Ukraine and its neighbours, explained

Advertisement

Home › World › Ransomware payment and pipeline waiver, May 2021

World

Ransomware payment and pipeline waiver, May 2021

Summary

A retrospective on two US stories with Russian links that emerged in the days around 22 May 2021.

What did the days around 22 May 2021 reveal about the United States and Russia? Two reports, published on 19 and 21 May, pointed in different directions.

On 19 May, the Biden administration lifted sanctions on the Nord Stream 2 pipeline project between Russia and Germany. The US State Department said it had concluded that waiving the sanctions served the US national interest, even though Joe Biden personally opposed the project.

On 21 May, CNA Financial, the seventh-largest commercial insurer in the United States, disclosed that it had been hit by a ransomware attack in March 2021. The company paid $40 million to a group named Phoenix two weeks after company data was stolen and its officials were locked out of their network.

The Evil Corp. link

The attackers used malware called Phoenix Locker, a variant of ransomware dubbed Hades. Cybersecurity experts said Hades was created by a Russian cybercrime syndicate known as Evil Corp.

In December 2019, the Treasury Department had announced sanctions on 17 individuals and six entities linked to Evil Corp. That designation made it illegal for a US company to knowingly pay a ransom to Evil Corp.

Taken together, the reports showed Washington easing sanctions on one Russia-related project while an earlier set of sanctions bore on a large ransom payment by a US insurer.

Related analysis