• Home
  • Southern New Hampshire University
  • Cyberlaw and Ethics IT412
  • Cybersecurity and Ethics

Cybersecurity and Ethics

Hello Everyone, The security breach I researched was a ransomware attack on the Colonial Pipeline. At first, I didn't understand how an oil pipeline could be the target of a security breach such as this Usually, I think of security breaches in terms of large computer firms and data centers. This pipeline is one of the largest fuel pipelines in the U.S. It provides approximately 45% of the fuel sent to the East Coast including, gasoline, diesel, jet fuel, military supplies, and home heating oil (Osborne, 2021). The attack on the Colonial Pipeline was caused by a single compromised password (Turton & Mehrotra, 2021). The attack on the Colonial Pipeline took place on April 29th, 2021. It was perpetrated by a robin hood-like group of hackers calling themselves DarkSide (Morgan, 2021). It was reported that the group stole more than 100 Gigabytes of the company's data. This data included the personal information of current and former company employees and their families. The hackers gained access to the company's network by using the virtual private network password of a former employee no longer in use. The VPN account did not incorporate multifactor authentication, so a compromised username and password was all that was required to access the company's network. As a result of this attack, Colonial Pipeline and several of its smaller pipelines were shut down and several private companies working with the U.S. government shut down cloud servers from which the Colonial Pipeline, attacks were launched (Morgan, 2021). This shut down lead to widespread fuel shortages all along the eastern coast. It also cost the company $4.4 million to resolve the incident although some of that ransom money has been recovered by authorities. References Fung, B. (2021, August 16). Colonial pipeline says ransomware attack also led to personal information being stolen. CNN. https://www.cnn.com/2021/08/16/tech/colonial-pipeline- ransomware/index.html. Morgan, L. (2021, May 14). I0TW: Ransomware attack Closes Colonial Pipeline. Cyber Security Hub. https://www.cshub.com/attacks/articles/iotw-ransomware-attack-closes- colonial-pipeline?preview=1882a995f678930583a8722943f42babe42f1e92. Osborne, C. (2021, May 13). Colonial pipeline attack: Everything you need to know. ZDNet. https://www.zdnet.com/article/colonial-pipeline-ransomware-attack-everything-you-need- to-know/. Turton, W., & Mehrotra, K. (2021, June 4). Hackers Breached Colonial Pipeline Using Compromised Password. Bloomberg.com. https://www.bloomberg.com/news/articles/2021-06-04/hackers-breached-colonial-pipeline- using-compromised-password