US authorities are offering $10 million for info on nation-state cyber-attacks
US authorities are offering up to $10 million in cryptocurrency for information ultimately causing the identification of state-sponsored cyber-attackers.
Under the scheme, which happens under the Department of State’s Rewards for world market darknet (http://grassrootsinpower.com/) Justice (RFJ) program, payouts will soon be awarded for the identity or location of anybody who, “while acting at the direction or underneath the control of a foreign government, participates in malicious cyber activities against US critical infrastructure in violation of the Computer Fraud and Abuse Act (CFAA).
A press release states that violations include threats made during ransomware attacks, unauthorized usage of a protected computer with intention to steal sensitive data, and intentionally causing damage without authorization to a protected computer.
The program has create a reporting channel accessible on the dark web to help protect the safety and security of potential sources.
“Reward payments may include payments in cryptocurrency,” said the Department of State.
Extra information on how to access the Tor-based reporting channel can be found in the release.
In the pipeline
The offer of a reward comes whilst the US continues to have cyber-attacks against critical infrastructure which have caused chaos across the nation.
In May this season, a ransomware attack on gas supplier Colonial Pipeline cut off services to multiple states on the east coast.
Attackers leveraging DarkSide malware demanded $4.3 million in bitcoin – a sum that has been reportedly paid out by the company.
Security professionals previously told The Daily Swig that in paying ransoms, organizations risk perpetuating a “feedback loop of malicious activity” that “allows the groups to reach a better amount of sophistication throughout their next attacks, whether that be via training, new tooling, purchasing credentials, or recruitment.