Wednesday, June 29, 2022

Trucking Company Gas Pump Hackers

The Federal Bureau of Inquiry raided the headquarters of Red Ball Express Trucking this morning, arresting the CEO, Budd Boetticher, and the CIO, Taffy Smith. Police from Delano, GA assisted the operation by executing arrest warrants for sixteen truck drivers employed by the company. According to Johnathan Quest, FBI spokesperson, this combined operation was in response to a month’s long investigation into the ongoing theft of diesel fuel from the Flying A Fuel Stops chain.

Andrew Mellon, spokesperson for the Flying A chain, the company has been having large shortages of fuel at each of their truck stops located along highways across the southern tier of the United States over the last year. “More fuel was being pumped each day than sales were being recorded,” Mellon told reporters; “An internal investigation led to the detention of a driver from Red Ball who had a device that allowed him to steal about 30 gallons of diesel during a routine fill-up at one of our pumps.”

That driver cooperated with the FBI, providing information that was the basis for the search warrant and arrest warrants executed this morning. “The driver told us that each Red Ball truck was provided with a Wi-Fi device that allowed them to take 30 gallons of fuel before the pump started registering the sale,” Quest told reporters.

ECS-CERT is cooperating with the FBI’s investigation. Immanuel C. Securitage told reporters that the devices communicated with the local station system via Wi-Fi. “No hacking was done by the drivers, the corporate fuel systems had previously been compromised,” Securitage explained, “We are still trying to determine how that system was initially attacked.”

Mellon told reporters that over the last year the company had about 100,000 gallons of diesel fuel stollen, 30-gallons at a time. “The rise in fuel prices over that time period have made this a very costly theft and we are not sure that this is covered by our cyber insurance policy.” Mellon said.

CAUTIONARY NOTE: This is a future news story –

Wednesday, May 11, 2022

Sewer Detector Attack Responsible for COVID Lockdown

The Chinese news agency Zhōngguó Xīnwén (ZX) announced today that the recent shutdown of port facilities in Shanghai was due to a cyber attack on computer systems being used to monitor COVID-19 infections. COVID detectors in the Shanghai sewer system reported positive detection of COVID in the neighborhood where most port workers were housed last month. As part of the Chinese zero-COVID policy, the neighborhood was put into 100% lockdown, and port operations had to be shutdown.

Lin Piao, spokesperson for the Shanghai Medical Directorate, told ZX that the Chinese government had started installing electronic detectors for COVID in the wastewater systems in Shanghai as a method for more precisely targeting the lockdowns that the government was using to counter the COVID-19 pandemic. “When these detectors report the presence of COVID-19 antigens in the sewer outflow of a district,” Lin Piao was reported to have said: “We know for certain that there are individuals in that district who have been infected with the disease.”

The ZX news report does not name the source for the cyberattack, but it does note that a Chinese Army cybersecurity unit is investigating the attack. This would typically mean that the government felt that there was a possibility that the attack could have been initiated by a foreign power.

The COVID sewer detectors were developed by scientists at the Tsinghua University in Beijing. The Chinese government has been deploying these sensors in sewer systems in large cities throughout the country as a way to effectively fight the COVID pandemic while reducing the economic cost of pandemic lockdowns.

CAUTIONARY NOTE: This is a future news story –

Thursday, March 3, 2022

US Cyber Firm Providing Cyber Warfare Support to Ukraine

The Department of Justice announced today that they had completed their investigation of the Russian claims of hackers in the United States conducting cyberattacks on Russian railroad. “All of the names provided by Russian Ministry of Justice (Minyust) are employees of Red Cyberteers, a company registered in Austin, TX.,” DOJ spokesperson Della Street told reporters this morning; “We have found no evidence of criminal activity by the personnel identified by Minyust.”

According to a press release from Red Cyberteers, the company is providing cyber warfare support to the government of Ukraine through the Ukrainian Consulate in Dallas, TX. Personnel operating on this contract are working through servers located in the Consulate. Reed Fleming, CEO of Red Cyberteers, confirmed that the cyber warfare operations included interfering with the operation of certain railroads in Western Russia.

Neither the Consulate in Dallas, nor the Ukrainian Embassy in Washington were willing to discuss the operations be conducted by Red Cyberteers. The Embassy did release a statement that in response to the Russian invasion of the Ukraine, the Ukrainian government was taking all available legal measures to counter the illegal Russian military incursion into their country.

A lawyer from DOJ speaking on background said that while the federal government has long rejected the issuance of letters of marque and reprisals in naval matters, there have been no laws or conventions that would prevent it from providing authority to private sector individuals for conducting cyberattacks on enemies of this country in the event of war. The lawyer explained that the main concern about the use of naval privateers has long been the lack of control over the actions of these ships under the guise of letters of marque. Stricter control of cyber operations under such grants could allow the government to conclude that such ‘cyber privateer’ activities would be an acceptable method of executing cyberattacks on our enemies. The briefer reminded the audience that the United States was no currently at war with anyone and the Federal government has not been accused of issuing any letters of cyber marque.

Fleming confirmed that Ukrainian military officers oversaw all aspects of the cyber operations being conducted by Red Cyberteers employees. “Additionally, I insisted that our contract with Ukraine specifies that we will not accept any orders to, or conduct operations designed to, kill people,” Reed said; “We are civilian employees of the Ukrainian government, working on property that is internationally recognized as territory of Ukraine, against an adversary that is conducting offensive military operations on Ukrainian soil. In short, there is no reason to consider us to be cybercriminals, and the DOJ has clearly indicated that they agree with that assessment.”

The Russian Embassy in Washington refused to provide a comment on this story.

CAUTIONARY NOTE: This is a future news story –

Monday, February 28, 2022

Russian Ministry of Justice Requests DOJ Assistance

The Department of Justice announced today that it had received a request for assistance from the Russian Ministry of Justice (Minyust) to help them identify and apprehend the hackers who have recently been attacking railroad operations in western Russian and Belarus. According to news reports in Russia, there have been cyberattacks on the railroad system that have caused intermittent shutdowns of rail traffic throughout western Russia and Belarus since last Thursday.

Della Street, spokes person for DOJ, told reporters this morning that the Attorney General was considering the request because of recent Minyust actions against Russian cybercriminals who have been conducting ransomware attacks against organizations in the United States and Europe. “We are talking with our allies in the region about this request.”

According to Nikolai Krylenko, Minyust spokesperson, the cyberattacks have disrupted key freight and passenger services thoughout Western Russia. “Our government is concerned that this criminal activity is harming the free movement of our citizens and hampering distribution of key materials throughout the region,” Krylenko said in a statement released this morning in New York.

The Free Ukraine Cyber Kollective against Russian has claimed responsibility for cyberattacks against the Russian military. A report on their web site, which was taken offline this morning, noted that they had delayed movement of military supplies and personnel to the border region with the Ukraine.

Rep. Harvey Milk (D,CA) told reporters that, while he has concerns about the use of cyber attacks against critical infrastructure any where in the world, the actions of the Kollective do not appear to be as concerning since they have been made in response to the Russian attack against the Ukraine. He said that he will be introducing legislation today prohibiting DOJ from taking any action against civilians that undertake cyberattacks against foreign military invasions of free countries. “We have a long history, reaching back to World War I, of civilians joining military action against oppressors in Europe before the United States government joins the fray,” Milk told reporters.

CAUTIONARY NOTE: This is a future news story –

 

Thursday, February 24, 2022

Russians Selling Access to Critical Infrastructure on Dark Web

Dragonfire Cyber released a brief report today concerning recent offerings on the Dark Web for access to critical infrastructure computer systems. They report that the Zhukov Brigade, a Russian hackers collective sometimes loosely associated with the Russian military, had posted a long list of organizations in Europe and the United States that it had proven access to computer networks. Exclusive access was being offered to those systems individually or in related groups.

Maskirovka, the frequent spokesperson for the Zhukov Brigade on these Dark Web sites, reports that the access being sold is sufficient to allow ransomware attacks on the systems without the need for additional exploit tools. Access is being offered for 1BTC (about $35,000) and 10% of ransomware proceeds.

Dade Murphy, CTO of Dragonfire Cyber, told reporters this morning that the list of organizations includes public sector and private sector systems in power generation and transmission, ports, railroads and airports throughout the United States and Europe. “We have notified each of the organizations listed, as well as cybersecurity organizations in the respective governments,” Murphy said.

When asked if this appeared to be related to last night's invasion of the Ukraine by Russia, Dade replied: “We do not know. The Zhukov Brigade is not an agency of the Russian government, but they have been employed by the Russian military for some specific hacking operations that we know of.

General Turgidson, Director of the National Critical Infrastructure Security Operations Center (CI-SOC), was asked about the report at this morning’s CI-SOC briefing, he told reporters that they had received advanced notice of the information from Dragonfire Cyber. “We have a close working relationship with Dade and his outstanding crew,” The General explained; “And we continue to work with them to address any potential threats to organizations in this country.”

When asked about rumors of government agencies buying up the access rights on the Dark Web sites, Turgidson laughed and said: “We do not have budget authority for that type of operation. Besides, I do not think that the Zhukov Group would be interested in selling us that access.” When asked if any intelligence agency might have the necessary authority, the General replied: “No comment.”

CAUTIONARY NOTE: This is a future news story –

Wednesday, February 23, 2022

Insulin Pump Hack Discovers Dosing Errors

Medical device software expert FrediG announced today at BlackCap Europe that he had found a calculation error in the GerateSoft application that he uses with the Robotron IPumpe insulin pump that he used to control his blood sugar levels. The pump routinely administered 0.5% more insulin than was necessary to keep his blood sugar levels at target levels. As a result, his blood sugar levels over the last six months have routinely been on the low end of the target range for the treatment of his Type 1 diabetes.

Robotron spokesperson, Erich Mielke, told reporters at a news conference at the conference that FrediG had disclosed the problem to Robotron last week, and that Robotron was recommending that the users of its IPumpe stop using the GerateSoft application. “We are very concerned that the application is incorrectly dosing patients using our device,” Mileke said; “But we are even more concerned that it appears that this dosing error may be deliberate.”

That unusual comment by Mielke was based on a claim by FrediG that the application used two different calculation formulas, depending on which account was used. FrediG reported in his talk today that the equations used when the default account on the application was being used was the industry standard calculation. The default account would be expected to be used by regulatory agencies and companies like Robotron when testing the application.

Users are specifically warned by GerateSoft not to use the default account to protect their privacy. But when users set up their own unique account on the App, a different equation is used to calculate the insulin dosage. That calculation produces a dose that is 0.5% higher than the industry standard equation.

GerateSoft tried to get a German Court to stop FrediG’s presentation claiming that he had accessed GerateSoft’s system without permission, but lawyers for Robotron told the Court that FrediG had been a registered member of Robotron’s vulnerability discovery program and access to GerateSoft’s application was covered by that program.

Mielke noted that FrediG had reported vulnerabilities in a number of Robotron’s devices over the last two years, including a vulnerable version of OpenSSL used in the IPumpe that Robotron reported and corrected last summer.

CAUTIONARY NOTE: This is a future news story –

Monday, February 14, 2022

EF-1 Charging Stations Hacked Again

The San Francisco Transit Authority (SFTA) announced today that hackers were stealing electricity from the enroute charging stations for the City’s new electric bus fleet. The electric costs for the new charging stations were five times higher than expected during the first six months of operation according to a report released today by the SFTA. Johan Muir, a spokesperson for the SFTA reported that the federal grant supporting the e-charging system would only last another three months at this rate.

Brewster Zenneck, the Director of the City’s SF eBus System, explained this morning that the innovative new electric transit bus system was able to use smaller, lighter batteries to power their new busses because the city had installed cordless power charging stations at about half of the bus stops used by the new vehicles. This means that the busses could partially recharge their batteries while unloading and loading passengers.

Zenneck explained that the system uses inductive charging plates built into to road at the bus stop. When a bus stopped to pickup passengers, a device on the bus would signal the charging system to turn on and then turn off when the bus pulled away. The high-powered charging system would be able to provide enough electricity to the vehicles batteries to allow it to reach the next powered bus stop.

According to an article in last week’s Democratic Press, an alternative new site, not long after the EF-1 charging system was installed a free application appeared on some alternate power web sites that would operate the charging stations. These apps would allow users to charge electric vehicles equipped with cordless charging systems while parked on or near the bus stops. Other apps soon appeared that would allow cordless charging of smaller devices, including cell phones from the vehicle charging system.

Zenneck confirmed that the appearance of the apps had taken the SFTA by surprise. They were enabled by the hard-coded credentials used by the busses to control the charging stations. Once the SFTA had become aware of the problem they had worked with Robotron, the supplier of the EF-1 charging system, to update the system software to provide for unique passwords for each city vehicle that used the system.

Updates for the apps soon appeared on scene that were able to steal passwords from the vehicles when they powered on the system. Zenneck said that the SFTA was working with Robotron to solve that problem.

CAUTIONARY NOTE: This is a future news story –