Unsplash

奥础厂贬滨狈骋罢翱狈听听The US Department of Justice is elevating investigations of ransomware attacks to a similar priority as terrorism in the wake of the Colonial Pipeline hack and mounting damage caused by听cybercriminals, a senior department official told Reuters.

Internal guidance sent on Thursday to US attorney鈥檚 offices across the country said information about ransomware investigations in the field should be centrally coordinated with a recently created task force in Washington.

鈥淚t鈥檚 a specialized process to ensure we track all ransomware cases regardless of where it may be referred in this country, so you can make the connections between actors and work your way up to disrupt the whole chain,鈥澨齭aid John Carlin,听principal听associate deputy attorney general at the Justice Department.

Last month, a cybercriminal group that the US authorities said operates from Russia, penetrated the pipeline operator on the US East Coast, locking its systems and demanding a ransom. The hack caused a shutdown lasting several days, led to a spike in gas prices, panic buying and localized fuel shortages in the southeast.

Colonial Pipeline decided to pay the hackers who invaded their systems nearly $5 million to regain access, the company said.

The DOJ guidance specifically refers to Colonial as an example of the听鈥済rowing threat that ransomware and digital extortion pose to the nation.鈥

鈥淭o ensure we can make necessary connections across national and global cases and investigations, and to allow us to develop a comprehensive picture of the national and economic security threats we face, we must enhance and centralize our internal tracking,鈥澨齭aid the guidance seen by Reuters and previously unreported.

The Justice Department鈥檚 decision to push ransomware into this special process illustrates how the issue is being prioritized, US officials said.

鈥淲e鈥檝e used this model around terrorism before but never with ransomware,鈥澨齭aid听Mr.听Carlin. The process has typically been reserved for a short list of topics, including national security cases, legal experts said.

In practice, it means that investigators in US attorney鈥檚 offices handling ransomware attacks will be expected to share both updated case details and active technical information with leaders in Washington.

The guidance also asks the offices to look at and include other investigations focused on the larger cybercrime ecosystem.

According to the guidance, the list of investigations that now require central notification include cases听involving听counter anti-virus services, illicit online forums or marketplaces, cryptocurrency exchanges, bulletproof hosting services, botnets and online money laundering services.

Bulletproof hosting services refer to opaque internet infrastructure registration services which help听cybercriminals to anonymously conduct intrusions.

A botnet is a group of compromised internet-connected devices that can be manipulated to cause digital havoc. Hackers build, buy and rent out botnets in order to conduct听cybercrimes ranging from advertising fraud to large听cyberattacks.

鈥淲e really want to make sure prosecutors and criminal investigators report and are tracking … cryptocurrency exchanges, illicit online forums or marketplaces where people are selling hacking tools, network access credentials听听going after the botnets that serve multiple purposes,鈥澨齭aid听Mr.听Carlin.

Mark Califano, a former US attorney and cybercrime expert, said the听鈥渉eightened reporting could allow DOJ to more effectively deploy resources鈥澨齛nd to听鈥渋dentify common exploits鈥澨齯sed by cybercriminals.听鈥斕Christopher Bing/Reuters