[HN Gopher] LockBit says it's leaked 50GB of stolen Boeing files...
___________________________________________________________________
LockBit says it's leaked 50GB of stolen Boeing files after ransom
fails to land
Author : thunderbong
Score : 95 points
Date : 2023-11-11 16:18 UTC (6 hours ago)
(HTM) web link (www.theregister.com)
(TXT) w3m dump (www.theregister.com)
| m-p-3 wrote:
| Once the data is stolen, you just consider it as leaked. It's
| just a matter of time before it goes online, ransom or not.
| sacrosanct wrote:
| > It's just a matter of time before it goes online, ransom or
| not
|
| Sometimes the groups want a good reputation for not disclosing
| stuff if the ransom was paid. They earn that reputation over
| time.
| sillysaurusx wrote:
| The likelihood that one particular group will ransom more
| than a handful of times decreases exponentially as LEO
| becomes more interested.
| xkekjrktllss wrote:
| What is LEO?
| wepple wrote:
| Law Enforcement Officers. The O maybe wasn't necessary
| here
| anonymouskimmer wrote:
| Low Earth Orbit. It has become sentient as more starlink
| satellites have gone into orbit. As starlink is used to
| transfer data LEO has become interested in the uses of
| the data transfer. Being of Lawful orientation LEO
| doesn't like ransomware, and may at some point use its
| computational and communication abilities to redirect any
| ballistic missiles or rockets which are fired into LEO at
| the points of origin of the ransomware demands.
|
| j/k, of course.
| ShamelessC wrote:
| Throw a few [redacted]'s in there and you've got yourself
| an SCP article.
| runeofdoom wrote:
| Or it could use the Low Orbit Ion Cannon.
| wnevets wrote:
| that may have been true 10 years ago but the vast number of
| criminals in the ransomware game renders having a good
| reputation meaningless.
| knightofmars wrote:
| It's still impossible to prove the files were deleted even if
| they don't release after the initial payment. All it takes is
| a single individual in a group to make a backup or have a
| default policy of keeping a backup "just in case".
|
| One should assume at this point that it's not a question of
| whether the files will be leaked but when.
| euroderf wrote:
| China sure isn't going to advertise buying a copy.
| cyanydeez wrote:
| also, governments like china, North Korea , Russia, Iran
| are basically silent endpoints for this stuff, so assuming
| it's valuable data, the ransom request should trigger
| whatever intelligence protocols you have.
| belltaco wrote:
| The 'when' can be important too, because the sensitivity
| and value of data generally goes down over time.
| sofixa wrote:
| > It's still impossible to prove the files were deleted
| even if they don't release after the initial payment
|
| Often the data isn't exfiltrated at all, only encrypted in
| place, which should be relatively easy to prove.
| dartos wrote:
| Even in that case, do you think the ransom group's security
| is better than their target?
| 8n4vidtmkvmk wrote:
| If they were the tiniest bit decent, they'd delete the
| files after the ransom was paid.
| jlarocco wrote:
| If they were the "tiniest bit decent" they wouldn't be
| ransoming exfiltrated data.
| erhaetherth wrote:
| Yes, yes, that's why I said "tiniest".
| Libcat99 wrote:
| If they were the tiniest bit decent they wouldn't be
| working in ransom ware.
|
| If they delete the files, it's not out of decency. It's
| out of a desire to build a reputation of post-ransom
| trustworthiness so others will pay in the future.
| GolfPopper wrote:
| Yeah! If they were decent people, they'd be
| nonconsensually taking individuals' data and profiting
| off selling _that_ , instead.
| batch12 wrote:
| Boeing does this?
| hot_gril wrote:
| They probably have a much smaller attack surface at least.
| axlee wrote:
| Obviously. The surface for such an enterprise is tiny,
| while a worldwide multinational with hundred of thousands
| of employees and contractors can't afford that luxury.
| victorbjorklund wrote:
| doesnt most of them operate as franchaises these days?
| bastawhiz wrote:
| If one group got it, there's no reason to assume another
| group didn't also get to it first and simply sat on the data.
| There's also no reason to assume the group holding your data
| ransom is acting as a single reasonable entity: it could be a
| group of people, each with a copy, who all have different
| opinions on what to do.
| tracedddd wrote:
| I know that's what one would expect, but it's not true. Many
| large ransomware distributors have a solid record of keeping
| their word and established relationships with the negotiation
| firms. Trustworthiness and honesty lead to more payouts and
| they have no interest in your data or doing you harm, just
| getting paid.
| cft wrote:
| That can replace PCI compliance then. Sounds like a better
| option
| mh- wrote:
| Good point. I bet the ransomware guys don't care how often
| my laptop's password expires.
| civilitty wrote:
| In case anyone is curious*, you need the Tor browser to download
| it from the LockBit onion site [1]. It's a dump from a malware
| distributor though, so downloader beware.
|
| From the file names it doesn't look like anything particularly
| interesting though.
|
| * I just want to make my own jet engine
|
| [1]
| https://old.reddit.com/r/Malware/comments/11gy7h1/list_of_ra...
| infecto wrote:
| I was excited to see if there were any juicy classified type
| documents in there.
| capableweb wrote:
| Judging by what Boeing said (but could just be damage control
| I guess), it doesn't seem like you're that lucky:
|
| > Elements of Boeing's parts and distribution business
| recently experienced a cybersecurity incident
|
| Sounds like boring data for the curious mind, unless
| logistics is your vice.
| civilitty wrote:
| _Very_ boring. Most of the files are MSSQL database backups
| according to trid, mostly for random Citrix, Ivanti, and so
| on services. I 'm still downloading data.zip and
| boeing.com.7z to see if there's anything juicy there (also
| unlikely)
|
| That said, I'm learning a lot about digital forensics
| neilv wrote:
| What are the ethical guidelines here?
|
| Some victim has been violated by a criminal, with the
| breaking in and stealing and threats, but doesn't
| _further_ violation happen when others pile onto that?
|
| Also, isn't the threat of releasing the information that
| the victim will be further violated by others if the
| information is released, and so those others could
| arguably be seen as enforcers for the criminal threat?
| mainpassathome wrote:
| i bet you pay for all your digital media
| neilv wrote:
| Like most people, I generally try to do the right thing.
|
| My ideas of what's the right thing, and how determined I
| am about it, change over time.
|
| One reason for change is receiving new information, or
| realizing a different way of looking at a situation.
| midasuni wrote:
| I bet you pay rent
| genewitch wrote:
| I lay 3 for 2 they use airmon-ng and squat.
| civilitty wrote:
| No idea but the ethics of this are fascinating. At first
| I was on the side of absolute freedom especially since
| I'm just satisfying a personal curiosity but this has led
| me down a rabbit hole of leaks where I'm not so sure. The
| ethics of using any of this information commercially is
| murky at best.
|
| A group called ALPHV (who AFAICT was responsible for the
| MGM resort outage) even makes an API available and
| indexes their leaks so users can search through them and
| download individual files. One particular leak for the
| 3-D Engineering Corporation caught my eye - I can see a
| bunch of Solidworks parts and assemblies from just a
| quick glance of the file list. I'm betting there's some
| ITAR violating files in there which makes me feel icky.
| Any serious leak from Boeing could contain stuff that's
| actually relevant to natsec.
|
| That said, we are talking about Boeing here, which was
| recently responsible for negligently killing hundreds of
| people. I'm inclined to say "fuck their right to
| confidentiality."
| neilv wrote:
| > _That said, we are talking about Boeing here, which was
| recently responsible for negligently killing hundreds of
| people. I 'm inclined to say "fuck their right to
| confidentiality."_
|
| Lose their right to confidentiality wrt public interest
| independent investigation of the 737 MAX 8 and/or other
| possible wrongdoing/dysfunction?
|
| Or lose their right to confidentiality just in general,
| as a kind of mob justice lite?
|
| In both cases, how clearly can we distinguish logical
| reasonings in pursuit of justice, and convenient
| rationalization for something we wanted to do anyway?
| lazide wrote:
| If you're asking if 'Bad people' get the same empathy as
| anyone else, then of course not. Always been that way.
| idontknowwhynot wrote:
| It may seem like boring data at first, but that kind of
| data is gold mine for hackers seeking to learn about Boeing
| internals and partners to enhance their social engineering
| attacks (people's name, methods of authentication, software
| used, password policy etc)
| capableweb wrote:
| Yes, but the context was information that would be useful
| for curious minds (that wanna, lets say build their own
| jet engine). For that purpose, these documents don't seem
| all that useful.
| fbdab103 wrote:
| What exciting classified bits were you expecting? Outside of
| signing keys, I would expect the vast majority of classified
| documentation is boring technical specs for the N millions of
| parts required to assemble military gear. Each valuable in
| their own right, but knowing the exact dimensions and
| composition of the inanimate carbon rod is not going to move
| hearts and minds.
|
| Juiciest potential bit is always going to be emails so you
| can see the human component of what people really think.
| anilakar wrote:
| A ton of military aircraft flight manuals are unclassified
| but it does not mean you can freely buy them.
| sundvor wrote:
| As a DCS player, I appreciate when information is moved
| into the public domain or whatever it's called when the
| module makers can freely design a plane that's almost
| just like the real thing. A few specifics are
| approximated to gloss over things that remain classified.
|
| (DCS World is a combat flight simulation game, the
| consumer version.)
| bragr wrote:
| >I just want to make my own jet engine
|
| Boeing does not manufacture any engine that I'm aware of.
| WJW wrote:
| Also out of all the problems with making your own jet engine,
| not having the plans is one of the smaller ones.
| jtriangle wrote:
| It's cheaper to just buy a used one with its support
| systems than it is to make one from zero.
|
| Probably won't be airworthy, but, that's a problem for
| later.
| panick21_ wrote:
| Amazing. That great counter intellegence work. If China buys it
| and learn from Boeing space division its gone nuke their whole
| program.
| anticensor wrote:
| Any B737 max correspondences and B737 max CAD files inside?
| AYBABTME wrote:
| It'll be a good day when everyone stops giving in to these ransom
| seeking parasites. I wonder how hard law enforcement goes looking
| for them? They're taking society hostage left and right.
| zen928 wrote:
| I don't agree that companies like boeing failing to secure
| their own assets properly is taking society hostage, rather
| than the absolute lax and laid-back approach to digital
| infrastructure that leads to allowing these weekly emerging
| "cyber terrorist" groups to take advantage to begin with.
|
| They may be inappropriately handling the contents relative to
| their scope and potential damage, but that's actually not their
| prerogative or their concern. It should be a punishable offense
| beyond "ransom fees" to be in such a position that you can get
| so easily exfiltrated when entrusted with nationally secure
| data. Making a big display to the company to pay up a ransom
| means this has likely already happened silently multiple times
| to varying degrees without notice, and that anything after the
| initial public response is just theater. Its unfortunate that I
| have to feel embarrassed by the security posture of businesses
| that have absolutely no excuse.
| yieldcrv wrote:
| Until companies accurately value their distributed bug bounties
| _and_ have a better track record of paying, then the parallel
| market of the true market price of security will flourish
|
| The market price of how worth it is this stuff to the company
|
| For now, the flogging continues until morale improves
| artursapek wrote:
| (profit_from_crime * risk_of_crime) has to <
| profit_from_whitehat
| yieldcrv wrote:
| correct, and the blackhat infrastructure is far more
| sophisticated to distribute liability, corporation like.
|
| the person creating a payload is compensated without doing
| the unauthorized access
|
| the person doing the unauthorized access is compensated
| without selling the things they found
|
| the person selling the things they found didn't do the
| unauthorized access, and is not trying to weaponize the
| information (lets use an example of identity theft here and
| below)
|
| the person weaponizing the information is only guilty of
| using someone else's credentials or making new credit cards
| bragr wrote:
| 50GB of data from a big company seems like a big nothing burger
| unless it's like 50GB of specifically executive email or similar.
| If it's actual product info, 50GB of CAD files is nothing for a
| big industrial project.
| sschueller wrote:
| It could contain just a few kbit of documents that would get
| Boeing into even bigger legal troubles for example regarding
| the MCAS and the 737 Max.
| rl3 wrote:
| Wonder if there's ever been hearings on evidence admission in
| product liability cases where the data source is a ransomware
| group.
|
| As aside, it's hard to believe this incident in particular
| didn't get full NSA attention.
|
| https://news.ycombinator.com/item?id=24670701
| lazide wrote:
| Shouldn't be an issue. Plenty of court precedent that
| evidence gathered through crimes is admissible as long as
| it wasn't the cops/gov't committing the crimes.
| jstarfish wrote:
| Fruit of the poisoned tree normally applies. When does it
| not?
|
| (The only exception I know of is allowing illegally-
| obtained evidence in defense against defamation
| claims...IANAL.)
| neodymiumphish wrote:
| FOTPT only applies in instances where the cops obtained
| the content illegally. If some vigilante or bad actor
| obtains evidence of a crime without coordination or
| involvement from the government, then the government
| obtains this illegally-obtained information through legal
| means, it's still fair game for prosecution.
|
| For example, if I break into your home and steal your
| safe, which contains evidence of fraud you're committing,
| then the cops catch me and seize the evidence of my
| crime, thus observing evidence of your crimes, the
| evidence they took from my case can be used against you.
|
| In fact, if I'm talking to my cop friend and he tells me
| about the case against you and that they think there's
| evidence of your criminal activity in your safe, but they
| haven't obtained probable cause, I could break in, take
| the safe, and provide it to my friend and it still be
| admissible in court. Your defense would have to make a
| convincing argument that my cop friend asked or
| coordinated with me to commit the crime of breaking into
| your house/safe.
| jstarfish wrote:
| Exfiltration isn't always about _copying_ the tech. 50GB may
| not be enough to reproduce the object, but it 's enough to
| sniff out a vulnerability. Boeing happens to be a _defense_
| contractor...
|
| > files said to be related to [...] supplier details.
|
| Supply chain attacks are the social equivalent of malware
| persistence. Now you know what parts they need, what vendors
| they source from, and maybe even for what products, so you've
| found a number of ways to get back in later.
| bertil wrote:
| Who would be interested in that data?
|
| I'm seriously asking because a while ago, I had an interview that
| was explicitly about finding a business model for that type of
| data (flights, on-time, maintenance, etc.) for a reseller. I
| think I did a good job, but the company closed before they made
| an offer. I reached out to a friend who was working for a big
| airline to ask for his help on that, he was helpful but cagey:
| that's because that was his job. A bit later, he mentioned that
| those were notoriously hard to buy because there wasn't really
| any client -- not a legitimate one.
|
| The only potentially interested parties he could mention were
| people looking at tourist trends (they get overall hotel and
| restaurant stats: flights aren't the right breakdown) and
| possibly taxi companies to get on-time stats (that's actually
| another project I worked on; small world). But landing data is
| public, or at least scrapable.
|
| Chinese manufacturers (if you believe the rumors that they like
| to copy technology) care about R&D. Airbus, maybe, to price them
| out when competing on bids? But it would seem obvious and not
| that helpful. I'm not a sales guy.
|
| This is "parts and distribution business" so, essentially, the
| business branch recently transformed by a lot of machine learning
| to predict failures. If another maintenance company could train a
| similar model, they would benefit, but is there such a company?
| Does anyone do that in both partnership and competition with
| Boeing?
|
| I'm genuinely curious: Who would want that data?
| notjoemama wrote:
| > rumors that they like to copy technology
|
| It's not a rumor that China copies tech, they've been caught
| stealing corporate and military IP.
| hef19898 wrote:
| Including the complete dataset for the F-35.
| genewitch wrote:
| At this point we all have a copy of that, I would think.
| 2OEH8eoCRo0 wrote:
| Source? I assume everyone has the unclass info but I can't
| find anything about China getting the classified deets.
| lazide wrote:
| Because no one on either side would want to admit it?
| hef19898 wrote:
| For example, this story was in the news back the day for
| a while.
|
| https://www.securitynewspaper.com/2021/08/23/how-chinese-
| apt...
| echelon wrote:
| Why aren't these things developed completely air gapped?
| hef19898 wrote:
| Because you cannot coordinate activities across multiple
| sites and suppliers if they were.
| Wowfunhappy wrote:
| How did we do that before the internet?
| bozhark wrote:
| Cute. It ain't no rumor
| bertil wrote:
| I was being snarky--and covering my butt, in case the PRC and
| the PLA suddenly gets very trial-friendly.
| dr_kiszonka wrote:
| I am curious if it is legal in the US:
|
| 1) to view these data (nothing nefarious, just to see what they
| look like)?
|
| 2) to use these data for business?
|
| Edit: I have no interest in using such data. I am asking to
| educate myself about legal ramifications that pertain to such
| leaks in general.
| bertil wrote:
| Presumably no privacy issues.
|
| That data is copyrighted, so Boeing could go after you for
| that, using anti-movie-piracy laws that are quite draconian
| in the US: copying itself is bad but hard to prove; making it
| available is definitely worse.
|
| Trade secret tends to extend more broadly, including
| soliciting, and corporate espionage carries real penalty
| including conspiracy, so I would avoid it.
|
| Where I'm less clear is if that data would be protected under
| anti-terrorism laws: now that I've been thinking about it,
| such documents could help someone plan a terrorist attack by,
| say, planning a watering hole or supply-chain attack. In that
| case, the law gets far more open-minded for the prosecution,
| letting them try anything to prove their case, and the
| consequences go as far as extra-territorial non-US-
| jurisdiction legal nightmares. I'd stay away from it, but
| IANAL.
| ttul wrote:
| If we want to stop ransomeware, then government should make it
| illegal to pay ransoms. If CFOs faced jail, then companies hit
| with attacks would never pay. After a few such failures, gangs
| would focus on countries that don't prohibit payments.
|
| Convince me I am wrong about this.
| sofixa wrote:
| Sometimes the government itself might be impacted directly.
| What happens when a government agency/local government/whatever
| gets ransowmared, turns out their backups don't exist/work/were
| locked as well, and the options are to shut down which they
| can't, legally, or pay up? Or in cases such as the above, when
| the impacted private entity is a massive government contractor
| that is too big to fail?
|
| Those are reasons why I think it's unlikely such a legislation
| would appear, not why it's a bad idea. Liability, personal at
| that, for lack of cybersecurity should absolutely be introduced
| globally.
___________________________________________________________________
(page generated 2023-11-11 23:01 UTC)