Department of Homeland Security thinks Anonymous may target SCADA systems at oil and gas companies

Tag: Anonymous, dhs, SCADA

 The Department of Homeland Security (DHS) is warning that hackers from the loose online protest collective called Anonymous have threatened attacks against the computer systems that run factories, power stations, chemical plants, and water and sewage facilities.

 

“While Anonymous recently expressed intent to target [industrial control software], they have not demonstrated a capability to inflict damage to these systems,” reads a leaked bulletin from from the department’sNational Cybersecurity and Communications Integration Center.

DHS did not immediately respond to a request for comment.

Industrial control software (ICS) systems, also known as Supervisory Control And Data Acquisition (SCADA) systems, are considered among the most dangerous targets for hackers because successful attacks could damage or destroy the industrial equipment they control — blowing up power generators, releasing clouds of dangerous chemicals or polluting water supplies.

The bulletin, which is unclassified but restricted “For Official Use Only,” notes that hackers from Anonymous have posted computer code and other material that show an interest in ICS computer programs, and some ability to get access to ICS systems.

It also warns that the group’s hackers “could be able to develop capabilities to gain access and trespass on [ICS] networks very quickly,” although they have not yet carried out any attacks.

The bulletin says oil and gas companies might be at particular risk because of what it calls a “green energy” agenda on the part of Anonymous, highlighting the campaign the group has supported against the trans-continental Keystone XL oil pipeline and the Alberta Tar Sands project in Canada.

“This targeting could likely extend beyond Anonymous to the broader [hacker activist] community, resulting in larger-scope actions against energy companies,” warns the bulletin, issued last month and posted Monday by the website Public Intelligence.

The bulletin notes that tools used by both “white hat” and “black hat” hackers to search for holes in computer security are increasingly able to look at ICS equipment.

Such tools “can be directly used with novice level skills in hacking and little to no background in control systems,” the bulletin states.

“In addition, there are control systems that are currently accessible directly from the internet and easy to locate through internet search engine tools and applications. These systems could be easily located and accessed with minimal skills in order to trespass, carry out nefarious activities, or conduct reconnaissance activities to be used in future operations,” the bulletin warns.

 

 Source: http://www.washingtontimes.com/news/2011/oct/17/hacker-group-threatens-industrial-computer-systems/


Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
CAPTCHA
This is to prevent spammers. Authenticated users can skip the CAPTCHA security measure.
Image CAPTCHA
Enter the characters shown in the image.

Who's new

  • ciberprov
  • michael.nguyen
  • mornjinfeng
  • aniketdaptardar
  • hadriker
  • Alanw

Security vids #1

Team Cymru Research NFP is a specialized Internet security research firm and 501(c)3 non-profit dedicated to making the Internet more secure. Team Cymru helps organizations identify and eradicate problems in their networks, providing insight that improves lives.

Team Cymru the video series 1 to 10
Team Cymru the video series 11 to 20
Team Cymru the video series 21 to 30
Team Cymru the video series 31 to 40
Team Cymru the video series 41 to 50
Team Cymru the video series 51 to 60

CWZ Books

Who's online

There are currently 0 users and 19 guests online.

Security vids #2

The Center for Education and Research in Information Assurance and Security (CERIAS) is currently viewed as one of the world’s leading centers for research and education in areas of information security that are crucial to the protection of critical computing and communication infrastructure.

CERIAS is unique among such national centers in its multidisciplinary approach to the problems, ranging from purely technical issues (e.g., intrusion detection, network security, etc) to ethical, legal, educational, communicational, linguistic, and economic issues, and the subtle interactions and dependencies among them.

CERIAS Security: Attribute-Based Access Control
CERIAS Security: Information Flow Analysis in Security Enhanced Linux
CERIAS Security: Towards Mining Syslog Data
Weapons of Mass Disruption Gallery Launch: Reitinger Remarks
Weapons of Mass Disruption: Mike McConnell on The Nightmare Scenario



#Cyberwar