Tag Archive for: pipeline

Cyberattack shuts down major US gas pipeline


A fuel pipeline right-of-way, like a wide, grassy path, stretches into the distance, through a forest. A yellow sign in the foreground alerts people to the presence of the petroleum pipeline.

Colonial Pipeline’s overall system is the US’ biggest, covering more than 5,500 miles and carrying more than 100 million gallons of fuel a day, the company says.


Colonial Pipeline

A cyberattack has taken down the main pipeline that carries gasoline to the US East Coast, the pipeline’s operator said Friday, further raising concern about how vulnerable critical systems are to hacking assaults.

Colonial Pipeline, which operates pipes that carry refined petroleum products like gas, diesel, jet fuel, home heating oil and fuel for the military, said in a statement that it’s taken “certain systems offline to contain the threat, which has temporarily halted all pipeline operations, and affected some of our IT systems.”

If the disruption doesn’t last beyond a few days, it likely won’t cause many problems, due to local supplies of gas that typically get replenished via the pipeline about once a week, The Wall Street Journal reported, likening the situation to pipeline shutdowns that occur during hurricanes. Still, the shutdown increases alarm about cyberattacks on key systems.

It’s unclear whether criminal hackers or a nation-state is behind the attack, the Journal reported. Colonial said it’s contacted “law enforcement and other federal agencies” and engaged a “leading, third-party cybersecurity firm” to investigate.

The attack involved ransomware, Colonial said in an updated statement Saturday. In such schemes, attackers use code to seize control of a computer system and then demand money to unlock it. The worldwide WannaCry ransomware attacks in 2017, for instance, locked up computer systems at hospitals, banks and phone companies.

But assaults like the one…

Source…

The Colonial Pipeline Hack Is a New Extreme for Ransomware 


For years, the cybersecurity industry has warned that state-sponsored hackers could shut down large swathes of US energy infrastructure in a geopolitically motivated act of cyberwar. But now apparently profit-focused cybercriminal hackers have inflicted a disruption that military and intelligence agency hackers have never dared to, shutting down a pipeline that carries nearly half the fuel consumed on the East Coast of the United States.

On Saturday, the Colonial Pipeline company, which operates a pipeline that carries gasoline, diesel fuel, and natural gas along a 5,500 mile path from Texas to New Jersey, released a statement confirming reports that ransomware hackers had hit its network. In response, Colonial Pipeline says it shut down parts of the pipeline’s operation in an attempt to contain the threat. The incident represents one of the largest disruptions of American critical infrastructure by hackers in history. It also provides yet another demonstration of how severe the global epidemic of ransomware has become.

“This is the largest impact on the energy system in the United States we’ve seen from a cyberattack, full stop,” says Rob Lee, CEO of the critical-infrastructure-focused security firm Dragos. Aside from the financial impact on Colonial Pipeline or the many providers and customers of the fuel it transports, Lee points out that around 40 percent of US electricity in 2020 was produced by burning natural gas, more than any other source. That means, he argues, that the threat of cyberattacks on a pipeline presents a significant threat to the civilian power grid. “You have a real ability to impact the electric system in a broad way by cutting the supply of natural gas. This is a big deal,” he adds. “I think Congress is going to have questions. A provider got hit with ransomware from a criminal act, this wasn’t even a state-sponsored attack, and it impacted the system in this way?”

Colonial Pipeline’s short public statement says that it has “launched an investigation into the nature and scope of this incident, which is ongoing.” Reuters reports that incident responders from security…

Source…

U.S. Government Issues Powerful Cyberattack Warning As Gas Pipeline Forced Into Two Day Shut Down – Forbes

U.S. Government Issues Powerful Cyberattack Warning As Gas Pipeline Forced Into Two Day Shut Down  Forbes
“cyber warfare news” – read more

Protection beyond the pipeline – Engineer Live

Protection beyond the pipeline
Engineer Live
Attacks using malware, such as 2012's Flame, which spread via a local area network or USB memory sticks and recorded audio, screenshots and keyboard activity, could see an organisation lose business-critical data or intellectual property. And malware …

and more »

flame malware – read more