Showing posts with label critical infrastructure. Show all posts
Showing posts with label critical infrastructure. Show all posts

Saturday, January 4, 2025

Sabotage of an Electricity Cable Between Finland and Estonia

Although we are mostly using wireless connections today, we are still highly reliant on physical environments in order to communicate with each other.


What I am trying to point out is that most of our heavy internet traffic travels over fiber cables buried under the ground and under the seas or oceans. It is not only about the IP network, it is about the availability of electricity. If there is no electricity, then there is also no internet. (Layer 1 availability is much more important than most people are aware of.)


An electricity cable between Finland and Estonia was sabotaged last week (25 Dec 2024), causing the operator of Finland's national grid (Estlink 2) to remain out of service. (The alleged perpetrators are members of the shadow fleet of Russia.)


The damaged cable had a transmission capacity of 650 megawatts and is 170km long (105 miles). Repairs are expected to take "several months." (Yes, critical infrastructure security is a major concern.)


Finnish police are investigating whether a Russian ship was involved in the sabotage.


https://bbc.in/4fHcFSh


"The authorities said on Thursday that they believe the anchor of the Eagle S, a tanker registered with the Cook Islands, may have damaged the Estlink 2 cable, which became disconnected on Wednesday (25 Dec 2024).

The vessel is thought to be part of Russia's 'shadow fleet', which is made up of ships that carry embargoed Russian oil products.

It is the latest in a series of incidents in recent years, in which underwater cables in the Baltic region have been either damaged or severed completely."


"The EU has threatened to impose further sanctions against Russia as a result of the incident and said it was 'strengthening efforts to protect undersea cables'.

'We strongly condemn any deliberate destruction of Europe's critical infrastructure,' the European Commission and the EU's foreign policy chief, Kaja Kallas, said in a joint statement."


"A telecommunications cable running between Finland and Germany was severed in November (2024), and an internet link between Lithuania and Sweden's Gotland Island stopped working at around the same time."

Wednesday, February 21, 2024

Ransomware Attack Forced 100 Romanian Hospitals to Go Offline

 

Hospitals are still being victims of ransomware attacks.


On the night of February 11-12, 2024, a ransomware attack impacted 25 hospitals in Romania, disrupting their online health services. As a precaution, another 75 hospitals took their systems offline, bringing the total affected hospitals to 100.


Fortunately, the hospitals had working backups and were able to restore their systems and data to a state from 3 days before this attack.


Hospitals are classified as critical infrastructure, yet they remain more vulnerable among other crititical infrastructures.


Managers in the critical infrastructure sectors DO have to be aware of that cyber threats are real and that cyber attacks can cause serious damage to the environment and also to the society.


DO NOT think that cybersecurity is a waste of time or waste of budget or just an unnecessary paperwork. Do not wait for a cyber attack to realize it.



https://bit.ly/3V5q9AT


"100 hospitals across Romania have taken their systems offline after a ransomware attack hit their healthcare management system."


"'During the night of 11-12 February 2024, a massive ransomware cyber-attack targeted the production servers running the HIS information system. As a result of the attack, the system is down, files and databases are encrypted,' the Romanian Ministry of Health said."


"'Most of the affected hospitals have backups of data on the affected servers, with data saved relatively recently (1-2-3 days ago) except one, whose data was saved 12 days ago,' DNSC said.


The attackers have sent a ransom demand of 3.5 BTC (roughly €157,000)..."


"Since the systems were taken offline or shut down, doctors have been forced to return to writing prescriptions and keeping records on paper."

Tuesday, September 6, 2022

London's Biggest Bus Operator Hit By Cyber Attack

 

It is a public transportation company from London this time. London's biggest bus operator suffered a cyber attack.


https://bit.ly/3KYH6pu


"Travellers in London are braced for more delays after the city’s largest bus operator revealed it has been hit by a 'cybersecurity incident,' according to reports.


Newcastle-based transportation group Go-Ahead shared a statement with the London Stock Exchange indicating 'unauthorized activity' had been discovered on its network yesterday."


"'Go-Ahead will continue to assess the potential impact of the incident but confirms that there is no impact on UK or International rail services which are operating normally.'


However, the same may not be true of its bus services. Sky News reported that bus and driver rosters may have been impacted by the attack, which could disrupt operations."


"It is London’s largest bus company, operating over 2400 buses in the capital and employing more than 7000 staff."

Tuesday, August 23, 2022

Greek Natural Gas Operator Suffers Data Breach

Another critical infrastructure, another cyber attack. This time Greece.

Greece's largest natural gas distributor is attacked on August 20th, 2022.


It was a limited attack but some files and data was allegedly possibly leaked. And the company rejected to pay any ransom payment. (Brave behaviour.)


Yes. It was Greece this time but it can be another EU country next time. Winter is coming. So more attention is needed.


Critical infrastructures are really critical.


https://www.bleepingcomputer.com/news/security/greek-natural-gas-operator-suffers-ransomware-related-data-breach/


"Greece's largest natural gas distributor DESFA confirmed on Saturday that they suffered a limited scope data breach and IT system outage following a cyberattack.


In a public statement shared with local news outlets on Saturday, DESFA explained that hackers attempted to infiltrate its network but were thwarted by the quick response of its IT team.


However, some files and data were accessed and possibly 'leaked,' so there was a network intrusion, even if limited."


"Finally, DESFA declares an unwavering stance against communicating with cyber criminals, so there will be no negotiation of a ransom payment."


"The confirmation of the attack comes after data was leaked on Friday by the Ragnar Locker ransomware operation, a threat actor that began operations over two years ago and has had numerous high-profile attacks in 2021.


Ragnar Locker remains active in 2022, even if its volumes have dropped compared to the past. A recent FBI report linked Ragnar Locker to 52 network intrusions in critical U.S. infrastructure entities as of January 2022."


"This attack comes at a tough time for gas suppliers in Europe, as all countries in the continent decided to abruptly cut their dependence on Russian natural gas, which inevitably created problems."

Saturday, August 20, 2022

Ransomware Attack on UK Water Company by Cl0p

Another ransomware attack, another critical infrastructure. The victim is from UK this time and it doesn't mean that the next victim won't be in the country you are living in.

A water company in UK was compromised by a ransomware gang.


It seems that ransomware attacks on critical infrastructures will continue increasingly until it is understood that critical infrastructures are really CRITICAL.


https://www.theregister.com/2022/08/18/clop_ransomware_uk_water/


https://www.thameswater.co.uk/network-latest/cyber-hoax

https://www.south-staffs-water.co.uk/news/important-statement

https://threatpost.com/water-supplier-hit-clop-ransomware/180422/


"A water company in the drought-hit UK was recently compromised by a ransomware gang, though initially it was unclear exactly which water company was the victim.


Clop, a prolific Russian-speaking gang known for extorting industrial organizations, claimed on its website that it had broken into and stolen data from Thames Water – which supplies water to about 15 million people, including those in the capital, London.


The cybercriminals said that after negotiations with the water company broke down, they published a raft of stolen documents, from passport scans and driver's licenses to screenshots of software user interfaces. They claimed to have more than 5TB of data taken from the victim organization, as well as access to some SCADA systems.


They also taunted Thames Water, writing they had spent months inside the company's network and that it had 'very bad holes in their systems.'"


"The company admitted that its corporate IT network was disrupted and that it is working with government and regulatory agencies to investigate the intrusion.


Within a couple of days, Clop updated its website, saying it was South Staffordshire that it attacked, and not Thames."


"Chris Vaughan, area vice president of technical account management for EMEA for Tanium, noted the increasing attacks on utilities and other critical infrastructure.


"'This is a trend which, unfortunately, I expect to continue,' Vaughn told The Register in an email. 'It's also a worrying reflection of the rapidly growing ransomware market, with major incidents being reported regularly. These attacks are growing in sophistication, and criminal gangs are becoming more targeted in their approach and increasing the huge sums of money that they are demanding.'


Clop has been an active ransomware group over the past several years. According to a report earlier this year by Trend Micro, the malware evolved from a variant of the CryptoMix ransomware family and was first tagged with the Cl0p name in 2019..."


"A year ago, six suspected members of the gang were arrested in Ukraine. Trend Micro noted reports that only parts of the ransomware group's operations were disrupted, including the server infrastructure used by affiliates and channels needed for laundering cryptocurrency-based ransom payments.


The cybersecurity firm estimated that through November 2021, the Clop group had pulled in $500 million."