DHS says ransomware hit US gas pipeline operator
#1
Quote:A ransomware attack has impacted the operations of a US-based natural gas compression facility, according to a security advisory from the US government.
The advisory, published today, doesn't say when the incident took place, but merely summarizes the event and provides technical guidance for other critical infrastructure operators so they can take precautions against a similar attack.
HOW THE ATTACK UNFOLDEDAccording to the advisory, published by the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (DHS CISA), the incident took place after "a cyber threat actor used a spearphishing link to obtain initial access to the organization's information technology (IT) network before pivoting to its operational (OT) network."
An OT network is different from an IT network. It's a network with workstations for managing critical factory equipment and other factory operations. IT networks are usually dedicated for office and other administrative work. In theory, IT and OT networks should be air-gapped.
CISA says that after gaining access to the OT network, the attacker then deployed commodity ransomware that encrypted the company's data on both the IT and OT networks at the same time, for maximum damage, before requesting a ransom payment.
CISA says the ransomware did not impact any programmable logic controllers (PLCs), which are small sensors and devices that interact directly with factory equipment.
However, CISA says that data from other related industrial processes, like human-machine interfaces (HMIs), data historians, and polling servers, could not be aggregated and read by human operators, resulting in a partial loss of insight into the pipeline facility's operations by is own staff.
PIPELINE OPERATOR SHUT DOWN OPERATIONS FOR TWO DAYS CISA says that the pipeline operator decided to implement "a deliberate and controlled shutdown to operations," as a precaution and to avoid any incidents.
The pipeline operator took this step even if its emergency plan did not mandate an obligatory shutdown in the a case of a cyber-attack.
CISA officials said the shutdown lasted approximately two days, after which normal operations resumed.
Blow are CISA's findings and conclusions from its recent investigation into the event:
  • At no time did the threat actor obtain the ability to control or manipulate operations. The victim took offline the HMIs that read and control operations at the facility. A separate and geographically distinct central control office was able to maintain visibility but was not instrumented for control of operations.
  • The victim's existing emergency response plan focused on threats to physical safety and not cyber incidents. Although the plan called for a full emergency declaration and immediate shutdown, the victim judged the operational impact of the incident as less severe than those anticipated by the plan and decided to implement limited emergency response measures. These included a four-hour transition from operational to shutdown mode combined with increased physical security.
  • Although the direct operational impact of the cyberattack was limited to one control facility, geographically distinct compression facilities also had to halt operations because of pipeline transmission dependencies. This resulted in an operational shutdown of the entire pipeline asset lasting approximately two days.
  • Although they considered a range of physical emergency scenarios, the victim's emergency response plan did not specifically consider the risk posed by cyberattacks. Consequently, emergency response exercises also failed to provide employees with decision-making experience in dealing with cyberattacks.
  • The victim cited gaps in cybersecurity knowledge and the wide range of possible scenarios as reasons for failing to adequately incorporate cybersecurity into emergency response planning.

Source
[-] The following 1 user says Thank You to ttyx for this post:
  • harlan4096
Reply


Messages In This Thread
DHS says ransomware hit US gas pipeline operator - by ttyx - 19 February 20, 02:10

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.4.5  Fixed a p...Kool — 07:41
AxCrypt 3.0.0.85
AxCrypt 3.0.0.85: ...harlan4096 — 06:52
Sumatra PDF 3.6.1
Changes in 3.6.1: ...harlan4096 — 06:50
Microsoft Edge 146.0.3856.109
Version 146.0.3856...harlan4096 — 06:49
Ventoy 1.1.11
Ventoy 1.1.11 2...harlan4096 — 06:48

[-]
Birthdays
Today's Birthdays
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>