Someone tried to poison a Florida city by hijacking its water treatment plant via TeamViewer, says sheriff
- Reference: 1612829893
- News link: https://www.theregister.co.uk/2021/02/09/florida_water_hacked/
- Source link:
Pinellas County Sheriff Bob Gualtieri said Oldsmar's water treatment system, which serves roughly 15,000 people, was accessed, presumably over the internet, by someone who had hoped to flood the supply with levels of sodium hydroxide more than 100 times the normal amount.
[1]
The miscreant gained access to remote-control software TeamViewer that was running on a PC at the plant, the sheriff [2]told Reuters, and used that machine to ultimately attempt to jack up the levels of sodium hydroxide.
In small amounts, the chemical – better known as lye – helps raise the pH of the water, reducing its acidity, and minimize the amount of lead and other heavy metals dissolving into the water. In higher concentrations, it can cause, in mild cases, skin and eye irritation; in more severe cases, burns and scarring.
[3]
Fortunately, a staffer who was also working remotely spotted the concentration of the chemical being increased, we're told, and immediately reversed the change. The city's water supply was not affected and the contamination attempt was thwarted.
The cyber-break-in did worry officials enough to call a [4]press conference , where they outlined the information they currently have while stressing that there are other safeguards that would have prevented high levels of sodium hydroxide from entering the main water supply.
It would have taken more than a day for the adulterated water to enter the public’s water system, we're told, during which time the plant would have caught the disparity. “The public was never in danger,” Sheriff Gualtieri said. Remote access on the PC has been disabled.
Investigation
The officials didn’t have a lot of info beyond that, except that they do not have a suspect yet though they do have some leads. There was no specific intelligence as to why Oldsmar’s water supply was targeted, they don’t know if the hacker was based inside or outside the US, and other cities have been told about the hack and advised to check their installations for insecure or poorly secured remote access. Oldsmar’s water treatment plant itself was set up to only allow authorized users to access it remotely, the sheriff insisted.
TeamViewer: So sorry we blamed you after your PC was hacked [5]READ MORE
Here's how it all went down, apparently: an operator logging into a PC at the facility early on Friday morning said he had noticed the system had been accessed but had assumed it was his supervisor and thought nothing of it. Several hours later, however, the same operator lost control of the computer's mouse and watched as it navigated the control software.
Over the course of several minutes, the hacker increased sodium hydroxide from 100 parts per million to 11,100 parts per million and then left. As soon as they had quit, the operator changed it back to the original setting and alerted his supervisor.
“The protocols that we have in place, monitoring protocols, they work – that’s the good news,” said Oldsmar Mayor Eric Seidel. “The important thing is to put everyone on notice. There’s a bad actor out there.”
[6]
The FBI and Secret Service are investigating. ®
Get our [7]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YCIW66eZIaKMZht-VDSC8AAAAJU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.reuters.com/article/us-usa-cyber-florida/hackers-broke-into-florida-towns-water-treatment-plant-attempted-poisoning-sheriff-says-idUSKBN2A82FV
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YCIW66eZIaKMZht-VDSC8AAAAJU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.youtube.com/watch?v=MkXDSOgLQ6M
[5] https://www.theregister.com/2016/06/06/teamviewer_sorry/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YCIW66eZIaKMZht-VDSC8AAAAJU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://whitepapers.theregister.com/
Re: For the love of the wee man
Because ThoseInCharge want to show their friends pretty real-time graphs on their iFads.
Really. That is the only reason.
We tugged on their capes, and were shrugged off. We tapped 'em on the shoulder & were elbowed away. We pulled on their sleeves, and were thrust aside. Some even kissed their boots, and were trodden upon. Our message was always "Please, PLEASE, **PLEASE**!! don't allow the connection of SCADA to publicly available networking systems!"
But did they listen? No. They did not. The idiots.
On the bright side, those of us with a clue are making a pretty penny in our retirement, cleaning up the resulting mess :-)
Not entirely convinced that "their system works", given that the reason they detected it this time was that a local user happened to be watching at the time.
How long would the overdose have to keep running before they could no longer dilute it again without closing the plant temporarily?
If they hadn't watched it happen, would they have actually noticed within that time period?
On the other hand, is the dosing tank large enough to cause a significant problem if totally emptied out?
Eh?
So the local user had opened Team Viewer? For why if they didn't expect remote control to take over?
Or TV is on all the time in which case what was the on-site user looking at if they weren't expecting anything. If they were doing something then the naughty remote person would have quietly tiptoed away until after the end of shift.
It's a long time since I used TV, but doesn't it assume all the current user's privileges? Good for lots of purposes, but surely in a case like this you want a VPN with logs and properly restricted user rights.
If the naughty remote person was a serious hacker won't they have fiddled with the system to give them TV starting say on Monday nights at 9:30? or some other back door? The tone of the statement is that eagle-eyed staff spotted a trivial attempt so 'nothing to see here'. Good for the head's-up, well done for admitting the security failure, well done for having safety nets, but clearly there's other stuff going on and I guess no attempt at catching the NRP.
Internet of Shit
I can imagine a similar scenario at a sewage plant where the things that slowly turn through the sludge are remotely increased to 3000rpm and the surrounding 30 square kilometres gets covered in poop.
Mine's the one with the built-in umbrella.
The wrong software for the job
I know a lot of industrial systems run Windows in some form or another, its because the foundation system that's customized for the particular plant or applciation was built on Windws "becuase it was the best platform avaialable (back in 1992)". Its tolerable but only if you realize that these are not office systems running Office but special purpose systems that won't have frequently patched versions of Windows. Management doesn't understand this -- I long gave up trying to explain why it was necessary to keep an old box with XP on it (specially patched drivers and kernel from manufacturer needed to support weird bit of hardware -- could upgrade, I daresay, but at a huge cost of $$$$$ and learning curve (also $$$$$)).
These systems should never be connected to the Internet. If someone desperately wants to see what they're doing get them a webcam.
For the love of the wee man
Why on earth are critical facilities like this on the internet at all? Previous incidents involved nuclear power and steel mills. Just stop - it's possible.