Showing posts with label SCADA. Show all posts
Showing posts with label SCADA. Show all posts

Monday, January 15, 2024

Hack of Danish Energy Companies


There are still many people in the companies who are still not aware of the cybersecurity risks and who underestimate the cyber threats. They wake up after they see their company in the hacking news on the internet while considering to pay (or not pay) the ransom which is requested by the hacker groups.

So be aware before you see your company in the hacking news the next day. Be aware that it is not a joke. Be aware that cyber threats are for real. Do not hesitate to spend enough budget for cyber security. Otherwise you will have to spend much more then that for hackers after you have been hit by a ransomware attack.


It is known that Ukrainian critical infrastructures are being attacked for more than 10 years (Allegedly by Russian affiliated hacker groups.) But Ukraine remained not the only victim.


Nearly two dozen Danish energy companies were hacked through a firewall bug in May 2023 which is also stated in a report of Forescout which is published this week. (A Critical Analysis of Recent Energy Sector Attacks in Denmark and Ukraine.)


You can read the report of Forescout in the link below:

https://www.forescout.com/resources/clearing-the-fog-of-war/?is=5a5d7ed30c1b46eb1c21fcf1e6c51b4c49dc532ddd4c930a7f4472ce34fe37c3


https://therecord.media/denmark-attacks-forescout-analysis-zyxel?is=5a5d7ed30c1b46eb1c21fcf1e6c51b4c49dc532ddd4c930a7f4472ce34fe37c3


"What happened in Denmark can also happen to you, cybersecurity researchers are warning in a new report that examines attacks against the country’s energy sector last year."


"The takeaway is that 'critical infrastructure organizations across Europe should remain alert to attacks on unpatched network infrastructure devices.'"


""...Nearly two dozen companies were affected, and the intrusions usually involved the abuse of products from the Taiwan-based manufacturer Zyxel,..."


"...The problem for administrators, Forescout said, is the 'common lack of detection and hardening capabilities around native OT scripting functionality.'"

Saturday, August 20, 2022

Ransomware Attack on UK Water Company by Cl0p

Another ransomware attack, another critical infrastructure. The victim is from UK this time and it doesn't mean that the next victim won't be in the country you are living in.

A water company in UK was compromised by a ransomware gang.


It seems that ransomware attacks on critical infrastructures will continue increasingly until it is understood that critical infrastructures are really CRITICAL.


https://www.theregister.com/2022/08/18/clop_ransomware_uk_water/


https://www.thameswater.co.uk/network-latest/cyber-hoax

https://www.south-staffs-water.co.uk/news/important-statement

https://threatpost.com/water-supplier-hit-clop-ransomware/180422/


"A water company in the drought-hit UK was recently compromised by a ransomware gang, though initially it was unclear exactly which water company was the victim.


Clop, a prolific Russian-speaking gang known for extorting industrial organizations, claimed on its website that it had broken into and stolen data from Thames Water – which supplies water to about 15 million people, including those in the capital, London.


The cybercriminals said that after negotiations with the water company broke down, they published a raft of stolen documents, from passport scans and driver's licenses to screenshots of software user interfaces. They claimed to have more than 5TB of data taken from the victim organization, as well as access to some SCADA systems.


They also taunted Thames Water, writing they had spent months inside the company's network and that it had 'very bad holes in their systems.'"


"The company admitted that its corporate IT network was disrupted and that it is working with government and regulatory agencies to investigate the intrusion.


Within a couple of days, Clop updated its website, saying it was South Staffordshire that it attacked, and not Thames."


"Chris Vaughan, area vice president of technical account management for EMEA for Tanium, noted the increasing attacks on utilities and other critical infrastructure.


"'This is a trend which, unfortunately, I expect to continue,' Vaughn told The Register in an email. 'It's also a worrying reflection of the rapidly growing ransomware market, with major incidents being reported regularly. These attacks are growing in sophistication, and criminal gangs are becoming more targeted in their approach and increasing the huge sums of money that they are demanding.'


Clop has been an active ransomware group over the past several years. According to a report earlier this year by Trend Micro, the malware evolved from a variant of the CryptoMix ransomware family and was first tagged with the Cl0p name in 2019..."


"A year ago, six suspected members of the gang were arrested in Ukraine. Trend Micro noted reports that only parts of the ransomware group's operations were disrupted, including the server infrastructure used by affiliates and channels needed for laundering cryptocurrency-based ransom payments.


The cybersecurity firm estimated that through November 2021, the Clop group had pulled in $500 million."