[HN Gopher] LockBit says it's leaked 50GB of stolen Boeing files...
       ___________________________________________________________________
        
       LockBit says it's leaked 50GB of stolen Boeing files after ransom
       fails to land
        
       Author : thunderbong
       Score  : 95 points
       Date   : 2023-11-11 16:18 UTC (6 hours ago)
        
 (HTM) web link (www.theregister.com)
 (TXT) w3m dump (www.theregister.com)
        
       | m-p-3 wrote:
       | Once the data is stolen, you just consider it as leaked. It's
       | just a matter of time before it goes online, ransom or not.
        
         | sacrosanct wrote:
         | > It's just a matter of time before it goes online, ransom or
         | not
         | 
         | Sometimes the groups want a good reputation for not disclosing
         | stuff if the ransom was paid. They earn that reputation over
         | time.
        
           | sillysaurusx wrote:
           | The likelihood that one particular group will ransom more
           | than a handful of times decreases exponentially as LEO
           | becomes more interested.
        
             | xkekjrktllss wrote:
             | What is LEO?
        
               | wepple wrote:
               | Law Enforcement Officers. The O maybe wasn't necessary
               | here
        
               | anonymouskimmer wrote:
               | Low Earth Orbit. It has become sentient as more starlink
               | satellites have gone into orbit. As starlink is used to
               | transfer data LEO has become interested in the uses of
               | the data transfer. Being of Lawful orientation LEO
               | doesn't like ransomware, and may at some point use its
               | computational and communication abilities to redirect any
               | ballistic missiles or rockets which are fired into LEO at
               | the points of origin of the ransomware demands.
               | 
               | j/k, of course.
        
               | ShamelessC wrote:
               | Throw a few [redacted]'s in there and you've got yourself
               | an SCP article.
        
               | runeofdoom wrote:
               | Or it could use the Low Orbit Ion Cannon.
        
           | wnevets wrote:
           | that may have been true 10 years ago but the vast number of
           | criminals in the ransomware game renders having a good
           | reputation meaningless.
        
           | knightofmars wrote:
           | It's still impossible to prove the files were deleted even if
           | they don't release after the initial payment. All it takes is
           | a single individual in a group to make a backup or have a
           | default policy of keeping a backup "just in case".
           | 
           | One should assume at this point that it's not a question of
           | whether the files will be leaked but when.
        
             | euroderf wrote:
             | China sure isn't going to advertise buying a copy.
        
             | cyanydeez wrote:
             | also, governments like china, North Korea , Russia, Iran
             | are basically silent endpoints for this stuff, so assuming
             | it's valuable data, the ransom request should trigger
             | whatever intelligence protocols you have.
        
             | belltaco wrote:
             | The 'when' can be important too, because the sensitivity
             | and value of data generally goes down over time.
        
             | sofixa wrote:
             | > It's still impossible to prove the files were deleted
             | even if they don't release after the initial payment
             | 
             | Often the data isn't exfiltrated at all, only encrypted in
             | place, which should be relatively easy to prove.
        
           | dartos wrote:
           | Even in that case, do you think the ransom group's security
           | is better than their target?
        
             | 8n4vidtmkvmk wrote:
             | If they were the tiniest bit decent, they'd delete the
             | files after the ransom was paid.
        
               | jlarocco wrote:
               | If they were the "tiniest bit decent" they wouldn't be
               | ransoming exfiltrated data.
        
               | erhaetherth wrote:
               | Yes, yes, that's why I said "tiniest".
        
               | Libcat99 wrote:
               | If they were the tiniest bit decent they wouldn't be
               | working in ransom ware.
               | 
               | If they delete the files, it's not out of decency. It's
               | out of a desire to build a reputation of post-ransom
               | trustworthiness so others will pay in the future.
        
               | GolfPopper wrote:
               | Yeah! If they were decent people, they'd be
               | nonconsensually taking individuals' data and profiting
               | off selling _that_ , instead.
        
               | batch12 wrote:
               | Boeing does this?
        
             | hot_gril wrote:
             | They probably have a much smaller attack surface at least.
        
             | axlee wrote:
             | Obviously. The surface for such an enterprise is tiny,
             | while a worldwide multinational with hundred of thousands
             | of employees and contractors can't afford that luxury.
        
           | victorbjorklund wrote:
           | doesnt most of them operate as franchaises these days?
        
           | bastawhiz wrote:
           | If one group got it, there's no reason to assume another
           | group didn't also get to it first and simply sat on the data.
           | There's also no reason to assume the group holding your data
           | ransom is acting as a single reasonable entity: it could be a
           | group of people, each with a copy, who all have different
           | opinions on what to do.
        
         | tracedddd wrote:
         | I know that's what one would expect, but it's not true. Many
         | large ransomware distributors have a solid record of keeping
         | their word and established relationships with the negotiation
         | firms. Trustworthiness and honesty lead to more payouts and
         | they have no interest in your data or doing you harm, just
         | getting paid.
        
           | cft wrote:
           | That can replace PCI compliance then. Sounds like a better
           | option
        
             | mh- wrote:
             | Good point. I bet the ransomware guys don't care how often
             | my laptop's password expires.
        
       | civilitty wrote:
       | In case anyone is curious*, you need the Tor browser to download
       | it from the LockBit onion site [1]. It's a dump from a malware
       | distributor though, so downloader beware.
       | 
       | From the file names it doesn't look like anything particularly
       | interesting though.
       | 
       | * I just want to make my own jet engine
       | 
       | [1]
       | https://old.reddit.com/r/Malware/comments/11gy7h1/list_of_ra...
        
         | infecto wrote:
         | I was excited to see if there were any juicy classified type
         | documents in there.
        
           | capableweb wrote:
           | Judging by what Boeing said (but could just be damage control
           | I guess), it doesn't seem like you're that lucky:
           | 
           | > Elements of Boeing's parts and distribution business
           | recently experienced a cybersecurity incident
           | 
           | Sounds like boring data for the curious mind, unless
           | logistics is your vice.
        
             | civilitty wrote:
             | _Very_ boring. Most of the files are MSSQL database backups
             | according to trid, mostly for random Citrix, Ivanti, and so
             | on services. I 'm still downloading data.zip and
             | boeing.com.7z to see if there's anything juicy there (also
             | unlikely)
             | 
             | That said, I'm learning a lot about digital forensics
        
               | neilv wrote:
               | What are the ethical guidelines here?
               | 
               | Some victim has been violated by a criminal, with the
               | breaking in and stealing and threats, but doesn't
               | _further_ violation happen when others pile onto that?
               | 
               | Also, isn't the threat of releasing the information that
               | the victim will be further violated by others if the
               | information is released, and so those others could
               | arguably be seen as enforcers for the criminal threat?
        
               | mainpassathome wrote:
               | i bet you pay for all your digital media
        
               | neilv wrote:
               | Like most people, I generally try to do the right thing.
               | 
               | My ideas of what's the right thing, and how determined I
               | am about it, change over time.
               | 
               | One reason for change is receiving new information, or
               | realizing a different way of looking at a situation.
        
               | midasuni wrote:
               | I bet you pay rent
        
               | genewitch wrote:
               | I lay 3 for 2 they use airmon-ng and squat.
        
               | civilitty wrote:
               | No idea but the ethics of this are fascinating. At first
               | I was on the side of absolute freedom especially since
               | I'm just satisfying a personal curiosity but this has led
               | me down a rabbit hole of leaks where I'm not so sure. The
               | ethics of using any of this information commercially is
               | murky at best.
               | 
               | A group called ALPHV (who AFAICT was responsible for the
               | MGM resort outage) even makes an API available and
               | indexes their leaks so users can search through them and
               | download individual files. One particular leak for the
               | 3-D Engineering Corporation caught my eye - I can see a
               | bunch of Solidworks parts and assemblies from just a
               | quick glance of the file list. I'm betting there's some
               | ITAR violating files in there which makes me feel icky.
               | Any serious leak from Boeing could contain stuff that's
               | actually relevant to natsec.
               | 
               | That said, we are talking about Boeing here, which was
               | recently responsible for negligently killing hundreds of
               | people. I'm inclined to say "fuck their right to
               | confidentiality."
        
               | neilv wrote:
               | > _That said, we are talking about Boeing here, which was
               | recently responsible for negligently killing hundreds of
               | people. I 'm inclined to say "fuck their right to
               | confidentiality."_
               | 
               | Lose their right to confidentiality wrt public interest
               | independent investigation of the 737 MAX 8 and/or other
               | possible wrongdoing/dysfunction?
               | 
               | Or lose their right to confidentiality just in general,
               | as a kind of mob justice lite?
               | 
               | In both cases, how clearly can we distinguish logical
               | reasonings in pursuit of justice, and convenient
               | rationalization for something we wanted to do anyway?
        
               | lazide wrote:
               | If you're asking if 'Bad people' get the same empathy as
               | anyone else, then of course not. Always been that way.
        
             | idontknowwhynot wrote:
             | It may seem like boring data at first, but that kind of
             | data is gold mine for hackers seeking to learn about Boeing
             | internals and partners to enhance their social engineering
             | attacks (people's name, methods of authentication, software
             | used, password policy etc)
        
               | capableweb wrote:
               | Yes, but the context was information that would be useful
               | for curious minds (that wanna, lets say build their own
               | jet engine). For that purpose, these documents don't seem
               | all that useful.
        
           | fbdab103 wrote:
           | What exciting classified bits were you expecting? Outside of
           | signing keys, I would expect the vast majority of classified
           | documentation is boring technical specs for the N millions of
           | parts required to assemble military gear. Each valuable in
           | their own right, but knowing the exact dimensions and
           | composition of the inanimate carbon rod is not going to move
           | hearts and minds.
           | 
           | Juiciest potential bit is always going to be emails so you
           | can see the human component of what people really think.
        
             | anilakar wrote:
             | A ton of military aircraft flight manuals are unclassified
             | but it does not mean you can freely buy them.
        
               | sundvor wrote:
               | As a DCS player, I appreciate when information is moved
               | into the public domain or whatever it's called when the
               | module makers can freely design a plane that's almost
               | just like the real thing. A few specifics are
               | approximated to gloss over things that remain classified.
               | 
               | (DCS World is a combat flight simulation game, the
               | consumer version.)
        
         | bragr wrote:
         | >I just want to make my own jet engine
         | 
         | Boeing does not manufacture any engine that I'm aware of.
        
           | WJW wrote:
           | Also out of all the problems with making your own jet engine,
           | not having the plans is one of the smaller ones.
        
             | jtriangle wrote:
             | It's cheaper to just buy a used one with its support
             | systems than it is to make one from zero.
             | 
             | Probably won't be airworthy, but, that's a problem for
             | later.
        
       | panick21_ wrote:
       | Amazing. That great counter intellegence work. If China buys it
       | and learn from Boeing space division its gone nuke their whole
       | program.
        
       | anticensor wrote:
       | Any B737 max correspondences and B737 max CAD files inside?
        
       | AYBABTME wrote:
       | It'll be a good day when everyone stops giving in to these ransom
       | seeking parasites. I wonder how hard law enforcement goes looking
       | for them? They're taking society hostage left and right.
        
         | zen928 wrote:
         | I don't agree that companies like boeing failing to secure
         | their own assets properly is taking society hostage, rather
         | than the absolute lax and laid-back approach to digital
         | infrastructure that leads to allowing these weekly emerging
         | "cyber terrorist" groups to take advantage to begin with.
         | 
         | They may be inappropriately handling the contents relative to
         | their scope and potential damage, but that's actually not their
         | prerogative or their concern. It should be a punishable offense
         | beyond "ransom fees" to be in such a position that you can get
         | so easily exfiltrated when entrusted with nationally secure
         | data. Making a big display to the company to pay up a ransom
         | means this has likely already happened silently multiple times
         | to varying degrees without notice, and that anything after the
         | initial public response is just theater. Its unfortunate that I
         | have to feel embarrassed by the security posture of businesses
         | that have absolutely no excuse.
        
         | yieldcrv wrote:
         | Until companies accurately value their distributed bug bounties
         | _and_ have a better track record of paying, then the parallel
         | market of the true market price of security will flourish
         | 
         | The market price of how worth it is this stuff to the company
         | 
         | For now, the flogging continues until morale improves
        
           | artursapek wrote:
           | (profit_from_crime * risk_of_crime) has to <
           | profit_from_whitehat
        
             | yieldcrv wrote:
             | correct, and the blackhat infrastructure is far more
             | sophisticated to distribute liability, corporation like.
             | 
             | the person creating a payload is compensated without doing
             | the unauthorized access
             | 
             | the person doing the unauthorized access is compensated
             | without selling the things they found
             | 
             | the person selling the things they found didn't do the
             | unauthorized access, and is not trying to weaponize the
             | information (lets use an example of identity theft here and
             | below)
             | 
             | the person weaponizing the information is only guilty of
             | using someone else's credentials or making new credit cards
        
       | bragr wrote:
       | 50GB of data from a big company seems like a big nothing burger
       | unless it's like 50GB of specifically executive email or similar.
       | If it's actual product info, 50GB of CAD files is nothing for a
       | big industrial project.
        
         | sschueller wrote:
         | It could contain just a few kbit of documents that would get
         | Boeing into even bigger legal troubles for example regarding
         | the MCAS and the 737 Max.
        
           | rl3 wrote:
           | Wonder if there's ever been hearings on evidence admission in
           | product liability cases where the data source is a ransomware
           | group.
           | 
           | As aside, it's hard to believe this incident in particular
           | didn't get full NSA attention.
           | 
           | https://news.ycombinator.com/item?id=24670701
        
             | lazide wrote:
             | Shouldn't be an issue. Plenty of court precedent that
             | evidence gathered through crimes is admissible as long as
             | it wasn't the cops/gov't committing the crimes.
        
               | jstarfish wrote:
               | Fruit of the poisoned tree normally applies. When does it
               | not?
               | 
               | (The only exception I know of is allowing illegally-
               | obtained evidence in defense against defamation
               | claims...IANAL.)
        
               | neodymiumphish wrote:
               | FOTPT only applies in instances where the cops obtained
               | the content illegally. If some vigilante or bad actor
               | obtains evidence of a crime without coordination or
               | involvement from the government, then the government
               | obtains this illegally-obtained information through legal
               | means, it's still fair game for prosecution.
               | 
               | For example, if I break into your home and steal your
               | safe, which contains evidence of fraud you're committing,
               | then the cops catch me and seize the evidence of my
               | crime, thus observing evidence of your crimes, the
               | evidence they took from my case can be used against you.
               | 
               | In fact, if I'm talking to my cop friend and he tells me
               | about the case against you and that they think there's
               | evidence of your criminal activity in your safe, but they
               | haven't obtained probable cause, I could break in, take
               | the safe, and provide it to my friend and it still be
               | admissible in court. Your defense would have to make a
               | convincing argument that my cop friend asked or
               | coordinated with me to commit the crime of breaking into
               | your house/safe.
        
         | jstarfish wrote:
         | Exfiltration isn't always about _copying_ the tech. 50GB may
         | not be enough to reproduce the object, but it 's enough to
         | sniff out a vulnerability. Boeing happens to be a _defense_
         | contractor...
         | 
         | > files said to be related to [...] supplier details.
         | 
         | Supply chain attacks are the social equivalent of malware
         | persistence. Now you know what parts they need, what vendors
         | they source from, and maybe even for what products, so you've
         | found a number of ways to get back in later.
        
       | bertil wrote:
       | Who would be interested in that data?
       | 
       | I'm seriously asking because a while ago, I had an interview that
       | was explicitly about finding a business model for that type of
       | data (flights, on-time, maintenance, etc.) for a reseller. I
       | think I did a good job, but the company closed before they made
       | an offer. I reached out to a friend who was working for a big
       | airline to ask for his help on that, he was helpful but cagey:
       | that's because that was his job. A bit later, he mentioned that
       | those were notoriously hard to buy because there wasn't really
       | any client -- not a legitimate one.
       | 
       | The only potentially interested parties he could mention were
       | people looking at tourist trends (they get overall hotel and
       | restaurant stats: flights aren't the right breakdown) and
       | possibly taxi companies to get on-time stats (that's actually
       | another project I worked on; small world). But landing data is
       | public, or at least scrapable.
       | 
       | Chinese manufacturers (if you believe the rumors that they like
       | to copy technology) care about R&D. Airbus, maybe, to price them
       | out when competing on bids? But it would seem obvious and not
       | that helpful. I'm not a sales guy.
       | 
       | This is "parts and distribution business" so, essentially, the
       | business branch recently transformed by a lot of machine learning
       | to predict failures. If another maintenance company could train a
       | similar model, they would benefit, but is there such a company?
       | Does anyone do that in both partnership and competition with
       | Boeing?
       | 
       | I'm genuinely curious: Who would want that data?
        
         | notjoemama wrote:
         | > rumors that they like to copy technology
         | 
         | It's not a rumor that China copies tech, they've been caught
         | stealing corporate and military IP.
        
           | hef19898 wrote:
           | Including the complete dataset for the F-35.
        
             | genewitch wrote:
             | At this point we all have a copy of that, I would think.
        
             | 2OEH8eoCRo0 wrote:
             | Source? I assume everyone has the unclass info but I can't
             | find anything about China getting the classified deets.
        
               | lazide wrote:
               | Because no one on either side would want to admit it?
        
               | hef19898 wrote:
               | For example, this story was in the news back the day for
               | a while.
               | 
               | https://www.securitynewspaper.com/2021/08/23/how-chinese-
               | apt...
        
             | echelon wrote:
             | Why aren't these things developed completely air gapped?
        
               | hef19898 wrote:
               | Because you cannot coordinate activities across multiple
               | sites and suppliers if they were.
        
               | Wowfunhappy wrote:
               | How did we do that before the internet?
        
         | bozhark wrote:
         | Cute. It ain't no rumor
        
           | bertil wrote:
           | I was being snarky--and covering my butt, in case the PRC and
           | the PLA suddenly gets very trial-friendly.
        
         | dr_kiszonka wrote:
         | I am curious if it is legal in the US:
         | 
         | 1) to view these data (nothing nefarious, just to see what they
         | look like)?
         | 
         | 2) to use these data for business?
         | 
         | Edit: I have no interest in using such data. I am asking to
         | educate myself about legal ramifications that pertain to such
         | leaks in general.
        
           | bertil wrote:
           | Presumably no privacy issues.
           | 
           | That data is copyrighted, so Boeing could go after you for
           | that, using anti-movie-piracy laws that are quite draconian
           | in the US: copying itself is bad but hard to prove; making it
           | available is definitely worse.
           | 
           | Trade secret tends to extend more broadly, including
           | soliciting, and corporate espionage carries real penalty
           | including conspiracy, so I would avoid it.
           | 
           | Where I'm less clear is if that data would be protected under
           | anti-terrorism laws: now that I've been thinking about it,
           | such documents could help someone plan a terrorist attack by,
           | say, planning a watering hole or supply-chain attack. In that
           | case, the law gets far more open-minded for the prosecution,
           | letting them try anything to prove their case, and the
           | consequences go as far as extra-territorial non-US-
           | jurisdiction legal nightmares. I'd stay away from it, but
           | IANAL.
        
       | ttul wrote:
       | If we want to stop ransomeware, then government should make it
       | illegal to pay ransoms. If CFOs faced jail, then companies hit
       | with attacks would never pay. After a few such failures, gangs
       | would focus on countries that don't prohibit payments.
       | 
       | Convince me I am wrong about this.
        
         | sofixa wrote:
         | Sometimes the government itself might be impacted directly.
         | What happens when a government agency/local government/whatever
         | gets ransowmared, turns out their backups don't exist/work/were
         | locked as well, and the options are to shut down which they
         | can't, legally, or pay up? Or in cases such as the above, when
         | the impacted private entity is a massive government contractor
         | that is too big to fail?
         | 
         | Those are reasons why I think it's unlikely such a legislation
         | would appear, not why it's a bad idea. Liability, personal at
         | that, for lack of cybersecurity should absolutely be introduced
         | globally.
        
       ___________________________________________________________________
       (page generated 2023-11-11 23:01 UTC)