Sunday, March 3, 2024

Refrigerator Used to Hack Chlorine Plant

The Federal Bureau of Inquire announced today the arrest of William Cruikshank in connection with last month’s attack on the ChlorAlk plant in Le Sel, LA. That attack resulted in a chlorine release at the facility that injured twelve employees and caused overnight evacuation of the nearby Depatman Doubs Neighborhood. Cruikshank is being charged with twelve counts of attempted murder, unauthorized access to a sensitive computer system, and wiretapping.

Johnathan Quest, FBI spokesperson, confirmed that Cruikshank was arrested when he tried to recover a Bluetooth device that he had placed at the home of an unnamed control system engineer that worked at ChlorAlk. “We were keeping an eye on the device,” Quest said; “It was a specially modified cell phone, that Cruikshank had apparently used before, so we were pretty sure that he wanted it back.”

The Director of the National Critical Infrastructure Security Operations Center (CI-SOC), General Buck Turgidson, briefed reporters on the latest information about the ChlorAlk hack. “This was a sophisticated attack on the control systems at the facility,” Turgidson explained; “but there were no specific control system vulnerabilities exploited. We quickly determined that the attack was made via the engineering laptop used by one of the facility’s control system engineers.”

Special Agent R. (Ace) Bannon told reporters at the FBI press conference that the Bureau had initially looked at that engineer as a potential suspect, but quickly changed the focus of their investigation when Students for Immediate Neutralization of Chlorine Technology and Energy Reversion (SFINCTER) announced responsibility for the attack. “We have a lengthy ongoing investigation on this group, and a close examination of the laptop showed signs of it being hacked by Cruikshank,” Bannon explained.

A technician working at CI-SOC who was part of the investigation told me that it was surprising that Cruikshank was able to penetrate the well protected laptop. “Then we learned that the engineer was using the tools on the laptop to do some work at home on his smart refrigerator, she said; “That refrigerator had an old Bluetooth application that had a number of vulnerabilities that Cruikshank was able to exploit to get access to the laptop.”

Sueur Hargreaves-Bird, spokesperson for ChlorAlk that the engineer, only identified as ‘Chris’, had been hired after the hack of the facility’s chlorine sensors two years ago. “We specifically hired Chris because of his hacking background and put him to work looking for vulnerabilities in our systems,” Seuer said; “He has coordinated vulnerability disclosures with all of our vendors. Many were not happy with Chris’ efforts, but if they wanted to keep being suppliers for us and others in the industry, they knew that they had to fix the vulnerabilities that Chris found.”

Bannon confirmed that Cruikshank had targeted Chris. “Chris had a very active blog where he discussed each of the vulnerabilities that he had uncovered, and there were numerous hints that he worked in the chlor-alkali industry. He was an obvious target for someone like Cruikshank.”

Sunday, February 25, 2024

Ransomware Class Action Suit

The City of Los Angeles filed a class action lawsuit against Hodes Automation for damages related to the recent ransomware attack against the City’s traffic light control system. Harry R. Haldeman announced the lawsuit this morning along with district attorneys from 25 other Southern California cities. “Not only was Hodes negligent in the design of their system, but they published a list of their customers on their web site,” Haldeman told reporters; “That list provided the hackers easy targets for publicly available exploits.”

Dean Hodes, owner of Hodes Automation, had no comment, referring reporters to his lawyer, Eunice Rivers. Rivers’ office issued a statement this morning; “We are looking at the details of the filing by the District Attorney and cannot comment on the facts of the case at this time, but Mr. Haldeman is clearly overreaching in trying to collect expenses the city incurred in their recovery from an incident from my client.” Rivers noted that Hodes had published an updated version of their software two weeks before the vulnerability was announced by Robert Lightman, the researcher who discovered the vulnerability.

Lightman published his report two months ago on the security bypass vulnerability in the TL Control program used by Los Angels and thirty other municipalities in Southern California. “I discovered the vulnerability while doing some work for the city of Montecito,” Lightman told reporters; “And I worked closely with Hodes to help them correct the problem.” Lightman explained that he had a disclosure agreement with Hodes that allowed him to publish his research two weeks after Hodes made their update available on their web site.

The City of Los Angeles installed the TL Control system two years ago after the hack of the Robotron system that the City had been using was discovered. Doug Wilson, the Los Angeles City Manager told reporters this morning that the city had decided to work with a local vendor after having problems working with Robotron. “We felt that a local vendor would be more responsive to our needs,” Wilson said.

When asked when the city became aware of the vulnerability in the TL Control product, Wilson told reporters that he was not able to comment on ongoing litigation. “All questions about the lawsuit should be referred to Haldeman’s office,” Wilson said.

A technician working with the Traffic Department who was not authorized to talk to the press told me that the city never received notification about the vulnerability from Hodes. “We read about the vulnerability in a newspaper article about the ransomware attack,” she said.

The Hodes web site announced the availability of a new version of the TL Control product on December 2nd. There was no mention of security vulnerability on the web site. The TL Control web page was taken down early this afternoon, after the lawsuit was announced.

The lawsuit is seeking $15 million in damages.

The City Traffic department announced a request for bids on a new traffic light control system. The bid request includes new requirements for cybersecurity notifications, including notifying the Department when vulnerabilities are reported to the vendor and reporting when the vendor has mitigation measures available for reported vulnerabilities.

CAUTIONARY NOTE: This is a future news story - 

Sunday, February 18, 2024

Robotron Drones Phone Home to China

This morning the Security and Applied Science (SAS) Directorate and the Federal Bureau of Inquiry announced this morning that they had shut down an automated espionage operation being conducted by the PRK’s UGG (Uilyo Gong-Gyeog) advanced persistent threat group. Their latest activity utilized hacked Robotron drones to collect photographic and electronic information about critical infrastructure. “The UGG effectively turned the fleet of Robotron BF 109 drones into a data collection bot,” Nelson E. R. Donally, SAS spokesperson told reporters.

An analyst with the SAS who is not authorized to speak to the press noted that: “While we were focusing on removing Chinese made drones from US airspace, the UGG was targeting the largest non-Chinese uncrewed aircraft manufacturer, Robotron Aero, to turn their aircraft into Chinese data collection tools.”

Johnathan Quest, FBI spokesperson, told reporters: “We have arrest warrants for three members of the UGG leadership, but we do not expect that Chinese authorities will cooperate in their apprehension and extradition. We do, however, have a programmer in custody who worked on the Robotron project for UGG. He was arrested on a federal warrant in Singapore and has been extradited.”

Donally told reporters that SAS became aware of the use of Robotron drones when Barkhorn Aviation of Dothan, AL approached the agency with communications logs from one of their BF 109’s. They noted a large block of data being transmitted to an unknown phone number after operations near Fort Novosel. We were able to track those communications through a number of links to a small server farm two blocks away from the Chinese mission in Atlanta. “We were able to seize those servers and use that access to track information back to an additional 150 BF 109 drones in use across the United States,” Donally explained.

A technician with Dragonfire Cyber who was not authorized to speak with reporters told me that the UGG chip was a communications control chip. The Robotron Aero design allows the drone to communicate via FM radio, cell phone and Bluetooth and encrypts all communications. UGG added additional communications monitoring capabilities and a separate encryption method for selected data.

The SAS Technical Division was able to isolate a single chip found in the BF 109 control system that allowed UGG to establish a physical backdoor in that control system. That chip was made in Taiwan by a manufacturer that was controlled by UGG. Quest told reporters that law enforcement personnel in Taiwan were helping the FBI in their investigation. “They seized customer records from that company,” Quest said; “We are currently tracking down locations where similar chips are in use in this country.”

Robotron Aero issued a statement that reported: “We are working in partnership with SAS and the FBI to try to determine how the electronic systems on our aircraft were compromised. We will have a team available to customers to remove the offending chip once the FBI or other regional law enforcement agencies have completed their forensic examination of each aircraft. The BF 109 fleet is currently grounded pending completion of those efforts.”

CAUTIONARY NOTE: This is a future news story –

Sunday, February 11, 2024

Security Researcher Exonerated

Delano, GA lawyer, Junior Butts announced this morning that the Department of Justice had dropped all charges against his client, David Lightman, for the ransomware attack on Bliechen Chemicals last December. Butts told reporters: “My client is a diligent white-hat hacker who found a vulnerability in the Robotron SK-1a safety system and reported that defect to the manufacturer. It was hardly his fault that Robotron was unable to control access to their site.”

Lightman has been in federal custody in Atlanta since January 2nd. He was released this morning. Lightman was arrested on December 31st and all of his research computers and equipment were seized on that day. Lightman referred all questions from the press today to his lawyer.

Della Street, spokesperson for the DOJ confirmed that Barlow was no longer a suspect in the case. “Mr. Lightman’s story checked out in all particulars after we were able to convince his lawyer to provide us access to the unencrypted contents of his research computer,” Ms. Street said this morning; “We are now on the trail of the team that hacked the Robotron web site that allowed them to intercept David’s vulnerability disclosure.”

The Federal Bureau of Inquiry is reportedly on the trail of AssaB, a notorious environmental hacker, thought to be working with Students for Immediate Neutralization of Chlorine Technology and Energy Reversion (SFINCTER). Johnathan Quest, FBI spokesperson, confirmed that AssaB was a person of interest in the case. “Anyone with information about the whereabouts of AssaB, should contact the FBI or their local law enforcement personnel,” Quest told reporters.

A reliable source at the National Critical Infrastructure Security Operations Center (CI-SOC) who is not authorized to talk to the press confirmed that someone had hacked the Robotron web site and substituted the links to their ‘Security.txt’ listing on the main page that pointed at a web site controlled by SFINCTER. That allowed the hacker collective to intercept Lightman’s vulnerability report which included proof-of-concept code. That vulnerability, along with at least one other zero-day vulnerability allowed SFINCTER to install ransomware on the Bleichen Chemical safety controller.

Carl Scheele, the Bleichen Delano Plant Manager, told reporters in December that the company was forced to shut down production at the plant for five days while they negotiated a final ransom payment to unblock the safety controller. “There was no way that we were going to run our chlorine production unity without that safety controller in place,” Scheele told reporters at the time; “We had to pay the ransom as we had no other way to restart that controller.” Bleichen has not disclosed how much ransom was paid to SFINCTER. Sources report that it was certainly less than the 100 bitcoin asked for in the initial ransom demand.

Kate Libby, security researcher at Dragonfire Cyber, provided background information on the ‘Security.Txt’ exploit used by the attackers. She explained that industry has been settling on using a standardized link on their web pages to allow independent security researchers like Lightman to reach out to the appropriate folks at a company to report cyber vulnerabilities. The ‘Security.txt’ link takes the researcher to a brief message that provides contact information, including an encryption key, to allow them to securely send information about vulnerabilities to teams at the company that are responsible for fixing such vulnerabilities.

“In this case,” Libby said; “Poor web site security allowed hackers to substitute their own contact information for those of the company’s security team.” That allowed SFINCTER to utilize the good work of Lightman for their own nefarious ends.

Erich Mielke, spokesperson for Robotron refused to take questions from reporters after issuing the following statement:

“Robotron thanks Mr. Lightman for his efforts to help us maintain our high standards of security. Researchers like Mr. Lightman are an important part of our security program. We are happy to see him vindicated and look forward to working with him in the future.”

CAUTIONARY NOTE: This is a future news story –

Sunday, February 4, 2024

FlottSoft Hack Paralyses Federal Government

This morning, shortly after news broke about hundreds of stalled vehicles blocking traffic in Washington and its suburbs, the Federal Fleet Management Service announced that the entire federal motor vehicle fleet had been paralyzed by ransomware. “This morning at six-thirty Washington time, each of our FlottSoft terminals across the country flashed a red screen and then announced that every non-electric vehicle in our fleet would not be able to start until a ransom of 10,000 Bitcoin was paid,” Terry Ragozine, spokesperson for the FFMS told reporters. Vehicles in transit when the ransomware struck shutdown the next time that the vehicle came to a stop.

Shortly after that announcement, a brief announcement was made by Regina Louis Ziegler, White House spokesperson, that the President was working with his national security advisors on a solution to this problem. “It remains the policy of the United States that we will not pay ransoms, nor will we deal with terrorists,” she announced. Ziegler refused to answer questions about how many of the President’s advisors were still stuck in stalled vehicles in Washington.

General Buck Turgidson, Director of the National Critical Infrastructure Security Operations Center (CI-SOC), announced that the CI-SOC was working on the problem. “Fortunately, we have four vehicles here at out headquarters in Delano, GA that are affected by the stoppage to work with,” Turgidson explained. “We have confirmed that the malware is acting at the vehicle level, somewhere within the vehicle CAN bus network, the FlottSoft terminals are working normally after the ransomware announcement is disabled.”

An FFMS background document on FlottSoft explains that the software was adopted by the federal government about ten years ago to manage the ever expanding fleet of motor vehicles. The software allows FFMS managers to track vehicle use and maintenance. Just two years ago, the vendor added anti-theft protections that allowed stolen vehicles to be shutdown by managers.

Late Breaking News: According to a variety of sources, at 8:30 EST all of the shut-down vehicles in the federal inventory began systematically flashing their lights on and off. Multiple sources noticed that the lights were flashing in Morse Code, repeating “Pay Me”. This affected electric vehicles that were previously excluded from the effects of the attack.

CAUTIONARY NOTE: This is a future news story –


Sunday, January 28, 2024

Chemical Plant Explosion Was Sabotage

Early this morning the Chemical Safety Investigative Office (CSIO) announced that it had determined that last week’s explosion at the Ravard Refinery in Los Angelas was the result of sabotage. Trevor Kletz, spokesperson for CSIO told reporters that: “Investigators have found a device on a pump in the crude oil distillation unit that is believed to be the source of the explosion.”

Background information provided by CISO on the device explained that that the singed remains were relatively intact because of where it was placed on the pump motor. The device consisted of an energy harvesting circuit, a flammable gas sensor, and a capacitor. Investigators from the National Critical Infrastructure Security Operations Center (CI-SOC) confirmed that the device was programed to short out the capacitor, producing an electric spark, when the gas sensor detected a flammable atmosphere. Gen. Turgidson, CI-SOC Director, confirmed that his team had been able to recover programming data from chips on the device that enable them to determine the way the device operated. “No communications were necessary to initiate the explosion, it was entirely automated,” Turgidson explained; “when the conditions were right for the spark to do the most damage, the device shorted out the capacitor.”

Shortly after the CISO announcement was made, a radical environmental group, Students for Immediate Neutralization of Chlorine Technology and Energy Reversion (SFINCTER), claimed responsibility for the attack. The social media claim stated: “We have begun a new engagement in our struggle against the corporate polluters responsible for the devastating changes in our climate. This is just the beginning.”

Johnathan Quest, spokesperson for the Federal Bureau of Inquiry confirmed that the FBI had assumed control of the investigation of the refinery incident. “Now that this is confirmed to be a terrorist attack, the full weight of the Bureau will be employed to find the perpetrators and bring them to justice,” Quest announced.

John Muir, spokesperson for the Ravard Refinery, noted that there was significant damage to the crude oil distillation unit and the refinery was completely shutdown until that unit could be restored. “While there was little or no damage to other operating units, there will be no fuel or other chemicals produced here until that unit is back in operation.” Muir explained.

Gasoline prices on the West Coast, already the highest in the nation, are expected to rise sharply as the Ravard refinery is about 20% of the West Coast’s refinery capacity. The Governor’s Office on Climate Change (COCC) noted that: “This is just another reason why it is so critical for the State to develop and support alternative transportation fuels.”

CAUTIONARY NOTE: This is a future news story –

Wednesday, March 1, 2023

Rare Earth Recovery Company Victim of Ransomware Attack

Today, Rare Earth Recovery (RER – NASDAQ) announced that it was declaring force majeure on deliveries because of serial ransomware attacks. “During the last three weeks we have experienced ransomware attacks on our commercial sales system, our HR and email systems, and most recently on the control systems for our Materials Recovery unit;” RER spokesperson Carl A. Arrhenius told reporters; “In each case, we were able to recover systems without paying ransoms, but the cumulative effects have seriously interfered with our production and shipping operations.”

Investigators from the National Critical Infrastructure Security Operations Center (CI-SOC) are working with RER to ensure that their systems are free from infection and prepared to move forward without additional attacks. “Our people have found indications that earlier attacks left backdoors in the corporate system that have allowed the attacker to regain access to the system,” General Buck Turgidson, CI-SOC Director: “These appear to be sophisticated attackers.”

The Federal Bureau of Inquiry is also investigating these attacks. “RER recovered materials are being used in critical defense systems, and so for national security reasons, the FBI is taking responsibility for the criminal investigation,” Johnathan Quest told reporters. There are rumors that that this attack is related to the attacks reported last week at Bermite Ammo. “BAM is a customer of ours,” Arrhenius told reporters, “We do not have any cyber linkage beyond the occasional email.”

BAM is one of the companies that will have delayed deliveries from RER. Patrick Lizza, BAM spokesperson noted that the rare earth metals provided by RER are used in house to manufacture proprietary components that it uses in their fuses. “We can still manufacture and fill the shell casings, but without the fuses, we are unable to ship to the Army,” Lizza said.

Kate Libby, a technical response manager with Dragonfire Cyber, that is working with CI-SOC on this investigation, told reporters this morning that it was unusual for an attacker to take three separate shots at getting ransom from a target. “They have not acted like a normal money-driven ransomware attacker. They have not made any other data extortion efforts to get money out of the company,” she told reporters. Turgidson added that there appeared to be another motive in these attacks, but refused to talk about what that motive might be.

REM is a biotechnology company that extracts minerals and rare earth metals from coal power plant ash using bioengineered bacteria and produces geo-bricks from the remaining ash.

CAUTIONARY NOTE: This is a future news story –

Friday, February 24, 2023

Innovative Ammo Manufacturer Shut Down to Ransomware Attacks

Bermite Ammo Mfg announced today that it would miss delivery of the next batch of its new carbon-composite 155mm artillery shells to the US Army because of a ransomware attack on its facility in Saugus, CA. “We have experienced a ransomware attack on the IT systems at our Saugus facility, so we have shut down all of our cyber systems pending resolution of the problem,” Patrick Lizza, corporate spokesperson told reporters; “Our production control systems were not directly affected by the ransomware, but we are doing detailed checks of those systems out of an abundance of caution.”

The Army Ammunition Command reports that they are aware of the shutdown and have coordinated with Cyber Command for assistance in investigating the problem. LTC Henry Knox, from AAC, told reporters at a press conference in St Louis, MO: “We are concerned about any delay in the manufacture at BAM since their new carbon composite 155mm artillery shells allow us to free up additional ammunition for shipment to Ukraine as the Army replaces their conventional shells with the lighter, more powerful BAM shells.”

Bermite had met all Army cybersecurity requirements for primary manufacturers, so the Cyber Command is concerned that this may represent a more effective ransomware attack. Cyber Command has employed investigators from Dragonfire Cyber to look specifically at the industrial control systems on the site to see if they were impacted. “Dragonfire has specific experience in incident response in the type of equipment utilized at BAM, Knox told reporters; “Cyber command will look at the ransomware issue, and Dragonfire will clear the control systems.”

A technician with Dragonfire that is not authorized to talk to the press about the investigation told me that there were some indications of unusual activity between corporate IT systems and the control systems at the facility. “Investigators are still looking to see if any changes had been made in device programming or security settings,” she said.

CAUTIONARY NOTE: This is a future news story –

Thursday, February 9, 2023

‘We’re Back’ Ransomware Targets Chemical Facilities

The National Critical Infrastructure Security Operations Center (CI-SOC) reported today that it was seeing an increasing number of chemical facilities being affected by ‘We’re Back’ ransomware attacks. “This ransomware is specifically designed to disrupt chemical manufacturing operations,” Gen Buck Turgidson told reporters; “Instead of shutting down equipment, it typically closes valves at non-critical points in the process and sends a ‘We’re Back’ message to the HMI controlling that valve.”


 The Federal Bureau of Inquiry is investigating these attacks. “We have only been notified of three attacks, so far,” Johnathan Quest, FBI spokesperson, said, “We know from anecdotal reports that many more facilities have been affected.” The FBI is requesting that any facilities that have been affected by this ransomware contact their local FBI office.

Turgidson confirmed that they have been notified of more than three attacks. “We have had some facilities share information with us on the condition that we specifically do not report the information to law enforcement,” Turgidson explained. CI-SOC does not report the incident to the FBI in those cases, but they do share technical information about the attack.

Kate Libby, a Technical Director for Dragonfire Cyber which is working with the CI-SOC on this investigation, told reporters that they have not yet been able to track down how the ransomware has made its way into the systems. “The previously unidentified attackers have apparently been in these systems for some time and have erased their tracks well,” Libby explained. Dragonfire has been able to locate the ransomware in the systems, it resides in programmable logic controllers (PLC’s). “We have found multiple copies of the malware in each facility,” she reported; “We are concerned that this may mean that the attackers may be prepared to re-demand ransom in the future.”

“We have not yet been able to identify the group behind the attacks, they are very sophisticated in their security measures,” Turgidson told reporters, “We do believe that they are operating out of Venezuela.”

According to the FBI, efforts to track the bit coins have been unsuccessful, “The WB Group, as we are currently calling them, transfers funds out of their initial wallets almost immediately and closes wallets or abandons wallets once used,” Quest said; “We need to be able to track transactions in real time if we are to have any hope of shutting these folks down. This is why we need to be informed immediately about any attack.”

CAUTIONARY NOTE: This is a future news story –

Thursday, February 2, 2023

Multiple Ransomware Attacks on Artillery Contractors

The Defense Armaments Agency announced today that production of 155mm artillery shells at Blackshear Arsenal in Georgia has been halted for two weeks due to multiple ransomware attacks on subcontractors supply parts for the high-tech munitions that are being consumed in high number in the Ukraine. “We are unable to obtain component parts for the fuses and attitude control systems because various manufacturers have had production interruptions due to cyberattacks on manufacturing facilities,” Samuel C Robinson, spokesperson for the Agency, told reporters this morning.

The Federal Bureau of Inquiry is the lead agency in the investigation because the facilities are not directly contracted by the Department of Defense. According to Johnathan Quest, FBI spokesperson, the companies involved provide parts to component manufacturers that supply the Blackshear Arsenal. “In most cases, the initial set of attacks were being investigated by State and local authorities as routine ransomware attacks,” Quest explained.

General Turgidson, Director of the National Critical Infrastructure Security Operations Center (CI-SOC) which is supporting the investigation, it was not until Blackshear reported supply interruptions of multiple contractors that national level interest was focused on the investigation. “For the most part, these are small businesses using highly-automated manufacturing systems to provide small volume, high-tech components for these ammunition components,” Turgidson explained.

“It looked like these were simply ransomware attacks on random organization when we first started receiving reports form our suppliers” Blackshear spokesperson George Forno told reporters; “When we started receiving reports of damaged control systems after ransoms were paid, it became apparent that this was something more organized.”

“We are still not convinced that this is a centrally directed effort,” Quest responded. The FBI has isolated four different ransomware programs associated with known criminal groups from Russia, North Korea, Iran and Nigeria.

CI-SOC had determined that there have been some indicators that some unknown actor is providing corporate access data to known ransomware groups. “While most of these small businesses do not have significant cyber defenses due to a lack of cybersecurity personnel, there have been at least two of the facilities have been supported by the CI-SOC,” Turgidson explained; “Access to those systems took a level of sophistication not normally associated with criminal organizations.”

A technician at CI-SOC that is not authorized to talk to the press has told me that a number of cybersecurity and industrial control system companies are working closely with CI-SOC, the FBI and the affected facilities in a coordinated effort to get them back on line. Turgidson confirmed that this is an all-hands effort. “We cannot afford to allow production at Blackshear to remain idle while our allies in Ukraine are preparing for an expected Russian offensive. They need these 155mm shells.”

CAUTIONARY NOTE: This is a future news story –

Thursday, January 26, 2023

Liability for Known Vulnerabilities Bill Introduced

Rep Mark Sloan (R,CA) introduced the Liability for Known Vulnerabilities Act today. The bill would make manufacturers of computer controlled equipment used in hospitals and schools financially liable for deaths and serious injuries that resulted from cyberattacks on those institutions using vulnerabilities that had been reported to the vendor more than six months before the attack. Sloan’s Los Angeles office says that the bill is a direct response to the attack on the Angels Memorial Hospital earlier this week that killed four people.

The four deaths in the hospital’s intensive care ward occurred when power back up systems failed to restore power to critical medical monitoring systems and medical devices during a power outage caused by local storms. The uninterruptable power system’s (UPS) control system had been breached by an unidentified hacker using vulnerabilities in the SotoPower HMI. Those vulnerabilities had been publicly reported to SotoPower last June by Israeli researchers. SotoPower reported Tuesday that they were still working on fixes for the reported vulnerabilities.

Sloan told reporters that an independent review of the Israeli research confirmed that the three reported vulnerabilities, including a path traversal vulnerability and a hard-coded credential vulnerability, were relatively easy to fix. “Security researchers looking at this week’s attack reported that those vulnerabilities were used to gain access to the system at Angels Memorial,” the Congressman explained, “Those basic vulnerabilities should not take six months to correct.”

Sloan’s bill would establish a prima facie case for product liability in any case where a cyber attack at a school or hospital resulted in deaths or serious injuries and the attack was facilitated by vulnerabilities that had been identified more than six months earlier.

CAUTIONARY NOTE: This is a future news story –

Tuesday, January 24, 2023

Hospital Deaths Due to UPS Hack

The Angels Memorial Hospital in Los Angeles announced today that three deaths overnight in their intensive care ward were due to cyberattacks on the hospital’s backup power system. A local power outage led to the failure of critical medical devices when the hospital’s UPS systems failed to switch power to the battery backups designed to take over in the event of local grid failures. The hospital has not released the names of the victims.

The Federal Bureau of Inquiry is investigating the apparent cyberattack that stopped the UPS control system from activating the backup power system. “Potential suspects have not yet been identified,” Johnathan Quest, FBI spokesperson, told reporters this afternoon; “But we are in the very early stages of the investigation.”

SotoPower has been identified as the manufacturer of the uninterruptable power supply system used by Angels Memorial. Jake Hanley, company spokesperson, told reporters in a brief statement that the company was cooperating fully with investigators. “The security of our systems is a high-priority for our company,” Hanley said.

In the early summer of 2022, the Israeli cybersecurity firm, BuddaHack, published a report outlining three vulnerabilities in the SotoPower HMI, the control system used in the medical facility power backup system. Last month the federal ECS-CERT, published an advisory about the same vulnerabilities. “SotoPower did not respond to our coordination efforts about the vulnerabilities reported by BuddaHack,” Immanuel C Securitage told reporters this afternoon. “We have no indication that the vulnerabilities have been addressed.”

Hanley responded to questions about the reported vulnerabilities, “We are continuing to work on remediation efforts,” he said; “Our web site includes instructions to protect systems from outside access.”

Ira Haaretz, a researcher with BuddaHack, told me that the vulnerabilities identified last summer could allow an attacker with access to the hospital network to reprogram the UPS control system. “These access control vulnerabilities provide a relatively low-skilled attacker with the ability to obtain administrative level access,” Haaretz said; “They do not require any significant programing capabilities beyond changing a publicly available URL.”

A wrongful death lawsuit was filed today in Los Angles Superior Court on behalf of one of the families. Details were not available when this article was published.

 

CAUTIONARY NOTE: This is a future news story –

Saturday, December 17, 2022

3 Chlorine Cylinders Stolen by BEC Fraud

Bleichen Chemical Company announced today that three 1-ton chlorine cylinders had been stolen from the company by fraud. “As a result of a business email compromise fraud, unknown parties set up a water treatment account with our company for chlorine supply at an abandoned water treatment plant on the East Side of Delano.” Carl Scheele, the Bleichen Delano Plant Manager told reporters this morning; “We made two deliveries over a three-week period and had a third order loaded on a truck when the FBI notified us that we had been scammed.”

Johnathan Quest, spokesperson for the Federal Bureau of Inquiry, told the news conference that the FBI had been tracking a series of BEC frauds being perpetrated by the same individual. When they intercepted emails from Bleichen about past due bills for the chlorine gas deliveries, they became concerned and contacted the company.

Scheele explained that Bleichen had received a request to set up a new delivery account for an existing food processing customer. “They claimed to be restarting the old Dolly Madison plant here in Delano and needed to get the water treatment plant functioning,” he explained: “They had the corporate account number and the right names on letterhead stationery as well as a legitimate looking email address for the account executive.”

Quest said that the FBI has lost track of the perpetrators and had not yet located their base of operations. “The Delano water facility where the deliveries were made has been cleaned up and re-abandoned.” He said, “We have multiple forensics teams going over the facility, but we have not yet found any useful evidence.”

When asked what the criminals had done with the chlorine gas, Quest replied: “We have found evidence that would seem to indicate that the material had been transferred to 5-lb pressure vessels, probably propane cylinders. We have not been able to identify a commercial purpose for small chlorine containers like this, so we do not know what financial incentives there were to perpetrate this fraud.”

Two 1-ton cylinders had been delivered for the initial order last month. A second order of one cylinder was delivered earlier this month and an empty cylinder was picked up. That means that as much as 2,000-lbs of chlorine gas may have been off-loaded into small cylinders. A technician from Bleichen that has been working with the FBI at the treatment facility told me that: “Propane cylinders are not approved for the storage of liquid chlorine, and there was no evidence of the equipment needed to do a liquid-liquid transfer at the site, so there is no way of telling how much chlorine was transferred to each cylinder. There were lots of them.”

CAUTIONARY NOTE: This is a future news story –


Sunday, December 11, 2022

TSP Fleet Tankers Hacked During Navy Exercise

The US Naval Department confirmed this morning that, during a recent fleet exercise in the South Atlantic, civilian fuel tankers that are part of the new Tanker Security Fleet were hacked by elements of Fleet Cyber Command. “Naval cyber operators conducted active operations against Ulan Master and Torrey Canyon tankers that were providing fuel support during Operation Malvinas;” reported David D. Porter, Naval spokesperson. “Navy personnel were able to take remote control of engines and steerage on both vessels using known vulnerabilities in various systems onboard the vessels.”

Captain Frank F. Fletcher of the Torrey Canyon told reporters: “In 20 years of operations in ocean going tankers I have never seen a ship fail so completely to respond to commands from the Bridge. It was quite disconcerting.”

Captain Na Dae-yong of the Ulsan Master added: “I did not appreciate losing control of my vessel, but hopefully we will be able to ensure that such actions could not be undertaken by an enemy during a wartime operation.”

Owners of the two vessels had been informed prior to their participation in the exercise that cyberattacks would be employed against the two vessels during the exercise to determine their susceptibility to such attacks. “These types of attacks would be expected against fleet assets involved in wartime operations,’ Porter explained; “And we expected that the civilian operators would not be as experienced as active fleet personnel in preparing for or responding to such attacks.”

The Navy plans on sharing the results of these attacks with the owners of the two vessels as well as the other owners of vessels in the TSF. Owners will be able to use the information gleaned from these attacks to upscale the cyber defenses for all of their vessels, a major incentive for owners of other fleet capable tankers to sign up for participation in the Tanker Security Program.

Cpt Berny McCollough, spokesperson for Fleet Cyber Command, refused to comment on reports that CYBERCOM detected another party participating in the exercise. “I cannot confirm or deny public reports that a foreign nation state was receiving information from the two ships.” There have been two reports quoting unofficial comments from naval cyber personnel that communications between the ships and a Chinese server had been detected during the operation. One unnamed Navy Lieutenant has been quoted as saying: “We found communications logs showing that the vessel (referring to Torrey Canyon) had been hacked prior to the start of the exercise and had been reporting vessel position and status to a foreign operator.”

McCollough also refused to comment on reporting by the naval blog, Kings Island, that purported to show tracking information of the maneuvers of the two ships under control of the Navy’s hackers. “We will not discuss operational details about the exercise.” The Kings Island tracking data shows the two tankers conducting right and left 180 degree turns and heading back in the direction from which they came.

 

CAUTIONARY NOTE: This is a future news story – 

Tuesday, December 6, 2022

Pipeline SCADA System Hacked in Texas

Pipeline Safety, Security and Operations Office (PSSOO) announced today that the recent crude oil leak near Tyler, Texas was due to a sophisticated cyberattack on the pipeline control system. “The attackers manipulated valves and pumps to create a local overpressure situation,” Michael E Thane, spokesperson for the PSSOO; “This caused pressure relief systems to open and begin pouring crude oil out at the remote location near the Neches River.”

The pipeline, owned by the Friendly Morning Pipeline Company, apparently started leaking just after sundown and was not stopped until a fisherman reported seeing the crude pouring into the Neches River near his favorite fishing spot the next morning. The sour crude being pumped through the pipeline contained high levels of hydrogen sulfide, a toxic gas. A major fish kill has been reported along a 20-mile stretch of the river.

The National Critical Infrastructure Security Operations Center (CI-SOC) is working with PSSOO and the Federal Bureau of Inquiry and the Texas Environmental Commission to investigate this incident. Local law enforcement has been told that this may be an environmental terrorist attack, but none of the federal agencies involved in the investigation are willing to use the T word publicly.

George Friendly, President and Owner of the affected pipeline company talked with reporters this morning. He noted that the company was using a pipeline SCADA system that was specifically designed for secure monitoring and controlling of pipeline operations. “We worked closely with Albert Foxborough, the founder of Flintstone Tech in his development of their pipeline secure automation system.” Friendly explained.

A source, who must remain nameless because they are not allowed to talk to the press, with the CI-SOC explained that the Flintstone PSAS was a complete supervisory control and data acquisition system that was designed for secure communications between the various parts of the pipeline automation system. “This system was designed in early 2016 before people generally started talking about zero trust systems,” she explained; “And certainly before people started to talk about it in industrial control systems.”

Friendly agreed that the PSAS had a zero trust architecture, but explained that: “Albert started employing what is now called zero trust architecture back in 2015 when he started the design of his new operating system”. Security was built into the operating system as one of the core principles of its design. This meant that there was no need for add on security appliances or applications.

The CI-SOC technician said that Flintstone was recently disbanded when its parent company was sold. “The new owners apparently did not want to offend their customers who were manufacturers and vendors of more conventional control system and security systems.” Flintstone shutdown operations and customer support on very short notice. The last thing the company did was issue a mandatory software upgrade for their systems that effectively reduced the security communications controls of the system.

Friendly told reporters: “We had the most secure pipeline control system the world has seen to prevent just this sort of incident. We had to reduce the security to keep the control system functioning. Now this happens. Where are all of the federal cybersecurity folks now?”

CAUTIONARY NOTE: This is a future news story –


Sunday, October 16, 2022

Car Swatting

The California Highway Patrol is currently investigating three instances of car swatting in the Bay Area this weekend. According to Francis L. Poncherello, CHP spokesperson, the latest incident occurred when a car was stopped in San Francisco at about noon today when a CHP officer noticed an Amber Alert notice on the vehicle digital license plate. Patrol cars from three different jurisdictions participated in the stop of the vehicle. Malcom Reynolds and his wife Jayne were forced from their car at gunpoint and handcuffed before the offices realized that Amber Alert on the tag was part of an ongoing cyber attack on the State’s new RiPlate, digital license plates.

Derrail Book, CEO of Reaver Electronics, explained that the RiPlates produced by his company had included the Amber Alert notice as an option on their digital license plates as a way to help police agencies locate and identify vehicle being used by kidnappers. “We have strong software controls designed into the system that only allow police departments equipped with an RiTerminal to activate the Amber Alert notices on our RiPlates,” Derrail explained; “This weekend’s problem must be due to inadequate administrative controls in local police terminals that can remotely access our plates.”

The first car swatting incident occurred in San Francisco early Saturday morning. A car owned by Congressman Harvey Milk was surrounded by a police tactical squad in the parking garage of the Muir Marriott Hotel. The license plate on the vehicle matched a plate that was reported to be involved in the recent theft of explosive from a construction site in San Mateo on Friday. The Congressman was upstairs receiving an award from the San Francisco Retired Police Organization (SFRPO) for his support for families of police officers wounded in the line of duty. When Milk returned to his car 30-minutes later he found that the trunk and doors had been forced open and the car was undergoing a detailed search for explosives. A digital license plate reader at the Hotel captured a picture of the license plate on the Congressman’s car, it matched the number of the car that was being looked for in the San Mateo case.

In theory, once the Department of Motor Vehicles assigned a license plate number to the RiPlate, it can only be changed by order of the DMV. Reaver Electronics actually makes the change, but only when ordered by the DMV. Book told reporters this morning that there is no record of a change being made to the RiPlate on Milk’s car.

When asked if there could have been a cyber attack on his company’s computer systems, Book replied: “We have very strong cybersecurity controls in place on our corporate networks. We have promised the Governor and the DMV that our systems will not allow unauthorized access to the RiPlates or their supporting technology.”

The National Critical Infrastructure Security Operations Center (CI-SOC) is helping the Highway Patrol investigate these three car swatting incidents. General Buck Turgidson, CI-SOC Director, reminded reporters this afternoon that there is no such thing as an unhackable system. “We have not yet found a hackable vulnerability in the system, but we have just started looking.”

 

CAUTIONARY NOTE: This is a future news story –


Friday, September 30, 2022

Cloud Server Farm Taken Offline by Drone Attack

Eniac Cloud confirmed that yesterday’s interruption in their cloud service was due to a remotely piloted aircraft being flown into the substation supplying power to their Delano Datacenter. “All systems switched over to alternative routings within minutes and our customers were only momentarily discomforted,” Richard Brathwait, spokesperson for the company told reporters. “We expect to resume full service in the Delano Center within a couple of weeks.” Two transformers at the company leased substation will have to be replaced.

Johnathan Quest, Federal Bureau of Inquiry spokesperson, confirmed that the FBI was working with the Federal Airline Administration in investigating the incident. “We have identified the owner of the aircraft, Barkhorn Aviation, but they lost control of the aircraft when it was almost 75 miles away from the Delano facility.” Quest told reporters.

Oscar Holmes, spokesperson for the FAA, confirmed that the agency had seized the controller used by Barkhorn Aviation, an agricultural sprayer company, but that it was apparent that the controller did not have the range necessary to conduct the attack in Delano.

A spokesperson for Barkhorn told reporters that they lost control of their BF 109 drone about 8:00 am yesterday. “The operator saw the aircraft take a left turn from its last spraying run on a cotton field outside of Dothan, AL,” Erich Hartmann told reporters; “It was last seen flying over the trees to the east of the field that we were spraying.”

A technician at Eniac who is not authorized to speak to the press told me that there was some small amount of data lost in the attack that had not yet been backed up, but the system worked as it was designed. “We have contingencies for power outages, and the plan worked well,” she said.

Brathwait said that the prolonged outage at the Delano Center would slow some of the data flow through their cloud network, but that customers would not be able to notice the difference. “Temporary loss of a single facility in our cloud network is not a problem,” he explained.

CAUTIONARY NOTE: This is a future news story –

Wednesday, September 14, 2022

Mini-Crime Wave Cover for Jewelry Stores Heist

A sophisticated gang of crooks cleaned out three jewelry stores in downtown Delano, GA yesterday morning while the police were responding to nonexistent emergencies around the city’s outskirts Chief S. James Butts told reporters this morning. “Not only did the thieves disable the store silent alarm systems,” Butts said; “They also were responsible for three automated alarms, two bomb threats at schools and four auto accidents with reports of injuries that tied up all of our patrol units well away from the downtown area.

Butts also reported that the Delano Police Department had requested assistance from the Federal Bureau of Inquiry in the conduct of the investigation. “Too many of cyberattacks were involved in this series of events for our Department to investigate,” Butts explained, “We only have one cyber-investigator on the force and she is already working on two other cases.” According to the Georgia Bureau of Inquiry, the State cyber-investigators are still tied up on the continuing attacks on vehicle charging stations in the Atlanta area and are not available to help the Delano investigation.

Johnathan Quest, spokesperson for the FBI, confirmed this morning that the FBI was working with the Delano Police Department on the investigation. “We have some indications that the criminals used an internet connection to hack the building security system,” Quest explained; “This means that they could be charged with computer fraud, which is, of course, a federal crime.”

Employees at all three of the jewelry stores reported that they had just finished putting jewelry on display when the thieves entered through the front door of each store. The doors had not yet been opened for the day, but the crooks apparently remotely manipulated the electronic locks on the doors. One of the store managers that asked not to be identified because of insurance concerns said that opening those doors before they were unlocked through the store security system should have immediately triggered an alarm to the Delano Police Department.

The three store owners refused to discuss the value of merchandise stollen from their stores because of ongoing negotiations with insurance companies. 

CAUTIONARY NOTE: This is a future news story –


Tuesday, September 6, 2022

Farbenhack Tool Being Sold on Dark Web

The ECS-CERT announced today that, in conjunction with investigators from the Federal Bureau of Inquiry, it had discovered a new hacking tool being sold on the Dark Web called Farbenhack. The tool provides a suite of applications that can be used to conduct ransomware attacks on manufacturing organizations. “We have seen various combinations of the applications being used in real world attacks on small companies in the United States,” Immanuel C Securitage, spokesperson for ECS-CERT, told reporters this morning.

Johnathan Quest, spokesperson for the FBI told reporters that the earlier attacks were apparently proof-of-concept demonstrations for the new Farbenhack Tool. “The web site where the tool is being sold shows screen shots of the applications being used in those attacks,” Quest said. “The tools provide tools for conducting targeted phishing attacks on control system engineering professions, with options for using drive by attacks on an engineering web site, or the download of compromised files from look-alike web sites. The phishing tools are very sophisticated, targeted at folks who should be knowledgeable about web-surfing vulnerabilities.”

An engineer working with ECS-CERT who is not authorized to talk to the press, told me that the post-compromise tools are even more refined. “While many, maybe most, control system devices are easily compromisable when one has access to the control network,” she told me; “These tools allow simultaneous reprograming of a large set of devices on a network to shutdown processes once the ransom notice is published, both on the engineering workstation and any HMI on the network.”

Interestingly, Quest notes that the Farbenhack Tool comes complete with command-and-control networks on Russian servers. “This CC network, along with some programming conventions, raises suspicions that the tool was developed by Russian hackers. It is not clear if they are officially sanctioned by the Russian government, but disruption of manufacturing capabilities in the United States and Europe would certainly be in the interest of the Putin government.” People who buy the tool, do have the option to change to their own CC networks.

Securitage points out that a premium version of the tool provides for an enhanced option to encourage victims to pay the ransom. The tool provides applications that will brick devices, making them inoperable and requiring replacement. “The vulnerabilities that lead to bricking are well known, but require authenticated access to the devices from the engineering workstation,” Immanuel said; “So many organizations find it an acceptable risk to not patch the devices.”

Neither ECS-CERT nor the FBI have any information on how many of these tools have been sold. ECS-CERT has published on their secure web portal a list of the compromised and look-alike web sites being used by the tool. “We do expect, however, that the crafters of the tool have the capability to update the tool with new web sites,” Quest explained, “We are being forced to play whack-a-mole with these sites.”

 

CAUTIONARY NOTE: This is a future news story –

Sunday, August 28, 2022

Aircraft Inflatable Lap Belts Hacked in TWA Incident

A Transportation World Airlines aircraft that was forced to return to Los Angeles International Airport yesterday when all the passenger inflatable lap belts simultaneously inflated as the aircraft crossed over the coast yesterday was the victim of a cyberattack. “We have been notified by GeschütztesDF, a notorious German hacker, that she was responsible for the activation of the lap belts,” John Frye, spokesperson for TWA, told reporters; “She has demanded that a ransom payment be paid to Stasi Ehemalige to avoid having future flights similarly attacked.”

Johnathan Quest, the spokesperson for the Federal Bureau of Inquiry, confirmed that Kate Libby, the hacker known as GeschütztesDF, was recently released from federal custody when a second federal trial on airline hacking charges based upon her part in the earlier WannaFly attacks resulted in a second hung jury. “She was released in New York just a little over a week ago and dropped out of sight within two hours of her release.”

Kate Libby (not related) from Dragonfire Cyber, reported that they were working with the FBI and the ECS-CERT on the investigation of the attack. “This morning our technicians found a vulnerability in the wireless test function of the electronics module of the lap belt system that allowed a specially crafted wireless signal to command inflate the lap belts,” Libby told reporters at a CI-SOC news conference this afternoon; “We have not confirmed that this vulnerability was exploited in the attack, but it is certainly an issue that needs to be addressed.”

Robotron Aero is working with Dragonfire to identify and fix the source of the vulnerability that was exploited in the attack. “Our technical staff is working on a fix for the vulnerability identified by Dragonfire,” Fritz Schmenkel, the Robotron manager for Aero division, “And we continue to look for other potential routes for yesterday’s attack.”

“Pending a solution to this problem, TWA is taking all seats that use the inflatable lap belts out of commercial service,” Frye told reporters this morning, “Fortunately, they are only currently being used in side facing seats in First Class on most of our aircraft, so we are not having to cancel any flights.”

Oscar Holmes, spokesperson for the Federal Airline Administration, reported that the agency has issued a safety advisory on the potential problem with the Robotron Aero lap belts. “We have told all airlines using the Robotron inflatable lap belts to stop allowing passengers in seats equipped with those lap belts. Replacements from other vendors that have been type certified for side facing seats can be used for up to 30-days without aircraft specific certification.” The FAA is continuing to monitor the investigation.

CAUTIONARY NOTE: This is a future news story –