Thursday, February 2, 2023

Multiple Ransomware Attacks on Artillery Contractors

The Defense Armaments Agency announced today that production of 155mm artillery shells at Blackshear Arsenal in Georgia has been halted for two weeks due to multiple ransomware attacks on subcontractors supply parts for the high-tech munitions that are being consumed in high number in the Ukraine. “We are unable to obtain component parts for the fuses and attitude control systems because various manufacturers have had production interruptions due to cyberattacks on manufacturing facilities,” Samuel C Robinson, spokesperson for the Agency, told reporters this morning.

The Federal Bureau of Inquiry is the lead agency in the investigation because the facilities are not directly contracted by the Department of Defense. According to Johnathan Quest, FBI spokesperson, the companies involved provide parts to component manufacturers that supply the Blackshear Arsenal. “In most cases, the initial set of attacks were being investigated by State and local authorities as routine ransomware attacks,” Quest explained.

General Turgidson, Director of the National Critical Infrastructure Security Operations Center (CI-SOC) which is supporting the investigation, it was not until Blackshear reported supply interruptions of multiple contractors that national level interest was focused on the investigation. “For the most part, these are small businesses using highly-automated manufacturing systems to provide small volume, high-tech components for these ammunition components,” Turgidson explained.

“It looked like these were simply ransomware attacks on random organization when we first started receiving reports form our suppliers” Blackshear spokesperson George Forno told reporters; “When we started receiving reports of damaged control systems after ransoms were paid, it became apparent that this was something more organized.”

“We are still not convinced that this is a centrally directed effort,” Quest responded. The FBI has isolated four different ransomware programs associated with known criminal groups from Russia, North Korea, Iran and Nigeria.

CI-SOC had determined that there have been some indicators that some unknown actor is providing corporate access data to known ransomware groups. “While most of these small businesses do not have significant cyber defenses due to a lack of cybersecurity personnel, there have been at least two of the facilities have been supported by the CI-SOC,” Turgidson explained; “Access to those systems took a level of sophistication not normally associated with criminal organizations.”

A technician at CI-SOC that is not authorized to talk to the press has told me that a number of cybersecurity and industrial control system companies are working closely with CI-SOC, the FBI and the affected facilities in a coordinated effort to get them back on line. Turgidson confirmed that this is an all-hands effort. “We cannot afford to allow production at Blackshear to remain idle while our allies in Ukraine are preparing for an expected Russian offensive. They need these 155mm shells.”

CAUTIONARY NOTE: This is a future news story –

Thursday, January 26, 2023

Liability for Known Vulnerabilities Bill Introduced

Rep Mark Sloan (R,CA) introduced the Liability for Known Vulnerabilities Act today. The bill would make manufacturers of computer controlled equipment used in hospitals and schools financially liable for deaths and serious injuries that resulted from cyberattacks on those institutions using vulnerabilities that had been reported to the vendor more than six months before the attack. Sloan’s Los Angeles office says that the bill is a direct response to the attack on the Angels Memorial Hospital earlier this week that killed four people.

The four deaths in the hospital’s intensive care ward occurred when power back up systems failed to restore power to critical medical monitoring systems and medical devices during a power outage caused by local storms. The uninterruptable power system’s (UPS) control system had been breached by an unidentified hacker using vulnerabilities in the SotoPower HMI. Those vulnerabilities had been publicly reported to SotoPower last June by Israeli researchers. SotoPower reported Tuesday that they were still working on fixes for the reported vulnerabilities.

Sloan told reporters that an independent review of the Israeli research confirmed that the three reported vulnerabilities, including a path traversal vulnerability and a hard-coded credential vulnerability, were relatively easy to fix. “Security researchers looking at this week’s attack reported that those vulnerabilities were used to gain access to the system at Angels Memorial,” the Congressman explained, “Those basic vulnerabilities should not take six months to correct.”

Sloan’s bill would establish a prima facie case for product liability in any case where a cyber attack at a school or hospital resulted in deaths or serious injuries and the attack was facilitated by vulnerabilities that had been identified more than six months earlier.

CAUTIONARY NOTE: This is a future news story –

Tuesday, January 24, 2023

Hospital Deaths Due to UPS Hack

The Angels Memorial Hospital in Los Angeles announced today that three deaths overnight in their intensive care ward were due to cyberattacks on the hospital’s backup power system. A local power outage led to the failure of critical medical devices when the hospital’s UPS systems failed to switch power to the battery backups designed to take over in the event of local grid failures. The hospital has not released the names of the victims.

The Federal Bureau of Inquiry is investigating the apparent cyberattack that stopped the UPS control system from activating the backup power system. “Potential suspects have not yet been identified,” Johnathan Quest, FBI spokesperson, told reporters this afternoon; “But we are in the very early stages of the investigation.”

SotoPower has been identified as the manufacturer of the uninterruptable power supply system used by Angels Memorial. Jake Hanley, company spokesperson, told reporters in a brief statement that the company was cooperating fully with investigators. “The security of our systems is a high-priority for our company,” Hanley said.

In the early summer of 2022, the Israeli cybersecurity firm, BuddaHack, published a report outlining three vulnerabilities in the SotoPower HMI, the control system used in the medical facility power backup system. Last month the federal ECS-CERT, published an advisory about the same vulnerabilities. “SotoPower did not respond to our coordination efforts about the vulnerabilities reported by BuddaHack,” Immanuel C Securitage told reporters this afternoon. “We have no indication that the vulnerabilities have been addressed.”

Hanley responded to questions about the reported vulnerabilities, “We are continuing to work on remediation efforts,” he said; “Our web site includes instructions to protect systems from outside access.”

Ira Haaretz, a researcher with BuddaHack, told me that the vulnerabilities identified last summer could allow an attacker with access to the hospital network to reprogram the UPS control system. “These access control vulnerabilities provide a relatively low-skilled attacker with the ability to obtain administrative level access,” Haaretz said; “They do not require any significant programing capabilities beyond changing a publicly available URL.”

A wrongful death lawsuit was filed today in Los Angles Superior Court on behalf of one of the families. Details were not available when this article was published.

 

CAUTIONARY NOTE: This is a future news story –

Saturday, December 17, 2022

3 Chlorine Cylinders Stolen by BEC Fraud

Bleichen Chemical Company announced today that three 1-ton chlorine cylinders had been stolen from the company by fraud. “As a result of a business email compromise fraud, unknown parties set up a water treatment account with our company for chlorine supply at an abandoned water treatment plant on the East Side of Delano.” Carl Scheele, the Bleichen Delano Plant Manager told reporters this morning; “We made two deliveries over a three-week period and had a third order loaded on a truck when the FBI notified us that we had been scammed.”

Johnathan Quest, spokesperson for the Federal Bureau of Inquiry, told the news conference that the FBI had been tracking a series of BEC frauds being perpetrated by the same individual. When they intercepted emails from Bleichen about past due bills for the chlorine gas deliveries, they became concerned and contacted the company.

Scheele explained that Bleichen had received a request to set up a new delivery account for an existing food processing customer. “They claimed to be restarting the old Dolly Madison plant here in Delano and needed to get the water treatment plant functioning,” he explained: “They had the corporate account number and the right names on letterhead stationery as well as a legitimate looking email address for the account executive.”

Quest said that the FBI has lost track of the perpetrators and had not yet located their base of operations. “The Delano water facility where the deliveries were made has been cleaned up and re-abandoned.” He said, “We have multiple forensics teams going over the facility, but we have not yet found any useful evidence.”

When asked what the criminals had done with the chlorine gas, Quest replied: “We have found evidence that would seem to indicate that the material had been transferred to 5-lb pressure vessels, probably propane cylinders. We have not been able to identify a commercial purpose for small chlorine containers like this, so we do not know what financial incentives there were to perpetrate this fraud.”

Two 1-ton cylinders had been delivered for the initial order last month. A second order of one cylinder was delivered earlier this month and an empty cylinder was picked up. That means that as much as 2,000-lbs of chlorine gas may have been off-loaded into small cylinders. A technician from Bleichen that has been working with the FBI at the treatment facility told me that: “Propane cylinders are not approved for the storage of liquid chlorine, and there was no evidence of the equipment needed to do a liquid-liquid transfer at the site, so there is no way of telling how much chlorine was transferred to each cylinder. There were lots of them.”

CAUTIONARY NOTE: This is a future news story –


Sunday, December 11, 2022

TSP Fleet Tankers Hacked During Navy Exercise

The US Naval Department confirmed this morning that, during a recent fleet exercise in the South Atlantic, civilian fuel tankers that are part of the new Tanker Security Fleet were hacked by elements of Fleet Cyber Command. “Naval cyber operators conducted active operations against Ulan Master and Torrey Canyon tankers that were providing fuel support during Operation Malvinas;” reported David D. Porter, Naval spokesperson. “Navy personnel were able to take remote control of engines and steerage on both vessels using known vulnerabilities in various systems onboard the vessels.”

Captain Frank F. Fletcher of the Torrey Canyon told reporters: “In 20 years of operations in ocean going tankers I have never seen a ship fail so completely to respond to commands from the Bridge. It was quite disconcerting.”

Captain Na Dae-yong of the Ulsan Master added: “I did not appreciate losing control of my vessel, but hopefully we will be able to ensure that such actions could not be undertaken by an enemy during a wartime operation.”

Owners of the two vessels had been informed prior to their participation in the exercise that cyberattacks would be employed against the two vessels during the exercise to determine their susceptibility to such attacks. “These types of attacks would be expected against fleet assets involved in wartime operations,’ Porter explained; “And we expected that the civilian operators would not be as experienced as active fleet personnel in preparing for or responding to such attacks.”

The Navy plans on sharing the results of these attacks with the owners of the two vessels as well as the other owners of vessels in the TSF. Owners will be able to use the information gleaned from these attacks to upscale the cyber defenses for all of their vessels, a major incentive for owners of other fleet capable tankers to sign up for participation in the Tanker Security Program.

Cpt Berny McCollough, spokesperson for Fleet Cyber Command, refused to comment on reports that CYBERCOM detected another party participating in the exercise. “I cannot confirm or deny public reports that a foreign nation state was receiving information from the two ships.” There have been two reports quoting unofficial comments from naval cyber personnel that communications between the ships and a Chinese server had been detected during the operation. One unnamed Navy Lieutenant has been quoted as saying: “We found communications logs showing that the vessel (referring to Torrey Canyon) had been hacked prior to the start of the exercise and had been reporting vessel position and status to a foreign operator.”

McCollough also refused to comment on reporting by the naval blog, Kings Island, that purported to show tracking information of the maneuvers of the two ships under control of the Navy’s hackers. “We will not discuss operational details about the exercise.” The Kings Island tracking data shows the two tankers conducting right and left 180 degree turns and heading back in the direction from which they came.

 

CAUTIONARY NOTE: This is a future news story – 

Tuesday, December 6, 2022

Pipeline SCADA System Hacked in Texas

Pipeline Safety, Security and Operations Office (PSSOO) announced today that the recent crude oil leak near Tyler, Texas was due to a sophisticated cyberattack on the pipeline control system. “The attackers manipulated valves and pumps to create a local overpressure situation,” Michael E Thane, spokesperson for the PSSOO; “This caused pressure relief systems to open and begin pouring crude oil out at the remote location near the Neches River.”

The pipeline, owned by the Friendly Morning Pipeline Company, apparently started leaking just after sundown and was not stopped until a fisherman reported seeing the crude pouring into the Neches River near his favorite fishing spot the next morning. The sour crude being pumped through the pipeline contained high levels of hydrogen sulfide, a toxic gas. A major fish kill has been reported along a 20-mile stretch of the river.

The National Critical Infrastructure Security Operations Center (CI-SOC) is working with PSSOO and the Federal Bureau of Inquiry and the Texas Environmental Commission to investigate this incident. Local law enforcement has been told that this may be an environmental terrorist attack, but none of the federal agencies involved in the investigation are willing to use the T word publicly.

George Friendly, President and Owner of the affected pipeline company talked with reporters this morning. He noted that the company was using a pipeline SCADA system that was specifically designed for secure monitoring and controlling of pipeline operations. “We worked closely with Albert Foxborough, the founder of Flintstone Tech in his development of their pipeline secure automation system.” Friendly explained.

A source, who must remain nameless because they are not allowed to talk to the press, with the CI-SOC explained that the Flintstone PSAS was a complete supervisory control and data acquisition system that was designed for secure communications between the various parts of the pipeline automation system. “This system was designed in early 2016 before people generally started talking about zero trust systems,” she explained; “And certainly before people started to talk about it in industrial control systems.”

Friendly agreed that the PSAS had a zero trust architecture, but explained that: “Albert started employing what is now called zero trust architecture back in 2015 when he started the design of his new operating system”. Security was built into the operating system as one of the core principles of its design. This meant that there was no need for add on security appliances or applications.

The CI-SOC technician said that Flintstone was recently disbanded when its parent company was sold. “The new owners apparently did not want to offend their customers who were manufacturers and vendors of more conventional control system and security systems.” Flintstone shutdown operations and customer support on very short notice. The last thing the company did was issue a mandatory software upgrade for their systems that effectively reduced the security communications controls of the system.

Friendly told reporters: “We had the most secure pipeline control system the world has seen to prevent just this sort of incident. We had to reduce the security to keep the control system functioning. Now this happens. Where are all of the federal cybersecurity folks now?”

CAUTIONARY NOTE: This is a future news story –


Sunday, October 16, 2022

Car Swatting

The California Highway Patrol is currently investigating three instances of car swatting in the Bay Area this weekend. According to Francis L. Poncherello, CHP spokesperson, the latest incident occurred when a car was stopped in San Francisco at about noon today when a CHP officer noticed an Amber Alert notice on the vehicle digital license plate. Patrol cars from three different jurisdictions participated in the stop of the vehicle. Malcom Reynolds and his wife Jayne were forced from their car at gunpoint and handcuffed before the offices realized that Amber Alert on the tag was part of an ongoing cyber attack on the State’s new RiPlate, digital license plates.

Derrail Book, CEO of Reaver Electronics, explained that the RiPlates produced by his company had included the Amber Alert notice as an option on their digital license plates as a way to help police agencies locate and identify vehicle being used by kidnappers. “We have strong software controls designed into the system that only allow police departments equipped with an RiTerminal to activate the Amber Alert notices on our RiPlates,” Derrail explained; “This weekend’s problem must be due to inadequate administrative controls in local police terminals that can remotely access our plates.”

The first car swatting incident occurred in San Francisco early Saturday morning. A car owned by Congressman Harvey Milk was surrounded by a police tactical squad in the parking garage of the Muir Marriott Hotel. The license plate on the vehicle matched a plate that was reported to be involved in the recent theft of explosive from a construction site in San Mateo on Friday. The Congressman was upstairs receiving an award from the San Francisco Retired Police Organization (SFRPO) for his support for families of police officers wounded in the line of duty. When Milk returned to his car 30-minutes later he found that the trunk and doors had been forced open and the car was undergoing a detailed search for explosives. A digital license plate reader at the Hotel captured a picture of the license plate on the Congressman’s car, it matched the number of the car that was being looked for in the San Mateo case.

In theory, once the Department of Motor Vehicles assigned a license plate number to the RiPlate, it can only be changed by order of the DMV. Reaver Electronics actually makes the change, but only when ordered by the DMV. Book told reporters this morning that there is no record of a change being made to the RiPlate on Milk’s car.

When asked if there could have been a cyber attack on his company’s computer systems, Book replied: “We have very strong cybersecurity controls in place on our corporate networks. We have promised the Governor and the DMV that our systems will not allow unauthorized access to the RiPlates or their supporting technology.”

The National Critical Infrastructure Security Operations Center (CI-SOC) is helping the Highway Patrol investigate these three car swatting incidents. General Buck Turgidson, CI-SOC Director, reminded reporters this afternoon that there is no such thing as an unhackable system. “We have not yet found a hackable vulnerability in the system, but we have just started looking.”

 

CAUTIONARY NOTE: This is a future news story –