Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Foreign hackers targeted U.S. water plant in apparent malicious cyber attack, expert says
The Washington Post ^ | 11/18/2011 | Ellen Nakashima

Posted on 11/18/2011 2:40:07 PM PST by Just4Him

Foreign hackers broke into a water plant control system in Illinois last week and damaged a water pump in what appears to be the first reported case of a malicious cyber attack damaging a critical computer system in the United States, according to an industry expert.

On Nov. 8, a municipal water district employee in Illinois noticed problems with the city’s water pump control system, and a technician determined the system had been remotely hacked into from a computer located in Russia, said Joe Weiss, an industry security expert who obtained a copy of an Illinois state fusion center report describing the incident.

“This is a big deal,” said Weiss. The report stated it is unknown how many other systems might be affected.

The Department of Homeland Security confirmed that a water plant in Springfield, Ill. had been damaged, but spokesman Peter Boogaard said officials had not yet determined that the water pump failure was caused by a cyber-attack. “DHS and the FBI are gathering facts surrounding the report of a water pump failure in Springfield, Illinois. At this time there is no credible corroborated data that indicates a risk to critical infrastructure entities or a threat to public safety,” he said

(Excerpt) Read more at washingtonpost.com ...


TOPICS: Miscellaneous; News/Current Events; US: Illinois
KEYWORDS: comedyoferrors; cyberattack; dhs; fbi; hackers; homelandsecurity; illinois; infrastructure; notcyberattack; nothackers; russia; scada; uscert; water; waterplant; waterpump

1 posted on 11/18/2011 2:40:10 PM PST by Just4Him
[ Post Reply | Private Reply | View Replies]

To: Just4Him

Must’ve been Tea Party people....you know what a threat they are.


2 posted on 11/18/2011 2:47:21 PM PST by Dallas59 (President Robert Gibbs 2009-2011)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Just4Him

Most plants (Power, water, utility etc.)are vulnerable to this attack. The Stuxnet virus variations attacks the control systems.


3 posted on 11/18/2011 2:47:28 PM PST by Drango (A liberal's compassion is limited only by the size of someone else's wallet.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Just4Him

I don’t get why process control systems like this have to be connected to the internet. If so, they only should be in a viewing mode.

Do we have to allow someone to position the main steam stop valve in a power plant from their house? We never used to.

If we tie this infrastructure to the internet; sabotage is inevitable; and sooner than anyone thinks. How many times have we heard that 128 bit keys are uncrackable, then someone cracks them in less than a week? The solution is to keep these systems off the net.

The expectation of ignorance is not a susbstitution for security.


4 posted on 11/18/2011 2:52:20 PM PST by cicero2k
[ Post Reply | Private Reply | To 1 | View Replies]

To: cicero2k

Yup


5 posted on 11/18/2011 2:55:15 PM PST by Just4Him (The truth shall set you free. John 8:32)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Just4Him

Jon Corzine is from that area of Illinois. Not that I’m suggesting anything about finding the $700 million that went missing.


6 posted on 11/18/2011 2:56:43 PM PST by Zuben Elgenubi
[ Post Reply | Private Reply | To 1 | View Replies]

To: Kartographer

Ping.


7 posted on 11/18/2011 3:39:17 PM PST by DuncanWaring (The Lord uses the good ones; the bad ones use the Lord.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Drango
Most plants (Power, water, utility etc.)are vulnerable to this attack.

Why in the world do we put these things on the Internet?

8 posted on 11/18/2011 3:41:27 PM PST by Cementjungle
[ Post Reply | Private Reply | To 3 | View Replies]

To: Just4Him

Sounds like someone’s managed to reverse engineer the stuxnet malware.


9 posted on 11/18/2011 3:42:00 PM PST by Oceander (TINSTAAFL - Mother Nature Abhors a Free Lunch almost as much as She Abhors a Vacuum)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Just4Him

And so it begins...


10 posted on 11/18/2011 3:52:26 PM PST by Dubh_Ghlase (Therefore, send not to know For whom the bell tolls, It tolls for thee.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: cicero2k; Cementjungle
I completely agree!
11 posted on 11/18/2011 4:16:54 PM PST by Cold Heart
[ Post Reply | Private Reply | To 4 | View Replies]

Freepers!

Where is the GREEN!

Come on! Day 49 of the Freepathon and only 43 days until the start of the next. What will you do and where will you post if it goes?

All contributions are for the Current Quarter Expenses.
Click here or mail checks to:

Free Republic, LLC - PO Box 9771 - Fresno, CA 93794



12 posted on 11/18/2011 4:23:36 PM PST by RedMDer (Forward With Confidence!)
[ Post Reply | Private Reply | View Replies]

To: All

http://www.pcmag.com/article2/0,2817,2396835,00.asp

“DHS, FBI Find ‘No Evidence’ of Public Water Utility Hack”
By Chloe Albanesius
November 23, 2011 02:14pm EST

SNIPPET: “The Department of Homeland Security and the FBI on Wednesday shot down reports that a cyber attack recently took down a pump at an Illinois public water utility.

“After detailed analysis, DHS and the FBI have found no evidence of a cyber intrusion into the SCADA system of the Curran-Gardner Public Water District in Springfield, Illinois,” a DHS spokesman said in a statement.”

#

Quote:

twitter.com/#!/danchodanchev/status/138683733573238785

@danchodanchev
Dancho Danchev
Posted on @ZDNet - SCADA systems at the Water utilities in Illinois, Houston, hacked - is.gd/ClsdCe #security #SCADA

21 Nov via HootSuite

#

Quote:

twitter.com/#!/danchodanchev/status/138676067232776192

@danchodanchev
Dancho Danchev
Cracker using the handle pr0f has posted details on the hacked SCADA systems at the Water utilities in Illinois,Houston is.gd/luGPOI

21 Nov via HootSuite

#

pastebin.com/Wx90LLum

#

http://www.pcmag.com/article2/0,2817,2396632,00.asp

“Illinois Water Utility Pump Destroyed After Hack”
By Chloe Albanesius
November 18, 2011 05:28pm EST

SNIPPET: “Joe Weiss, managing partner at Applied Control Systems LLC, said in a Thursday blog post that cyber scammers hacked a Supervisory Control And Data Acquisition (SCADA) software vendor and stole customer usernames and passwords. During the hack, however, the SCADA system was powered on and off, burning out a water pump, he said.

Department of Homeland Security spokesman Peter Boogaard said officials were investigating the incident.”


13 posted on 11/25/2011 6:02:11 PM PST by Cindy
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

http://www.washingtonpost.com/world/national-security/water-pump-failure-in-illinois-wasnt-cyberattack-after-all/2011/11/25/gIQACgTewN_story.html

“Water-pump failure in Illinois wasn’t cyberattack after all”

By Ellen Nakashima, Friday, November 25, 1:53 PM

SNIPPET: “A water-pump failure in Illinois that appeared to be the first foreign cyberattack on a public utility in the United States was in fact caused by a plant contractor traveling in Russia, according to a source familiar with a federal investigation of the incident.

Investigators analyzed log files and connections to foreign Internet protocol addresses within the utility’s computer system, said the source, who was not authorized to speak for attribution. “No indictors of malicious activity were found” in the computer system of the Curran-Gardner Townships Public Water District in Springfield, the source said.”


14 posted on 11/25/2011 8:13:34 PM PST by Cindy
[ Post Reply | Private Reply | To 13 | View Replies]

To: All

Just url & title:

http://www.washingtonpost.com/world/national-security/water-pump-failure-in-illinois-wasnt-cyberattack-after-all/2011/11/25/gIQACgTewN_story.html

“Water-pump failure in Illinois wasn’t cyberattack after all”

By Ellen Nakashima, Friday, November 25, 1:53 PM


15 posted on 11/25/2011 8:14:42 PM PST by Cindy
[ Post Reply | Private Reply | To 14 | View Replies]

To: All

us-cert.gov/control_systems/pdf/ICSB-11-327-01.pdf

US-CERT.gov - INDUSTRIAL CONTROL SYSTEMS CYBER EMERGENCY RESPONSE TEAM - Report - ICSB-11-327-01: “ILLINOIS WATER PUMP FAILURE REPORT” (November 23, 2011)


16 posted on 11/25/2011 11:41:21 PM PST by Cindy
[ Post Reply | Private Reply | To 15 | View Replies]

To: All

More updates:

http://www.wired.com/threatlevel/2011/11/water-pump-hack-mystery-solved/

“Exclusive: Comedy of Errors Led to False ‘Water-Pump Hack’ Report”
By Kim Zetter
November 30, 2011 | 5:54 pm

#

Previously...

http://www.information-age.com/channels/security-and-continuity/news/1676243/hackers-accessed-city-infrastructure-via-scada-fbi.thtml

“Hackers accessed city infrastructure via SCADA – FBI”
by Hal Hodson
29 NOVEMBER 2011

#

Quote:

twitter.com/#!/HSPI/status/142278717723512832

@HSPI
GW Homeland Security

Comedy of errors led to false ‘Water-Pump Hack’ report bit.ly/roN3Gg

16 hours ago via Twitter for BlackBerry

#

Previously...

Quote:

twitter.com/#!/HSPI/status/141986003987599360

@HSPI
GW Homeland Security

FBI: Hackers accessed city infrastructure via SCADA bit.ly/syP4lS

30 Nov via TweetMeme


17 posted on 12/02/2011 1:09:44 AM PST by Cindy
[ Post Reply | Private Reply | To 16 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson