Wednesday, January 8, 2020

East Coast Brownouts Due to Pipeline Hack


The Energy Security Agency (ESA) today confirmed that brownouts seen overnight in the Northeast are connected to the ongoing cyberattacks against the Friendly Morning Pipeline Company. Spokesman Edison Watt reported that three gas-fired powerplants suffered supply interruptions yesterday causing them to shut down safely. All three plants were subsequently brought back online after gas supply resumed.

Watts noted that there were no cyber attacks on any electrical production or distribution systems. “The grid is safe and operating nominally,” he noted. “The system is designed to allow for production interruptions at individual production facilities. The minor problems last night were due to these three major generators dropping off-line at nearly the same time.”

George Friendly, CEO of the Friendly Morning Pipeline Company, told reporters that his company had engineers at each pumping station to operate the system under manual controls until the cyber issues could be remediated. “We should see no more interruptions of gas delivery to either our residential customers or power generation facilities.” The company is relying on assistance from other pipeline operators to maintain the 100% manual operation of the East Coast Prime Pipeline.

Immanuel C. Securitage from ECS-CERT told reporters that the agency has confirmed that the Smerdis Group is behind the ongoing cyberattacks on the pipeline. The group is known to operate out of Karaj, Iran, but appears to be independent of the Iranian government.

Dade Murphy from Dragonfire, a cybersecurity company assisting in the investigation, reported that it appears that the Smerdis Group had been present in the pipeline control system for some time. The attacks were exploiting known denial-of-service vulnerabilities in a number of the control system components. These vulnerabilities were rated as ‘low-risk’ because rebooting the affected device restored full system operation fairly quickly. Murphy noted that: “Companies frequently decide not to patch for these vulnerabilities due to time constraints and costs involved; it’s a common risk-benefit conclusion for these types of vulnerabilities.”

Securitage told reporters what was going on with this extended cyberattack on the pipeline was that the attackers were stringing minor DOS attacks on multiple devices at a pumping station together to have a larger impact on pipeline pressure. “This is a sophisticated attack requiring extensive pipeline engineering experience and a high-level of knowledge about the control system involved. This is a hallmark of the Smerdis Group.”

Watts agreed with a reporter’s suggestion that coal fired power plants were not subject to this type of fuel-denial attack. He noted that: “Coal-fired plants did typically have days to weeks of coal supplies on hand to avoid problems with fuel-delivery interruptions. That has not been deemed necessary for gas-fired plants. The ESA will be looking at that issue. On-site gas storage may become a requirement.”


CAUTIONARY NOTE: This is a future news story –


Monday, January 6, 2020

FBI Raids China Water Treatment Headquarters


Johnathan Quest, spokesman for the Federal Bureau of Inquiry, told a news conference today that a team of investigators from the FBI, ECS-CERT and Dragonfire, a commercial cybersecurity firm, executed a search warrant at the headquarters of China Water Treatment, a US subsidiary of Tianjin Chemical here in New Orleans. Quest told reporters that three Chinese nationals were detained, and a large number of records and computer hardware were removed from the building.

While Quest was unwilling to discuss the case to which this raid was related, an investigator from ECS-CERT who spoke on condition of anonymity reported that seizures were related to the attack on Blew Bayou Chemical Christmas Week that sent three firefighters to the hospital and caused major damage to the monomer production area of the facility.

An email sent last week from Dragonfire to ECS-CERT reported that company investigations turned up evidence of Chinese involvement in the cyberattack on the facility. Unconfirmed reports this weekend seemed to indicate that Dragonfire had found evidence that the command-and-control server for the attack was located in Louisiana not in China.

Immanuel C. Securitage, spokesman for ECS-CERT, confirmed at today’s press conference that there had been some indications in the attack software that it had been generated by a known Chinese APT group, HuaxueGang. There were not, Securitage reported, any indications that that group was actually involved in the use of that malware in this case. All communications indicators pointed to IP and physical addresses here in the United States.

Eaton Kaghun, a plant manager for Blew Bayou Chemical told reporters outside of today’s news conference that Tianjin Chemical was the competitor of Blew Bayou in Asia and was trying to break into the tight US monomer market via their China Water Treatment subsidiary.

An unidentified spokesperson from the Chinese Consulate in New Orleans reported that the Chinese government was cooperating fully with investigators from ECS-CERT. “We do not in anyway condone attacks on industrial control systems that could have physical impacts on the health and safety of anyone in the US chemical industry.”

A well-known Chinese dissident in Hong Kong, Zhēnzhū Jiàng Yā, reportedly told Dragonfire that in the current international situation, China did not want anyone in the current administration to blame them for a cyber-physical attack on a US company facility. That dissident also reported that it appeared that the President of Tianjin Chemical was being questioned by police in Beijing.


CAUTIONARY NOTE: This is a future news story –

Saturday, January 4, 2020

East Coast Prime Pipeline Interruptions Being Investigated


The DOT’s Pipeline Safety, Security and Operations Office (PSSOO) announced today that it was launching an investigation in the problems being seen in the last 24-hours along the East Coast Prime Pipeline. Low pipeline pressures, intermittent failures at pumping stations and other anomalies have been reportedly been interfering with the delivery of natural gas to a number of electric generating stations along the east coast from Maryland thru New Hampshire. Local distribution of natural gas to local communities has also been a problem where local gas companies derive their supplies from the same pipeline.

George Friendly, owner and CEO of the Friendly Morning Pipeline Company that owns East Coast Prime, says that company engineers and service personnel have been dispatched to all of the pumping stations along the pipeline to try to restore normal operations. He has also asked the ECS-CERT to help look into the problems because much of what has been happening appears to be connected to control system issues.

Rep Rebecca Pinter (D,MA), has asked that the Federal Bureau of Inquiry to help with the investigation because her office has been receiving reports that the problems were due to a cyber attack on the pipeline. A spokesperson for her office reported that they had received information from a constituent with family in the middle east that indicated that this was connected to international tensions in the Persian Gulf. The FBI has refused to comment on that request other than saying that a preliminary investigation had been started based on the information provided by Pinter.

The Department of Homeland Security continues to maintain that there is currently no indication of a credible threat against the United States, but encouraged critical infrastructure to be aware of the increased potential for cyberattacks.

CAUTIONARY NOTE: This is a future news story –

Wednesday, January 1, 2020

Acrylamide Lines Were Actually the Target


Immanuel C. Securitage, spokesperson for ECS-CERT today told reporters that last weeks attack on a Baton Rouge chemical manufacturing facility was apparently more successful than originally planned by the cyber attackers responsible. Information uncovered today indicates that the attacker’s original plan was to apparently disable acrylamide production, not destroy the acrylic acid tank that exploded and caused the facility fire.

As the investigators from the Agency for Chemical and Environmental Security (ACES) were going through the facility today looking at the consequences of the attack while waiting for clearance to enter the acrylic acid storage building found problems with all of the acrylamide transfer lines in the facility. Like the line that exploded, injuring three firefighters, all of whom have been released from the hospital, every acrylamide transfer line in the facility was full of acrylamide.

Daniel Varg, the ACES spokesman, explained that acrylamide transfer lines used to move the monomer around the facility are normally blown empty when they are done being used. This is to prevent the monomer from polymerizing in the line. This is especially critical when temperatures drop below 50˚F. At that temperature the acrylamide freezes out of solution (this facility manufactures 50% acrylamide in water). That process separates the acrylamide from the chemical that is added to the solution to inhibit the polymerization reaction.

We did see temperatures drop below that level after the facility shut down manufacturing before their Christmas break. When temperatures warm back up the acrylamide goes partially back into solution, but does not mix with the inhibitor. Transfer lines that are in the sun can reach temperatures where the monomer can then start the polymerization process, blocking the lines with a polymer plug that has to be cut out of the line.

It appears that there are multiple blockages in most of the transfer lines in the facility. This essentially shuts down acrylamide product until all of the lines can be inspected and all of the blockages cleared. Blew Bayou Chemical estimates that it will be at least two week until production can resume, and most of the transfer lines from storage tanks to truck and rail loading lines were also blocked.

A spokesman for Dragonfire, a company that is supplying control system forensic experts to assist ECS-CERT in their investigation, told reporters that the code for filling the transfer lines was written before the code for the attack on the acrylic acid tank. That acrylic acid attack depended upon the existence of a bad check valve in an airline going into a reaction vessel. That problem was not identified by Blew Bayou until just before their shutdown before Christmas. Dade Murphy explained that it appears that the attackers saw the work order on the maintenance server and realized that it provided them with another mode of attack on the facility.

Murphy also explained that at least one of the people writing exploit code for the attack appears to have been a native Chinese speaker. He would not go into details about how Dragonfire made that connection. After hearing that announcement, IB Kaghun, spokesman for Blew Bayou was heard to be saying something about Tianjin Chemical when the company attorney, Charlene Matlock pulled him away from the dias.

China Water Treatment, a US subsidiary of Tianjin Chemical, announced today that they also had acrylamide available for shipment from its terminal in New Orleans.

CAUTIONARY NOTE: This is a future news story –

Tuesday, December 31, 2019

Acrylic Acid Explosion the Result of Cyber Attack


Daniel Varg, the spokesman for Agency for Chemical and Environmental Security (ACES) announced at a news conference today that last week’s explosion and fire was apparently due to a deliberate cyber attack on the control systems at the Blew Bayou Chemical facility outside of Baton Rouge. The plant produces acrylic acid, acrylamide and other associated polymers. Varg reported that both the ECS-CERT and the Federal Bureau of Inquiry are now participating in the ACES investigation.

Johnathan Quest, the FBI spokesman was asked why the agency was not leading the investigation since it was now about a criminal act. He noted that ACES investigators had been on-site for almost a week now and were more familiar with the hazards associated with working around a chemical incident of this sort. Immanuel C. Securitage from ECS-CERT added that his agency had a recent history of working closely with both organizations and the teams were working well together.

Varg reported that the ACES investigators had determined that the initial explosion at the facility took place in one of the 50,000 gallon storage tanks in an enclosed tank farm building. The reason for the explosion was that an exothermic reaction had taken place in the tank when nitrogen had somehow been substituted for an air sparge in the tank. Daniel noted that with the nitrogen displacing the dissolved oxygen in the tank the inhibitor in the acrylic acid no longer functioned to stop the polymerization reaction. The liquid expansion due to heat and polymerization caused the tank to burst, damaging several adjacent acrylic acid tanks. The subsequent fire and explosion in the storage tank building resulted when acrylic acid fumes were ignited in an apparently improperly secured control panel.

Securitage explained that the cyber portion of the attack is what caused the nitrogen sparge. Their investigators looking at the data historian logs for the facility found that a number of valves had been opened by an unknown attacker allowing nitrogen to be routed to the air sparge line via an empty vessel in an adjacent part of the facility that had both types of lines feeding the vessel.

When asked if this was the result of poor design, Varg told reporters that there was check valve in the air line to that vessel, but it was not functioning properly and was scheduled to be replaced before the plant started operations after the holidays. IC Securitage told reporters that the attacker would have had to have detailed knowledge about the facility engineering to have determined what valves to open to achieve the nitrogen sparge of the tank. He did note that there was evidence that an attacker had been in the control system network for months before the attack happened.

Varg also reported that the explosion that caused the injuries to the three responding fire fighters took place in an acrylamide transfer line near where they were standing. There should not have been a significant amount of acrylamide in that line, but it was full and that was also probably a result of the cyber attack on the facility. As the line was heated by the nearby fires the acrylamide started to polymerize and the combined heat for the fire caused the water in the acrylamide to turn to steam and rupture the line. All three fire fighters were expected to recover.

In a separate announcement earlier in the day, Issac B Kaghun, a spokesman for Blew Bayou Chemical, reported that it would be months before the company could resume shipment of acrylic acid from the facility. As a result, the company was declaring force majeure on their acrylic acid contracts. In light of today’s announcement by the FBI and Blew Bayou’s earlier law suit against Parish Chemical, there may be objections to that claim.

In related news, Tianjin Chemical’s American subsidiary China Water Treatment, announced that it currently had a surplus of acrylic acid in its terminal in New Orleans and was looking to take on new customers. Kaghun reportedly had unprintable comments about the offer at the end of today’s news conference, noting that Tianjin was a disreputable supplier with numerous quality control issues. He did acknowledge that even before last week’s incident, that the domestic acrylic acid supply in this country was tight.

CAUTIONARY NOTE: This is a future news story –

Friday, December 27, 2019

Multiple Chemical Company Systems Hacked


Cybersecurity Agency (CSA) announced today that it had discovered an advanced persistent attack targeted at chemical manufacturing facilities in the United States. Ida Long explained that at least fourteen chemical facilities from three separate companies have had their corporate computer systems and chemical control systems compromised in the last couple of months. The attacks have been accomplished by a new cyber attack group being called ChemStat by the CSA. ChemStat may be associated with the Chinese government according to Long.

Long reported that the CSA had been monitoring email systems for a large number of chemical facilities for the last six months. The attacks had started as targeted phishing attacks with emails being sent to control systems engineers and technicians at twenty different chemical facilities that CSA had been monitoring. The emails were purportedly from control system suppliers announcing new control system software and upgrades that were available.

Links in the email took people who clicked on the links to look-alike web sites where sophisticated software compromised the systems of those visiting the site. The attackers then used those compromised machines to pivot into both the corporate IT network and the facility’s control system networks.

When asked if the companies involved knew that CSA was monitoring their email systems, Long responded that since the monitoring was not being done from corporate resources, CSA was not required to inform the companies that their systems were under surveillance. CSA was operating these monitoring efforts as part of a congressional mandate to be more proactive in defending critical infrastructure system from nation-state attacks. Long assured reporters that CSA was not reading all of the emails, just those that appeared to contain phishing attacks.

Long would not confirm what other critical infrastructure sectors were being monitored in the same way.

Immanuel C. Securitage confirmed that ECS-CERT was the lead agency looking at the control system infiltration at the affected plants. He noted that the longest any system had been affected was 30-days and that ECS-CERT had not found any indications that anything beyond data exfiltration had been done on those systems.

Securitage did note that once ECS-CERT had become involved in the process, they immediately notified the affected facilities had had their control systems compromised and worked with them to identify the limits of that compromise and restore all systems to their prior condition.

He did explain that his group was not allowed to tell the affected facilities how they had become aware of the control system compromise. ECS-CERT had not become aware until todays press conference that the IT systems at the companies had also been compromised.

CAUTIONARY NOTE: This is a future news story –

Friday, October 4, 2019

Stolen Army NKE Round Used in Cyber Attack


The Federal Bureau of Inquiry’s Johnathan Quest today confirmed that investigators had found a 157mm artillery shell inside the boundary fence of NACL Industries, the site of last week’s massive chlorine release outside of Blew Bayou, LA. He refused to confirm that it was one of the US Army’s new NKE (non-kinetic effects) rounds that had been stolen from an Army munitions dump in Poland. Quest was responding to a reporter’s question about claims from SFINCTER that it had used such a munition in their cyberattack on the facility.

Earlier in the day an internet announcement from Students for Immediate Neutralization of Chlorine Technology and Energy Reversion (SFINCTER) claimed that the organization was responsible for the theft and employment of the munition. They claim to have used the advanced cyber-tools and communications protocols contained in the shells electronic core to take over the facility’s control system and disable the automated safety systems in place to initiate the attack.

Anonymous Army sources commenting without authorization confirmed that four of the NKE projectiles had been stolen last month from the munition depot outside of Triblinka, Poland. The Army had just started forward deploying the munitions six months ago. The Army officially has not commented on either the reported theft or the use of the munition in Louisiana.

Dade Murphy from Dragonfire told this reporter that the Army’s NKE round was just a delivery system for a sophisticated cyberattack tool. It included a radio frequency receiver/transmitter to pick up signals from industrial control systems and send hacking signals back to those systems. He noted that the impressive AI chip employed in the system could be preprogramed with a desired outcome for an attack and the onboard processors would find a way into the system employing known vulnerabilities and implement system changes necessary to achieve the desired outcome. Murphy denied that Dragonfire had anything to do with the development of the NKE system or the underlying AI chip.

Murphy did note that he thought that the Army had required the developer to include a safety mechanism in the round that would not allow the processor to turn on until it had been fired from an artillery piece. That safety mechanism should have prevented this type of attack where the munition was emplaced by hand rather than fired into the installation. Murphy acknowledged that such a safety device could probably be hacked.

CAUTIONARY NOTE: This is a future news story –