Hackers breached the network at a water utility in Springfield, Ill. and destroyed a pump, according to a post on the Wired Threat Level blog.
Cyber-attackers gained remote access into the control systems used by the city water utility in Springfield, Ill. on Nov. 8, a security expert told Wired. A water district employee noticed the supervisor control and data acquisition (SCADA) systems used in the facility kept turning on and off, causing the attached water pump to burn out, according to the report.
Joe Weiss, a managing partner of Applied Control Solutions, told Wired he learned of the incident from a Nov. 10 report issued by the Illinois Statewide Terrorism and Intelligence Center, a state government agency. The “Public Water District Cyber Intrusion” report did not name the compromised utility or the SCADA system vendor.
Weiss noted that the incident has not been disclosed by the Water Information Sharing and Analysis Center, the Department of Homeland Security’s Daily unclassified report, by the DHS Industrial Control System-Cyber Emergency Response Team or other government and industry security groups.
“None of the water utilities I have spoken to were aware of it,” Weiss said, noting the fact that the lack of notification was as “big a deal” as the attack itself.
The attack originated from IP addresses based in Russia, although with proxies and other routing technologies, that doesn’t necessarily mean the attackers were based out of that country. The intruders first hacked into the network of the vendor that makes the SCADA system used by the utility and stole customer usernames and passwords, Weiss posted on his blog. The stolen credentials were then used to remotely connect to the utility itself to target the equipment within the facility.
The attack is likely to have lasted for at least two to three months before it was discovered, since operators had noticed “glitches” in the system, the state report found. The nature of those glitches remained unclear.
It is also unknown whether other SCADA systems at other water utilities have been attacked, Weiss said.
“My gut tells me that there is greater targeting and wider compromise than we know about,” said David Marcus, director of security research at McAfee. Many of these infrastructure facilities do not have cyber-forensics and response procedures necessary to detect these cyber-intrusions, Marcus said.
DHS is currently investigating the incident and has not seen “credible corroborated data” that indicates there was a risk to critical infrastructure, the agency said in a statement.
The Stuxnet worm last year that damaged centrifuges in Iran’s nuclear facility spotlighted how vulnerable SCADA systems were to remote attack. “It is really no more difficult to attack a SCADA network or system than it is to attack any other system,” Marcus said. It just takes time, specialized knowledge and dedicated resources to develop the attack, much like any other threat vector, he said.
Many of these SCADA systems also don’t need to be connected to the Internet in the first place, Mike Geide, a senior security researcher at Zscaler ThreatLabZ, told eWEEK. To prevent these attacks the users, systems and software should have the least privilege necessary to complete the task and nothing else.
The report comes less than a day after Norway’s National Security Agency (NSM) reported that oil , gas and defense firms were hit by a series of sophisticated cyber-attacks. Industrial secrets and sensitive details about contract negotiations have been stolen, NSM said. At least 10 firms have been targeted in the attack in which user names, passwords, industrial drawings, contracts and documents were stolen and taken out of the country.
“We have to suppose that the actual number (of victims) is much higher, but that many (companies) have not been in contact” with authorities, the Norwegian agency said.
The attackers breached the networks using customized email messages sent to specific individuals in the organizations with malware attachments which managed to slip past anti-malware detection systems, according to NSM. The mail had been carefully crafted to look like legitimate messages and tailored for each individual target. They were sent while the companies were in the middle of negotiations over big contracts.
NSM said one group was likely behind all the attacks but did not provide any additional information.

Dans cet épisode d’eSpeaks, Jennifer Margles, Director of Product Management chez BMC Software, évoque le passage de l’ordonnancement traditionnel des tâches à l’ère de l’entreprise autonome.

Corey Noles, d’eSpeaks, s’entretient avec Rob Israch, président de Tipalti, sur ce que signifie placer la finance pensée pour l’international au cœur de sa stratégie et sur la manière dont les entreprises peuvent mettre en place des opérations évolutives et conformes dans un monde de plus en plus incertain. Ils examinent comment l’automatisation, l’IA et les plateformes intégrées aident les équipes financières à relever les plus grands défis actuels, de la conformité transfrontalière et de la volatilité des taux de change à […]

« Dans cet épisode, “Corey Noles s’entretient avec le Dr Chris Hillman, responsable mondial de l’IA chez Teradata, qui explique que les écosystèmes ouverts de données et de technologies sont essentiels à l’IA d’entreprise, car le domaine évolue trop rapidement pour les approches fermées reposant sur un fournisseur unique. Hillman met en avant l’interopérabilité de Teradata avec AWS, Python-in-SQL, la limitation des transferts de données, les formats de tables ouverts, les feature stores et le déploiement selon le principe « bring your own model » via des formats tels qu’ONNX et PMML, en s’appuyant sur des études de cas pour montrer comment cette approche prend en charge les charges de travail d’IA à grande échelle, améliore la conformité et la connaissance client, et permet à de petites équipes de gérer des systèmes fonctionnant en continu.
-
Actualités récentes - Ressources Centres de ressourcesRessources en vedetteLink to The Real AI Power Play: Who Controls Your Enterprise Data Layer?
The Real AI Power Play: Who Controls Your Enterprise Data Layer?IT and data teams were promised that AI would make work easier. Instead, it's created new layers of complexity.Link to Building the Backbone of Agentic AI with Trusted, Context-Rich Data
Building the Backbone of Agentic AI with Trusted, Context-Rich DataIn this 10-minute take video, Reltio Principal Solutions Consultant Guy Vorster explains how organizations can overcome fragmented data challenges to power AI agents.Link to IHG scales real-time, trusted data across global brands
IHG scales real-time, trusted data across global brandsAccelerating time to value while powering data-driven engagementLink to Jennifer Margules de BMC sur l’orchestration intelligente de l’entreprise
Jennifer Margules de BMC sur l’orchestration intelligente de l’entrepriseDans cet épisode d’eSpeaks, Jennifer Margles, Director of Product Management chez BMC Software, évoque le passage de l’ordonnancement traditionnel des tâches à l’ère de l’entreprise autonome.
Link to La finance pensée pour l’international : bâtir des opérations évolutives et conformes dans un monde incertain
La finance pensée pour l’international : bâtir des opérations évolutives et conformes dans un monde incertainCorey Noles, d’eSpeaks, s’entretient avec Rob Israch, président de Tipalti, sur ce que signifie placer la finance pensée pour l’international au cœur de sa stratégie et sur la manière dont les entreprises peuvent mettre en place des opérations évolutives et conformes dans un monde de plus en plus incertain. Ils examinent comment l’automatisation, l’IA et les plateformes intégrées aident les équipes financières à relever les plus grands défis actuels, de la conformité transfrontalière et de la volatilité des taux de change à […]
Link to eSpeaks : le BYOM avec le Dr Chris Hillman de Teradata
eSpeaks : le BYOM avec le Dr Chris Hillman de Teradata« Dans cet épisode, “Corey Noles s’entretient avec le Dr Chris Hillman, responsable mondial de l’IA chez Teradata, qui explique que les écosystèmes ouverts de données et de technologies sont essentiels à l’IA d’entreprise, car le domaine évolue trop rapidement pour les approches fermées reposant sur un fournisseur unique. Hillman met en avant l’interopérabilité de Teradata avec AWS, Python-in-SQL, la limitation des transferts de données, les formats de tables ouverts, les feature stores et le déploiement selon le principe « bring your own model » via des formats tels qu’ONNX et PMML, en s’appuyant sur des études de cas pour montrer comment cette approche prend en charge les charges de travail d’IA à grande échelle, améliore la conformité et la connaissance client, et permet à de petites équipes de gérer des systèmes fonctionnant en continu.
-
Intelligence artificielle -
Vidéo -
Mégadonnées et analyse -
Cloud -
Réseau - Cybersécurité Cybersécurité
- Applications Applications
- Gestion IT Gestion IT
- Stockage Stockage
- Mobile Mobile
- Petites entreprises Petites entreprises
- Développement Développement
- Base de données Base de données
- Serveurs Serveurs
- Android Android
- Apple Apple
- Innovation Innovation
- Matériel informatique Matériel informatique
- Avis Avis
- Moteurs de recherche Moteurs de recherche
- Virtualisation Virtualisation
-
- Blogs Blogs
- Événements Événements