Water-pump failure in Illinois wasn’t cyberattack after all
washingtonpost.com
washingtonpost.com
Well at least they managed to create a lot of publicity in the international press about how their systems are on the internet and use three letter passwords which may or may not be the default three letter password set at the factory. That information should be helpful to someone I guess.
(not to say that they shouldn't have used a better password, but please, please media stop shouting "cyberwar!!!" at each possible instance)
Remember, The Hacker Crackdown [1] is from 1992, and the news then was still not that the media freaked out about this sort of thing, but the huge arrest wave it represented.
As plausible as that is, it doesn't sound like that's quite what happened here (emphasis mine):
"Federal officials confirmed that the FBI and the Department of Homeland Security were investigating damage to the water plant but cautioned against concluding that it was necessarily a cyber-attack before all the facts could be learned. “At this time there is no credible corroborated data that indicates a risk to critical infrastructure entities or a threat to public safety,” said DHS spokesman Peter Boogaard."
"News of the incident became public after Joe Weiss, an industry security expert, obtained a report dated Nov. 10 and collected by an Illinois state intelligence center that monitors security threats. The original source of the information was unknown and impossible to immediately verify."[1]
The article (and seemingly all of the others) go on to cite Weiss as the sole source for the claim that it was a hack and "a big deal". From his blog post[2] and more recent posts it sounds like the report he had obtained claimed it was a hack and he publicized it "to highlight a concern that information is not being disseminated in a timely manner", which I suppose is the opposite of full on red alert.
I think Weiss was probably trying to make a good point (if you believe the DHS, then not only wasn't information getting disseminated, it was also wrong information) but the press ran with the sexier "We're getting hacked by Russia!" aspect even without verification.
[1] http://www.washingtonpost.com/blogs/checkpoint-washington/po...
[2] http://community.controlglobal.com/content/water-system-hack...
The media ran with the attack angle.
http://nakedsecurity.sophos.com/2011/11/22/interview-with-sc...
"Last week I wrote a story on the compromise of an industrial control system in Illinois that destroyed a pump at a water processing facility. The same day a hacker came forward and posted internal information on pastebin.com from another compromised utility in South Houston, Texas."
"Within hours of publication I was contacted by the hacker involved in the Texas incident and I was able to ask him a few questions via email about the state of critical infrastructure security."
It's probable that you're under a constant low-level attack -- bots and script kiddies at the very least. If your infrastructure's interesting enough, there may even be targeted attacks. Your own ops / eng team is probably your biggest threat (just plain shit happening, though intentional damage does happen). Parts breaking, or various buckets overflowing generally don't help matters much. Since you're talking about a system with usually at a minimum hundreds of discrete subsystems, let alone the number of physical components, interconnects, and external dependencies, it's difficult to monitor it all let alone have a solid sense of what's going on. Your best bet is some overall metric of system/site health.
I worked for ... a large Internet presence where an apparently unauthorized access to an admin tool (unknown username) and resetting of system parameters was traced (with the help of the internal security team) ... to our own office. The dipshit doing this sat two chairs over but hadn't piped up during several days' worth of "WTF is going on / who's accessing this system as 'username'".
Don't ask me how my Thanksgiving went.
Seriously, this pretty much sounds like a test run to see if the media will still take the bait without asking questions.