‘It was the right thing to do’: Colonial Pipeline CEO defends bitcoin ransom payment to hackers

‘I will admit that I wasn’t comfortable seeing money go out the door to people like this,’ CEO Joseph Blout says

<p>Colonial Pipeline CEO Joseph Blout has defended paying ransom to Russian hackers</p>

Colonial Pipeline CEO Joseph Blout has defended paying ransom to Russian hackers

Leer en Español

Colonial Pipeline’s CEO has defended the company’s decision to pay a bitcoin ransom to hackers after a cybersecurity attack shut down the pipeline.

“It was the right thing to do for the country,” CEO Joseph Blout told The Wall Street Journal. “I didn’t make it lightly. I will admit that I wasn’t comfortable seeing money go out the door to people like this.”

This was the first public statement from the Georgia-based company that admitted to paying the $4.4 million in bitcoin ransom to DarkSide, a Russian-based hacking group.

Mr Blout said his company decided to pay the ransom on the same day of the attack even though it was a “highly controversial decision”.

Typically a ransomware attack involves hackers locking up computer systems by encrypting data and paralysing networks before asking for a large ransom from the targeted company to unscramble it.

The FBI has long advised companies against paying a ransom when hit by a ransomware attack, as paying the hackers gives them more incentive to target other organisations.

“The FBI does not support paying a ransom in response to a ransomware attack,” the FBI states on its website. “It also encourages perpetrators to target more victims and offers an incentive for others to get involved in this type of illegal activity.”

The ransomware attack led to the shutdown of Colonial Pipeline’s 5,500 mile pipeline for six days, causing gas shortages and prices to increase in parts of the US.

Mr Blout told The Wall Street Journal that his company decided to pay the ransom on the day of the attack after consulting with experts who’ve previously dealt with DarkSide. But the CEO declined to name these experts to the publication.

After DarkSide received payment from Colonial Pipeline, the hackers provided the operator with a decrypting tool that would restore the company’s computer network, thus allowing for pipeline services to resume, Bloomberg first reported. But the company also reportedly used its own backups to restore the system due to how slowly the provided tool worked.

Although the pipeline’s service, which runs between Texas and New Jersey delivering more than 100 million gallons of fuel per day, was restored, the company was still unable to bill customers due to the aftermath of the cyberattack.

Colonial Pipeline has also lost all anonymity with the public.

“We were perfectly happy having no one know who Colonial Pipeline was, and unfortunately that’s not the case anymore,” Mr Blount said. “Everybody in the world knows.”

Register for free to continue reading

Registration is a free and easy way to support our truly independent journalism

By registering, you will also enjoy limited access to Premium articles, exclusive newsletters, commenting, and virtual events with our leading journalists

Please enter a valid email
Please enter a valid email
Must be at least 6 characters, include an upper and lower case character and a number
Must be at least 6 characters, include an upper and lower case character and a number
Must be at least 6 characters, include an upper and lower case character and a number
Please enter your first name
Special characters aren’t allowed
Please enter a name between 1 and 40 characters
Please enter your last name
Special characters aren’t allowed
Please enter a name between 1 and 40 characters
You must be over 18 years old to register
You must be over 18 years old to register
Opt-out-policy
You can opt-out at any time by signing in to your account to manage your preferences. Each email has a link to unsubscribe.

By clicking ‘Create my account’ you confirm that your data has been entered correctly and you have read and agree to our Terms of use, Cookie policy and Privacy notice.

This site is protected by reCAPTCHA and the Google Privacy policy and Terms of service apply.

Already have an account? sign in

By clicking ‘Register’ you confirm that your data has been entered correctly and you have read and agree to our Terms of use, Cookie policy and Privacy notice.

This site is protected by reCAPTCHA and the Google Privacy policy and Terms of service apply.

Register for free to continue reading

Registration is a free and easy way to support our truly independent journalism

By registering, you will also enjoy limited access to Premium articles, exclusive newsletters, commenting, and virtual events with our leading journalists

Already have an account? sign in

By clicking ‘Register’ you confirm that your data has been entered correctly and you have read and agree to our Terms of use, Cookie policy and Privacy notice.

This site is protected by reCAPTCHA and the Google Privacy policy and Terms of service apply.

Join our new commenting forum

Join thought-provoking conversations, follow other Independent readers and see their replies

Comments

Thank you for registering

Please refresh the page or navigate to another page on the site to be automatically logged inPlease refresh your browser to be logged in