News: 1755175508

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Law and water: Russia blamed for US court system break-in and Norwegian dam drama

(2025/08/14)


Russian attackers reportedly spent months rummaging through the US federal court's creaky case-management system, while Norway reckons the same Kremlin-friendly miscreants took control of a dam's controls – a transatlantic double-act in legal files and floodgates.

The attack on Washington's systems, [1]confirmed by the Administrative Office of the United States Courts on August 5, saw attackers break into the US court system's digital filing cabinet where they began rifling through the paperwork.

The CM/ECF platform (and its public-facing cousin PACER) is a patchwork of more than 200 locally run instances, many of them built when Windows XP was still considered cutting-edge, and is used by lawyers to file motions, submit evidence, and upload sensitive case material.

[2]

The intruders reportedly accessed the system via bugs that had been gathering dust since 2020 to make off with sealed documents, witness identities, and even a copy of the court system’s own blueprint, according to reports.

[3]

[4]

On Monday, the New York Times [5]reported that Russia "is at least in part responsible" for the cyberattack, which is said to have been a "years-long effort."

"Some of the searches included midlevel criminal cases in the New York City area and several other jurisdictions, with some cases involving people with Russian and Eastern European surnames," the paper stated.

[6]

US President Donald Trump, when pressed on whether he'd raise the issue with Vladimir Putin during their planned meeting in Alaska, offered the verbal shrug: "I guess I could. Are you surprised?"

Whether the years-long spree was bankrolled by a nation state or just enterprising crooks with time to kill remains unanswered. The US Department of Justice didn't immediately respond to The Register 's questions.

Open the floodgates

Norway's recent encounter with suspected Russian cyber operators was less about stealth and more about spectacle.

In April, Norway said criminals gained access to a digital system to seize control of a dam in Bremanger by holding its valves open for four hours and sending around 500 liters of water per second gushing downstream. That's not enough to wash away a village, but it was enough to show they could, in theory, turn a scenic fjord into an inland sea.

[7]Ex-White House cyber, counter-terrorism guru: Microsoft considers security an annoyance, not a necessity

[8]Kremlin goons caught abusing ISPs to spy on Moscow-based diplomats, Microsoft says

[9]Aeroflot aeroflops over 'IT issues' after attackers claim year-long compromise

[10]UK uncovers novel Microsoft snooping malware, blames and sanctions GRU cyberspies

[11]NCSC says cyber-readiness of UK's critical infrastructure isn't up to scratch

Norway's domestic intelligence agency, PST, is pointing the finger at Moscow for the dam attack, saying the stunt was pure muscle-flexing designed "to cause fear and chaos among the general population," according to [12]local news reports .

Beate Gangås, head of the agency, said: "Over the past year, we have seen a change in activity from pro-Russian cyber actors." She added that the incident at Bremanger was one such activity.

Authorities still haven't singled out which Russian outfit toyed with the Bremanger dam.

[13]

From sealed indictments to spillways, the Kremlin's keyboard warriors appear intent on proving there's no corner of Western infrastructure too obscure to poke. Whether it's a court clerk's login or a dam's control panel, both seem to leak just fine under pressure. ®

Get our [14]Tech Resources



[1] https://www.uscourts.gov/data-news/judiciary-news/2025/08/07/cybersecurity-measures-strengthened-light-attacks-judiciarys-case-management-system

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aJ4IFtJAbqbT_UXxyh5U4gAAAIw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aJ4IFtJAbqbT_UXxyh5U4gAAAIw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aJ4IFtJAbqbT_UXxyh5U4gAAAIw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.nytimes.com/2025/08/12/us/politics/russia-hack-federal-court-system.html

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aJ4IFtJAbqbT_UXxyh5U4gAAAIw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2025/08/08/exwhite_house_cyber_and_counterterrorism/

[8] https://www.theregister.com/2025/07/31/kremlin_goons_caught_abusing_isps/

[9] https://www.theregister.com/2025/07/28/aeroflot_system_compromise/

[10] https://www.theregister.com/2025/07/20/uk_microsoft_snooping_russia/

[11] https://www.theregister.com/2023/11/14/ncsc_cyber_readiness/

[12] https://www.vg.no/nyheter/i/mPJaE4/pst-sjefen-mener-pro-russiske-hackere-sto-bak-cyberangrepet-mot-damanlegget-i-bremanger

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aJ4IFtJAbqbT_UXxyh5U4gAAAIw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



Head meet wall

Kevin Johnston

On what planet was it deemed a good idea to be able to manage the dam controls from outside the facility? I could understand Read-only data to display status at a remote site or similar but the ability to change a valve state?????

Re: Head meet wall

Empire of the Pussycat

If it's in a remote location, especially given Norway's nippy winters, remote control makes sense vs. the alternative of on-site personnel with accommodation etc. etc., or travelling in harsh weather conditions.

Probably cheaper too.

The issue isn't remote control, it's the legacy of pisspoor security in utilities, industrial control etc. that's built up over decades.

@Empire of the Pussycat - Re: Head meet wall

Anonymous Coward

You have to choose between cheap and secure. We all know that.

Re: Head meet wall

Joe Gurman

Control over critical facilities should never involve the public Internet. End of discussion.

from scenic fjord to inland sea

LogicGate

"That's not enough to wash away a village, but it was enough to show they could, in theory, turn a scenic fjord into an inland sea."

I have trouble parsing this sentence.

Norwegian fjords are connected to the ocean (except for misnamed ones like Tyrifjorden).

I fail to see how adding more water to a fjord will somehow break the connection to the ocean and create an inland sea.

Can someone enlighten me?

ChoHag

If your dam[n] control surfaces are available to all and sundry, that's on you.

Dam(n) rite!

RM Myers

"https://discoanon.bandcamp.com/track/dam-rite"

You can not get anything worthwhile done without raising a sweat.
-- The First Law Of Thermodynamics

What ever you want is going to cost a little more than it is worth.
-- The Second Law Of Thermodynamics

You can not win the game, and you are not allowed to stop playing.
-- The Third Law Of Thermodynamics