Connect with us

Published

on

Ransomware has long been plaguing American municipalities. It appeared to be another typical ransomware attack that impacted the city of Columbus, Ohio, this past July. The city’s response to the hack, however, was not, and it has cybersecurity and legal experts across the country questioning its motives.

Connor Goodwolf (legal name is David Leroy Ross) is an IT consultant who plumbs the dark web as part of his job. “I track dark web-type crimes, criminal organizations, and stuff like what the Telegram CEO has been arrested for,” Goodwolf said.

So when word got out that the city of Columbus, his hometown, had been breached, Goodwolf did what he does: he poked around online. It didn’t take him long to discover what the hackers had in their possession.

“It wasn’t the biggest, but it was one of the most impactful breaches I have seen,” Goodwolf said.

In some ways, he described it as a routine breach, with personal identifiable information, protected health information, Social Security numbers and driver’s license photos exposed. However, because multiple databases were breached, it was more encompassing than other attacks. According to Goodwolf, the hackers had breached multiple databases from the city, the police, and the prosecutor’s office. There were arrest records and sensitive information about minors and domestic violence victims. Some of the breached databases, he says, went back to 1999. 

Goodwolf found over three terabytes of data that took over 8 hours to download.

“The first thing I see is the prosecutor’s database, and I’m like ‘holy sh-t’ these are domestic violence victims. When it comes to domestic violence victims, we need to protect them the most because they have already been victimized once, and now they are again by having their information exposed,” he said.

Goodwolf’s first action was to contact the city to let them know how serious the breach was, because what he saw contradicted official statements. At a press conference on August 13,  Columbus Mayor Andrew Ginther said: “The personal data that the threat actor published to the dark web was either encrypted or corrupted, so the majority of the data came by the threat actor is unusable.”

But what Goodwolf was finding didn’t support that view. “I tried to reach out to the city multiple times to multiple departments and was blown off,” he said.

Google-owned Mandiant, as well as many other top cybersecurity firms, have been tracking a continued increase in ransomware attacks, both in prevalence and severity, and the rise of the Rhysida Group behind the Columbus hack, which has come into prominence within the last year.

The Rhysida Group claimed responsibility for the hack. While not much is known about the cyber gang, Goodwolf and other security experts say they appear to be state-sponsored and based in Eastern Europe, possibly linked to Russia. Goodwolf says these ransomware gangs are “professional operations” with a staff, paid vacation, and PR people.

“They have ramped up the attacks and targets since last autumn,” he said.

The U.S. government’s Cybersecurity and Infrastructure Security Agency issued a bulletin about Rhysida last November.

Goodwolf said that because no one from the city responded to him he went to the local media and shared data with journalists to get the word out about the seriousness of the breach. And that is when he heard from the city of Columbus, in the form of a lawsuit and a temporary restraining order preventing him from disseminating additional information. 

The city defended its response in a statement to CNBC:

“The City initially moved to obtain this order, which was granted by the Court, to prevent the dissemination of sensitive and confidential information, potentially including the identities of undercover police officers, that threatens public safety and criminal investigations.”

The city’s temporary 14-day restraining order against Goodwolf has since expired, and now it has a preliminary injunction and an agreement with Goodwolf not to release more data.

“It should be noted that the Court order does not prohibit the defendant from discussing the data breach or even describing what kind of data was exposed,” the city’s statement added. “It simply prohibits the individual from disseminating the stolen data posted on the dark web. The City remains engaged with federal authorities and cyber security experts to respond to this cyber intrusion.”

Meanwhile, the mayor did have to perform a mea culpa at a subsequent press conference, saying his initial statements were based on the information he had at the time. “It was the best information we had at the time. Clearly, we discovered that that was inaccurate information and I have to accept responsibility for that.”

Realizing the exposure to residents was greater than first thought, the city is offering two years of free credit monitoring from Experian. This includes anyone who has had contact with the city of Columbus via an arrest or other business. Columbus is also working with Legal Aid to see what additional protections are needed for domestic violence victims who may have been compromised or need help with civil protection orders.

To date, the city has not paid the hackers, who were demanding $2 million in ransom.   

‘He’s Not Edward Snowden’

Those who study cybersecurity law and work within the realm expressed surprise at Columbus filing a civil lawsuit against the researcher.

“Lawsuits against data security researchers are rare,” said Raymond Ku, professor of law at Case Western Reserve University. On the rare occasion they do happen, he said, it is usually when the researcher is alleged to have disclosed how a flaw was or can be exploited, which would then allow others to take advantage of the flaw as well.

“He wasn’t Edward Snowden,” said Kyle Hanslovan, CEO of cybersecurity company Huntress, who described himself as troubled by the city of Columbus’s response and what it could mean for future breaches. Snowden was a government contract employee who leaked classified information and faced criminal charges, but considered himself a whistleblower. Goodwolf, Hanslovan says, is a Good Samaritan who independently found the breached data.

“In this case, it appears we have just silenced someone who, as far as I can tell, appears to be a security researcher who did the bare minimum and confirmed the official statements made were not true. This can’t possibly be an appropriate use of the courts,” Hanslovan said, predicting the case will be quickly overturned.

Columbus City Attorney Zach Klein said during a September press conference that the case was “not about freedom of speech or whistleblowing. This is about downloading and disclosure of stolen criminal investigatory records.”

Hanslovan worries about the ripple effect where cybersecurity consultants and researchers are afraid to do their jobs for fear of being sued. “The bigger story here is are we seeing the emergence of a new playbook” for hacking response in which individuals are silenced, and that should not be welcomed, he said. “Silencing any opinion, even for 14 days, could be enough to prevent something credible from coming to light, and that terrifies me,” Hanslovan said. “That voice needs to be heard. As we see bigger cybersecurity incidents come up, I am worried that folks will be more concerned bringing them to light.”

Scott Dylan, founder of United Kingdom-based venture capital firm NexaTech Ventures, also thinks the actions of the city of Columbus could induce a chilling effect on the field of cybersecurity.

“As the field of cyberlaw continues to mature, this case is likely to be referenced in future discussions about the role of researchers in the aftermath of data breaches,” Dylan said.

He says legal frameworks must evolve to keep pace with the sophistication of both cyberattacks and the ethical dilemmas they generate, and the approach taken by Columbus is a mistake.

Meanwhile, the legal process will grind on for Goodwolf. Despite Columbus and Goodwolf reaching an agreement last week on the dissemination of information, the city is still suing him for damages in a civil suit that could reach $25,000 or higher. Goodwolf is representing himself in his talks with the city, though says that he has a lawyer on standby, if needed.

Some residents have filed a class-action lawsuit against the city. Goodwolf says that 55% of the information breached has been sold onto the dark web, while 45% is available for anyone with the skills to access it.

Dylan thinks the city is taking a big risk, even if its actions may be legally defensible, by creating the appearance of an attempt to silence discourse rather than encourage transparency. “It’s a strategy that could backfire, both in terms of public trust and future litigation,” he said.

“I am hoping the city realizes the mistake of filing a civil suit and the implications not just on security,” Goodwolf said, noting that Intel is building a $1 billion facility in a Columbus suburb. In recent years, the city has been positioning itself as a new tech hub in the Midwest, and attacking white hats and cybersecurity researchers, he said, could cause some in the tech sector to rethink it as a location.

Continue Reading

Technology

CNBC Daily Open: The weight of Nvidia’s crown

Published

on

By

CNBC Daily Open: The weight of Nvidia's crown

Jensen Huang is interviewed by media during a reception for the 2025 Queen Elizabeth Prize for Engineering, at St James’ Palace November 5, 2025 in London, England, U.K.

Yui Mok | Getty Images Entertainment | Getty Images

Uneasy lies the head that wears the crown.

Shares of artificial intelligence czar Nvidia fell 2.6% on Tuesday as signs of unrest continued rippling through its kingdom.

Over the month, Nvidia has been contending with concerns over lofty valuations and an argument from the “The Big Short” investor Michael Burry that companies may be overestimating the lifespan of Nvidia’s chips. That accounting choice inflates profits, he alleged.

The pressure intensified last week in the form of a potential challenger to the crown. Google on Nov. 18 announced the release of its new AI model Gemini 3 — so far so good, given that Nvidia isn’t in the business of designing large language models  — powered by its in-house AI chips — uhoh.

And on Monday stateside, Meta, a potential kingmaker, appeared to signal that it is considering not just leasing Google’s custom AI chips, but also using them for its own data centers. It seemed like Nvidia felt the need to address some of those rumblings.

The chipmaker said on the social media platform X that its technology is more powerful and versatile than other types of AI chips, including the so-called ASIC chips, such as Google’s TPUs. Separately, Nvidia issued a private memo to Wall Street that disputed Burry’s allegations.

Power, whether in politics or semiconductors, requires a delicate balance.

Remaining silent may shroud those in power in a cloak of untouchability, projecting confidence in their authority — but also aloofness. Deigning to address unrest can soothe uncertainty, but also, paradoxically, signal insecurity.

For now, the crown is Nvidia’s to wear — and the weight of it is, too.

What you need to know today

The UK Autumn Budget 2025 is here. Britain prepares for a “smorgasbord” of tax hikes to be unveiled Wednesday. Follow CNBC’s coverage of the Budget throughout the day on our live blog here

U.S. stocks advanced on Tuesday. Major indexes had their third straight winning session, erasing earlier intraday losses. Asia-Pacific markets rose Wednesday. Shares of Foxconn climbed more than 3% after the firm received approval for a contract amendment.

Meta is looking to use Google AI chips. That’s according to a Monday report by The Information. Nvidia on Tuesday wrote on X that its chips are “a generation ahead of the industry.” The chipmaker also sent analysts a memo on alleged bubble claims.

Taiwan President pledges $40 billion more for defense. Lai Ching-te, Taiwan’s leader, on Wednesday said the self-governing island will improve its self-defense capabilities in the face of “unprecedented military buildup” by China.

[PRO] What to watch as UK budget is unveiled. Strategists told CNBC they will be monitoring the budget’s effects on interest rates, economic growth and the British pound — and one “rabbit out of the hat” from U.K. Finance Minister Rachel Reeves.

And finally…

Lights on in skyscrapers and commercial buildings on the skyline of the City of London, UK, on Tuesday, Nov. 18, 2025. U.K. business chiefs urged Chancellor of the Exchequer Rachel Reeves to ease energy costs and avoid raising the tax burden on corporate Britain as she prepares this year’s budget.

Bloomberg | Bloomberg | Getty Images

The UK’s Autumn Budget is coming: Here’s what it could mean for your money

The run-up to this year’s U.K. Autumn Budget has been different from the norm because so many different tax proposals have been floated, flagged, leaked and retracted in the weeks and months leading up to Wednesday’s statement.

It has also made it harder to gauge what we’re actually going to get when Finance Minister Rachel Reeves finally unveils her spending and taxation plans for the year ahead.

— Holly Ellyatt

Continue Reading

Technology

Uber rolls out driverless robotaxis in Abu Dhabi

Published

on

By

Uber rolls out driverless robotaxis in Abu Dhabi

Driverless WeRide robotaxis for Uber.

Courtesy: Uber

Uber on Wednesday rolled out fully driverless rides in its fourth market, launching the service in Abu Dhabi in partnership WeRide, a Chinese autonomous vehicle company.

The ride-hailing company said the launch in the United Arab Emirates capital represents the first driverless robotaxi service in the Middle East. In the U.S., Uber already offers robotaxi services in Austin, Phoenix and Atlanta through Alphabet’s Waymo.

Riders in Abu Dhabi can book a WeRide robotaxi when requesting an UberX or Uber Comfort ride, the ride-hailing company said.

WeRide, which is listed on the Nasdaq, formed its partnership with Uber in September 2024 and began offering autonomous rides with an operator on board in Abu Dhabi last December. Uber and WeRide also debuted robotaxi rides with a safety operator on board in Riyadh, Saudia Arabia, in October. In May, Uber said it plans to roll out the WeRide service to 15 more cities, including in Europe, over the next five years.

In recent years, Uber has bet big on autonomous vehicle technology through partnerships.

Uber started offering a robotaxi service in Austin and Atlanta earlier this year, and in Phoenix in late 2023. In July, the company landed a six-year robotaxi deal with electric vehicle maker Lucid and AV startup Nuro.

WeRide, meanwhile, has launched full driverless robotaxi services in China’s Beijing and Guangzhou, according to its website.

Uber has not said how it splits revenue from robotaxi rides with its partners.

Competitors have also readily adopted the technology, with Lyft announcing a deal with Waymo in September to launch robotaxis in Nashville next year.

Uber said the driverless vehicles in Abu Dhabi will operate in certain areas of Yas Island. Riders can boost their chance of a robotaxi drive by selecting the autonomous option. On-board support is available during the ride through the app and an in-vehicle tablet.

WATCH: WeRide CEO: We are using both Tesla and Waymo’s approach to scale robotaxi operations

WeRide CEO: We are using Tesla and Waymo's approach to scale robotaxi operations

Continue Reading

Technology

Amazon faces FAA probe after delivery drone snaps internet cable in Texas

Published

on

By

Amazon faces FAA probe after delivery drone snaps internet cable in Texas

Amazon’s new MK30 Prime Air drone is displayed during Amazon’s “Delivering the Future” event at the company’s BFI1 Fulfillment Center, Robotics Research and Development Hub in Sumner, Washington on Oct. 18, 2023.

Jason Redmond | AFP | Getty Images

Amazon is facing a federal probe after one of its delivery drones downed an internet cable in central Texas last week.

The probe comes as Amazon vies to expand drone deliveries to more pockets of the U.S., more than a decade after it first conceived the aerial distribution program, and faces stiffer competition from Walmart, which has also begun drone deliveries.

The incident occurred on Nov. 18 around 12:45 p.m. Central in Waco, Texas. After dropping off a package, one of Amazon’s MK30 drones was ascending out of a customer’s yard when one of its six propellers got tangled in a nearby internet cable, according to a video of the incident viewed and verified by CNBC.

The video shows the Amazon drone shearing the wire line. The drone’s motor then appeared to shut off and the aircraft landed itself, with its propellers windmilling slightly on the way down, the video shows. The drone appeared to remain in tact beyond some damage to one of its propellers.

The Federal Aviation Administration is investigating the incident, a spokesperson confirmed. The National Transportation Safety Board said the agency is aware of the incident but has not opened a probe into the matter.

Amazon confirmed the incident to CNBC, saying that after clipping the internet cable, the drone performed a “safe contingent landing,” referring to the process that allows its drones to land safely in unexpected conditions.

“There were no injuries or widespread internet service outages. We’ve paid for the cable line’s repair for the customer and have apologized for the inconvenience this caused them,” an Amazon spokesperson told CNBC, noting that the drone had completed its package delivery.

Amazon delivery drone snaps internet cable in Texas

The incident comes after federal investigators last month opened a separate probe into a crash involving two of Amazon’s Prime Air drones in Arizona. The two aircrafts collided with a construction crane in Tolleson, a city west of Phoenix, prompting Amazon to temporarily halt drone deliveries in the area.

For over a decade, Amazon has been working to realize founder Jeff Bezos’ vision of drones whizzing toothpaste, books and other goods to customers’ doorsteps in 30 minutes or less. The company began drone deliveries in 2022 in College Station, Texas, and Lockeford, California.

But progress has been slowed by a mix of regulatory hurdles, missed deadlines and layoffs in 2023 that coincided with broader cost-cutting efforts by Amazon CEO Andy Jassy.

The company has previously said its goal is to deliver 500 million packages by drone per year by the end of the decade.

The hexacopter-shaped MK30, the latest generation of Amazon’s Prime Air drone, is meant to be quieter, smaller and lighter than previous versions.

Amazon says the drones are equipped with a sense-and-avoid system that enables them to “detect and stay away from obstacles in the air and on the ground.” The company recommends that customers maintain “about 10 feet of open space” on their property so drones can complete deliveries

The company began drone deliveries in Waco earlier this month for customers within a certain radius of its same-day delivery site who order eligible items weighing 5 pounds or less. The drone deliveries are supposed to drop packages off in under an hour.

Amazon has brought other locations online in recent months, including Kansas City, Missouri, Pontiac, Michigan, San Antonio, Texas, and Ruskin, Florida. Amazon has also announced plans to expand drone deliveries to Richardson, Texas.

Walmart began offering drone deliveries in 2021, and currently partners with Alphabet’s Wing and venture-backed startup Zipline to make drone deliveries in a number of states, including in Texas.

WATCH: Amazon unveils satellite terminal for enterprise customers — but Starlink still dominates

Amazon unveils satellite terminal for enterprise customers — but Starlink still dominates

Continue Reading

Trending