Showing posts with label OT. Show all posts
Showing posts with label OT. Show all posts

Wednesday, October 9, 2024

American Water Works Cyber Attack

Cyber security on critical infrastructure are really critical but you need to understand it before you get hit by a cyber attack. Understand this before you are left without electricity or water. Take the cyber threats seriously and take countermeasures against cyber threats before it's too late.


American Water Works, a major water utility, was recently targeted by a cyber attack, they announced via a statement. While the company reported that its water and wastewater facilities were not directly affected, the incident underscores the vulnerability of critical infrastructure to cyber threats. A successful cyber attack on a critical infrastructure provider could have severe consequences, including disruptions in essential services and potential public health risks. Investing in robust cybersecurity measures is essential to protect critical infrastructure and ensure the continued delivery of essential services.


https://bit.ly/4eNgl50


"The company’s MyWater account system is currently down, according to a notice on the company website, and all appointments set up by customers will be rescheduled. Additionally, all billing has been paused until further notice as they try to bring systems back online — there will be no late charges or service shut offs while systems are down."


"American Water Works provides drinking water, wastewater and other related services to an estimated 14 million people in 14 states as well as 18 military installations. From its regulated businesses, the company reported a net income of $971 million for 2023."


"American Water Works did not respond to requests for comment about whether they are dealing with a ransomware attack or if a ransom has been issued."


The EPA (U.S. Environmental Protection Agency) said in May (2024) that in recent inspections, over 70% of water systems examined do not fully comply with the Safe Drinking Water Act and some 'have critical cybersecurity vulnerabilities, such as default passwords that have not been updated and single logins that can easily be compromised.'”

Monday, January 15, 2024

Hack of Danish Energy Companies


There are still many people in the companies who are still not aware of the cybersecurity risks and who underestimate the cyber threats. They wake up after they see their company in the hacking news on the internet while considering to pay (or not pay) the ransom which is requested by the hacker groups.

So be aware before you see your company in the hacking news the next day. Be aware that it is not a joke. Be aware that cyber threats are for real. Do not hesitate to spend enough budget for cyber security. Otherwise you will have to spend much more then that for hackers after you have been hit by a ransomware attack.


It is known that Ukrainian critical infrastructures are being attacked for more than 10 years (Allegedly by Russian affiliated hacker groups.) But Ukraine remained not the only victim.


Nearly two dozen Danish energy companies were hacked through a firewall bug in May 2023 which is also stated in a report of Forescout which is published this week. (A Critical Analysis of Recent Energy Sector Attacks in Denmark and Ukraine.)


You can read the report of Forescout in the link below:

https://www.forescout.com/resources/clearing-the-fog-of-war/?is=5a5d7ed30c1b46eb1c21fcf1e6c51b4c49dc532ddd4c930a7f4472ce34fe37c3


https://therecord.media/denmark-attacks-forescout-analysis-zyxel?is=5a5d7ed30c1b46eb1c21fcf1e6c51b4c49dc532ddd4c930a7f4472ce34fe37c3


"What happened in Denmark can also happen to you, cybersecurity researchers are warning in a new report that examines attacks against the country’s energy sector last year."


"The takeaway is that 'critical infrastructure organizations across Europe should remain alert to attacks on unpatched network infrastructure devices.'"


""...Nearly two dozen companies were affected, and the intrusions usually involved the abuse of products from the Taiwan-based manufacturer Zyxel,..."


"...The problem for administrators, Forescout said, is the 'common lack of detection and hardening capabilities around native OT scripting functionality.'"