digital currency worth $5.3 million before its devastation.
The DarkSide reported that cryptocurrency transfers to DarkSide were made from 47 wallets. The average payment of extortion victims is estimated at $1.9 million.
Security experts from Intel 471, in turn, said that DarkSide decided to dissolve after losing access to its servers and devastating wallets with cryptocurrency. There are suggestions that the remaining $5.3 million after the operations were frozen by the US government.
American media reported a possible connection between hackers who attacked Colonial Pipeline and Russia. At the same time, the White House did not confirm this information. Deputy Assistant to the US President for National Security Ann Nyberger explained that the attack was carried out by a group of hackers, and not some state.
In turn, the press secretary of the President of the Russian Federation Dmitry Peskov on May 11, 2021 stated that Russia had nothing to do with these hacker attacks.[1]
Attack on the American pipeline Colonial Pipeline
In May 2021, Colonial Pipeline announced that the company was subjected to a cyber attack. Some systems are "proactively" disabled, for the time being "all operations are stopped." More details here.