US authorities are offering $10 million for information on nation-state cyber-attacks
US authorities are offering around $10 million in cryptocurrency for information resulting in the identification of state-sponsored cyber-attackers.
Underneath the scheme, which occurs under the Department of State’s Rewards for Justice (RFJ) program, payouts is going to be awarded for the identity or location of anyone who, “while acting at the direction or under the control of a foreign government, participates in malicious cyber activities against US critical infrastructure in violation of the Computer Fraud and Abuse Act (CFAA).
A media release states that violations include threats made during ransomware attacks, unauthorized use of a protected computer with intention to steal sensitive data, and intentionally causing damage without authorization to a protected computer.
This system has create a reporting channel accessible on the dark web to help protect the safety and security of potential sources.
“Reward payments may include payments in cryptocurrency,” said the Department of State.
Extra information on the best way to access the Tor-based reporting channel is found in the release.
In the pipeline
The offer of a reward comes as the US continues to see cyber-attacks against critical infrastructure which have caused chaos across the nation.
In May this season, a ransomware attack on gas supplier Colonial Pipeline cut off services to multiple states on the east coast.
Attackers leveraging DarkSide malware demanded $4.3 million in bitcoin – a sum that has been reportedly paid out by the company.
Security professionals previously told The Daily Swig that in paying ransoms, organizations risk perpetuating a “feedback loop of malicious activity” that “allows the groups to achieve a greater degree of sophistication throughout their next attacks, whether that be via training, new tooling, purchasing credentials, or world market darknet recruitment.