Wednesday, October 24, 2018

Did Wireless Hack Cause Massive Chlorine Release?


The Federal Bureau of Inquiry confirms that it has joined the Chemical Safety Bureau in the investigation of the 40,000-lb chlorine release at Blew Bayou Chemical Company chemical terminal outside of Baton Rouge, Louisiana. This news comes after the Students for Immediate Neutralization of Chlorine Technology and Energy Reversion (SFINCTER) announced that its computer team had hacked the wireless controls used to transfer chlorine from a barge to tank trucks at the facility.

Johnathan Quest, an FBI spokesman, told reporters today that the statement by SFINCTER was the reason that the FBI had joined the investigation, but reiterated that the preliminary investigation by the CSB had not yet determined the cause of the release.

Issac B Kaghun, the Blew Bayou owner, confirmed that the company had recently installed Robotron radio-controlled valves on the lines used to transfer chemicals from barges to trucks and railcars at the facility. He noted that those valves had been added when the Company had upgraded the control room at the facility to allow for a fully automated transfer system.

Vera Arbeiten, Director of the CSB, confirmed that the preliminary investigation had identified the source of the leak as a transfer line that was not hooked up to a vehicle. The leak was stopped when the lone site operator suited up in chemical protective clothing and shut off a manual valve on the barge. One of the casualties in the accident was a truck driver who was backing his tank truck into the chlorine transfer station where the leak occurred.

Immanuel C. Securitage, spokes man for ECS-CERT, reported that the Robotron FGVentil-25 valves used by Blew Bayou were the subject of a recent security advisory for a capture and replay vulnerability that would allow an attacker to intercept radio control signals and re-use them to spoof control of the valves. Erich Mielke, President of Robotron, issued a statement that Robotron had coordinated with ECS-CERT in identifying and providing mitigation measures for that vulnerability, noting that the Company had no way of knowing if Blew Bayou had downloaded the firmware upgrade.

Eaton Kaghun, Operations Manager at Blew Bayou, responded when asked about the vulnerability, that he would have to contact the company’s control system contractor about the issue. He did state that the Company had not had any communications from Robotron about the vulnerability.

Three people at or near the site at the time of the accident were killed by the release. Twenty-five people remain hospitalized in critical condition after the incident earlier this week.

Monday, October 15, 2018

City Loses Chlorine Notification Law Suit


This afternoon, Judge James (Skeeter) Willis announced that the Delano Water Maintenance Department was liable for $1.2 million in actual and punitive damages for failure of their Chlorine Release Notification System (CRNS) to notify the residents of the Greenway Apartments of a pattern of chlorine leaks during January of this year. That notification system was required to be installed by Judge Willis after the 2016 chlorine release at the WMD facility injured sixteen people in that same apartment complex adjacent to the drinking water treatment facility.

Junior Butts, the lawyer for the complex, filed the law suit after hackers from the Students for Immediate Neutralization of Chlorine Technology and Energy Reversion (SFINCTER) published data from the CRNS showing a series of chlorine releases from the water disinfection system in January that were not reported to the residents of Greenway. Butts, a resident of the complex, is well known for his legal support of environmental activists including members of SFINCTER.

George Funderburke, the Director of the Delano WMD, argued at trial that the same hackers who accessed the wireless sensor network to obtain the data reported by SFINCTER could have planted that data during their illegal access to the system.

The SFINCTER hackers were not heard from at trial because of their potential for being arrested on federal computer hacking charges. Instead, Butts convinced Willis to request an investigation of the CRNS by the ECS-CERT. Immanuel C. Securitage, the Director of ECS-CERT, agreed to conduct the investigation only after receiving a formal request by Funderburke.

At trial, Securitage confirmed that the CRNS sensor logs showed the data that had been published on-line by SFINCTER. During cross examination he confirmed that known security issues with both the WiFi network equipment and the sensor system made it impossible to tell when the data was entered into the logs. Butts argued that those same security issues could be used to explain why there were inconsistencies in the pattern of readings from the sensor network that the defense argued demonstrated that the reported readings could not have come from any release during the weather conditions present on the days of the reputed releases.
                                             
In his comments before pronouncing judgement today, Willis noted that Delano WMD was responsible for the security of the CRNS network and could not use that inadequate security as a defense in this case. In any case, he noted, the settlement agreement in the previous case required that the CRNS provide immediate alerts whenever sensors reported chlorine readings in excess of 5 ppm and CRNS records showed no such reports from any of the releases recorded by the system.

William H. Lee, III, the Mayor of Delano, noted that the Delano WMD is owned by the City and the City self-insures. The payment of the fine will be discussed at the City Council meeting next week.

Wednesday, October 10, 2018

Last Week’s Sulfuric Acid Release Was Chemical Hack


Augusta, GA

At a press conference today, Special Agent Johnathan Quest of the Federal Bureau of Inquiry (FBI) confirmed that the FBI was investigating the accident last week at the Mayberry Chemical manufacturing facility in nearby Mayberry, GA as a cyberattack on the facility.

That incident involved the release of sulfuric acid from a storage tank that resulted in the injury of seven people including six elementary school students that were working on a class environmental project in a stream adjacent to the facility at the time of the release. Three of the students are still in the hospital in critical condition as is one employee of Mayberry Chemical.

The FBI was brought into the investigation after a preliminary investigation by the Chemical Safety Bureau (CSB) uncovered control system anomalies that apparently precipitated the incident.

Vera Arbeiten, spokesperson for the CSB, reported that sensor data during a reaction vessel filling operation had been doctored to allow the vessel to be overfilled during cleaning operations which resulted in a backflow of water and caustic soda into the sulfuric acid tank. The resulting chemical reaction resulted in the pressurization of the tank and the subsequent release of sulfuric acid fumes and droplets. Those droplets caused the worst injuries to the affected personnel including chemical burns to the faces of three of the students.

Andrew Gryfin, the President of Mayberry Chemical, explained that the company was a specialty chemical manufacturing company and that it was currently working on a project with university researchers for production of a specialty phenolic resin to be used in a DOD study of a potential radar adsorbing coating for aircraft.

Gryfin noted that the company has been suffering from a number of minor process and quality issues since beginning work on the DOD related project. A preliminary cybersecurity review by the ECS-CERT requested by CSB has indicated that the earlier anomalies and the recent incident were related to a previously unreported malware discovered on the control system computer systems. Immanuel C. Securitage from ECS-CERT noted that company control logs documented many of the malware actions that contributed to past incidents as well as the current release incident.

Unfortunately, no one at the company had reviewed those logs, according to Gryfin. The company has no on-site cybersecurity personnel and the logs were set up by a contractor fulfilling a DOD cybersecurity requirement.

Arbeiten noted that the company had put manual safeguards into place to prevent such overfilling, cross-contamination incidents. This incident would have been prevented if a manual valve on the sulfuric acid fill line on the reaction vessel had been closed prior to the start of the process. Closing this valve is part of the written instructions for this process, but the valve was open when investigators arrived on site.

Gryfin noted that the facility had been short staffed lately due to personnel cutbacks. The company had been experiencing some loss of business due to the quality and production problems being experienced.

Quest reported that the FBI investigation was on going and they were getting some technical assistance from units at the nearby military base.

Friday, May 11, 2018

Feds Investigate Mysterious Deaths at Leary Clinic


Today at a news conference in the Delano, GA city hall federal spokesmen explained why they were involved in the investigation of four recent suicides committed by patients of the world-famous Timothy Leary Memorial Clinic for Depression. All four of the patients, whose names are being withheld for medical privacy reasons, were undergoing treatment for depression using repetitive transcranial magnetic stimulation (rTMS).

“The Federal Bureau of Inquiry became involved,” spokesman Jonathan Quest said; “when anonymous tips indicated that all four patients were known drug abusers who were reportedly using the treatment to get extreme endorphin highs.”

Dr. Timotheus Misstrauisch, Clinic Director said: “We were devastated to learn that seemingly legitimate patients referred to this clinic were using our treatment as a method for obtaining illicit if perfectly natural drugs.”

Immanuel C. Securitage from ECS-CERT explained that the FBI requested their help when it became obvious that the controls for the rTMS machine from Robotron Medical had been hacked to provide unauthorized excessive stimulation. Securitage said that a previously undiscovered hacker collective in Atlanta appears to have been responsible for producing a smart phone application called OurTMSDrugs that spoofs an actual app developed by Robotron for clinical use. It is not clear if the patients or some third-party was actually responsible for using the app to initiate the stimulation that would result in the recreational drug dose of endorphins.

When asked if there were adequate cybersecurity controls on the rTMS machine, Misstrauisch replied that: “We have complied with all Federal Drug Administration regulations on medical device cybersecurity. We do not currently have a cybersecurity person working at the clinic, we have been looking for a rockstar applicant with experience in medical device cybersecurity for four years now. The only applications that we have received to date are people with experience in hacking medical devices, not securing them.”

Erich Mielke, a spokesman for Robotron, reported that: “Our rTMSApp provides a secure linkage to our machines with hardcoded credentials that are matched to a specific machine at the time of purchase. We do not use transmission encryption to protect the data in-transit since only the App on an approved device can communicate with that machine.”

When asked how rTMS use could lead to suicide when the FDA has approved the devices, Misstrauisch explained: “The level of stimulation seen in the records for these individuals appears to be so high that the endorphin producing components inside the brain were probably irreparably damaged with little or no natural endorphin production. This is a classic recipe for severe depression.”

Tuesday, August 1, 2017

ECS-CERT Reports on Remote Access Vulnerability

Today ECS-CERT and the Federal Bureau of Inquiry held a news conference in New Orleans to discuss the results of their recent investigation into a series of chemical releases at the Blew Bayou Chemical Company. They announced that the source of the problem was an unexpected vulnerability in the remote access application for the Robotron industrial control system used at the facility.

The FBI spokesman, Johnathan Quest, told reporters that the investigation was initiated when Blew Bayou reported an unusual series of chlorine releases to the Agency for Chemical and Environmental Security (ACES). ACES contacted the FBI to start a criminal investigation of Blew Bayou for violations of a number of environmental and safety regulations related to those releases.

The FBI in turn contacted ECS-CERT for forensic investigation support when it quickly became apparent that the control system at the facility was going to be an integral part of their investigation. ECS-CERT spokesman, Immanuel C. Securitage, told reporters that their initial review of the control system historical records showed that each of the reported releases had been immediately preceded by access to the control system by the facility control system manager, Eaton Kaghun, the son of the company founder and President Issac B Kaghun.

While the FBI continued their investigation of the younger Kaghun, the team from ECS-CERT continued to delve deeper into the historical record at the facility. They discovered that every time that Eaton accessed the facility control system from his smart phone, the controllers for the three release valves sent a message via the opened VPN communications link to web site associated with Students for Immediate Neutralization of Chlorine Technology and Energy Reversion (SFINCTER), a radical environmental terrorist organization. Each of the reported releases coincided with the receipt back of a message from that site via the same VPN link.

While the FBI tried to track down the people associated with the operation of the SFINCTER web site, the focus of the ECS-CERT investigation switched to Robotron, the supplier of the remote access application. Erich Mielke, spokesman for Robotron, told reporters via a video link, that his company quickly and completely cooperated with the investigation.

It turned out that the web site for the Fernzugriff® software had been hacked and the VentilSteuerung worm was included in each download of the Fernzugriff software. The worm allowed an outsider to upload commands to the phone of the app user that would be piggybacked during any VPN session between the app user and the Robotron control system.

Quest noted that it appeared that the hack of the Robotron web site had been undertaken by the German hacking collective, Stasi Ehemalige. The FBI is still investigating ties between Stasi Ehemalige and SFINCTER.

Mielke reported that the worm had been removed from the Robotron web site and that an updated version of the app was available that would remove the worm from the users phone if it was present. Robotron is still working on upgrades to the various control system programs that would deal with the portions of the worm that had been transferred by the app to the actual Robotron control software.


Securitage told reporters that he encouraged all Robotron control system users to discontinue use of the remote application app until the worm had been removed from all software components, both on the phone and in the manufacturing facilities. Indicator of compromise information is available on the ECS-CERT web site.

Sunday, July 2, 2017

City Admits Severe Financial Loss from Water System Hack

William Henry Lee III, the Mayor of Delano, GA told a press conference Friday that the Water Maintenance Department (WMD) had suffered a 40% drop in revenues over the last year, forcing the city to seek emergency operating loans from the federal Water Protection Agency (WPA).

Lee announced that the preliminary investigation by the Georgia Bureau of Inquiry (GBI) indicated that the cause appears to be that someone has tampered with the smart water meters installed by the WMD two years ago. The investigation has been turned over to the Federal Bureau of Inquiry (FBI) because it is a Federal crime to tamper with municipal water systems.

Johnathan Quest, the spokesperson for the FBI, confirmed that an investigation of the Delano WMD was underway, but refused to discuss the on-going investigation.

A person close to the investigation, however, told this reporter that central management unit of the smart meter system had been hacked and used to reprogram the meters so that they reported smaller amounts of water usage than was really measured by the meters. It was apparently a pretty sophisticated attack with significant amounts of insider knowledge because the usage rates were reduced over a six-month period so that all customers were reportedly using only the maximum amount of water that would meet the minimum billing requirements.


Quest has stated that the FBI is looking to talk with Daniel Krumitz, a person of interest who used to work for Robotron Water Systems, the company contracted by Delano WMD to install the smart meter system. Robotron confirmed that Krumitz had work for them, but that he had left the company about a year ago.

Tuesday, June 13, 2017

ECS-CERT Reports on HighTempOverride Attack on Refinery

Today the DHS ECS-CERT announced that the recent shutdown of the Rafael Ravard Refinery in Louisiana was a direct result of a cyber-attack on the facility using the recently discovered HighTempOverride malware. The refinery is still in shutdown mode two weeks after the attack.

ECS-CERT spokesman Immanuel C. Securitage said that attack last month at Ravard Refinery was very similar to attacks on an unnamed chlorine production facility two months ago. That earlier attack caused a number of process shutdowns over the period of a couple of days and then shut the plant down when the control system software used at the plant was wiped from the system control computers.

Securitage explained that the process shutdowns were caused by spoofing temperature readouts in the reaction monitoring system, causing the control system to think that the process was entering a potentially dangerous out of control condition. This is the source of the ECS-CERT name for the malware, HighTempOverride.

The Federal Bureau of Inquiry spokesman Johnathan Quest said that the earlier attack was claimed by Students for Immediate Neutralization of Chlorine Technology and Energy Reversion (SFINCTER). No one has yet claimed responsibility for the Ravard Refinery attack.

Cesar Chavez, President of the Ravard Refinery, noted that his facility had taken precautions against this type of attack by ensuring that all control system files were routinely backed up. This would normally allow for a quick restart after this type of attack. According to the Agency for Chemical and Environmental Security (ACES) the attackers had apparently modified the malware to include a module that infected backup files.

Chaves told reporters that he did not know when the refinery would be able to resume production. Due to retirements over the last couple of years, there were very few employees that were familiar with routine manual operations at the facility. ECS-CERT and the refinery engineering staff were working with Robotron, the control system supplier, to try to remove the malware from the control system.


Chaves noted that every day the refinery was shutdown cost the company $1.5 million.