CIA admits hackers can control power grid online

happygeek 0 Tallied Votes 345 Views Share

A CIA analyst speaking at the SANS 2008 SCADA and Process Control Summit in New Orleans has admitted that hackers have not only been able to penetrate the power grids of several countries, but also successfully cut power to several cities, all from the relative safety of the Internet.

Central Intelligence Agency analyst Tom Donahue was quick to point out that all the attacks were external to the United States, but not so quick to provide specifics of the incidents. According to reports Donahue claimed the objective was simple criminal extortion rather than being driven by a terrorist agenda. Conference organisers, the SANS Institute, posted a statement by Donahue which stated that "We have information, from multiple regions outside the United States, of cyber intrusions into utilities, followed by extortion demands. In at least one case, the disruption caused a power outage affecting multiple cities. We do not know who executed these attacks or why, but all involved intrusions through the Internet." The SANS Institute added that according to Mr Donahue the CIA "actively and thoroughly considered the benefits and risks of making this information public, and came down on the side of disclosure."

According to Brian Contos, Chief Security Officer at Arcsight which is an active member of all these cybersecurity consortia, there are a whole host of projects underway in the US to ensure that such penetration of national infrastructure utility services is made as difficult as possible:

  • has been created to minimise the opportunity for a cyber attack to severely damage America's oil and gas infrastructure.
  • is a Department of Energy initiative to integrate technologically-advanced controls and cyber-security devices into the electricity grid and energy infrastructure.
  • is bringing together various national organisations to make use of the cross-disciplinary research available to ensure that control systems used in critical national infrastructures are made more resilient to attack and just as importantly allow for a more rapid recovery if any attack proved to be successful.

And finally, the Federal Energy Regulatory Commission (FERC) has approved eight new mandatory critical infrastructure protection (CIP) reliability standards to protect the nation's bulk power system against potential disruptions from cyber security breaches. FERC Chairman Joseph T. Kelliher says it has achieved a milestone "by adopting the first mandatory and enforceable reliability standards that address cyber security concerns on the bulk power system in the United States.The electric industry now can move on to the implementation of the standards in conjunction with improvement of these standards in order to increase the security and reliability of the bulk power system."

The eight CIP reliability standards address the following topics:

  1. Critical Cyber Asset Identification
  2. Security Management Controls
  3. Personnel and Training
  4. Electronic Security Perimeters
  5. Physical Security of Critical Cyber Assets
  6. Systems Security Management
  7. Incident Reporting and Response Planning
  8. Recovery Plans for Critical Cyber Assets

Dani AI

Generated

's post correctly flags the SANS 2008 disclosure that a CIA analyst reported multiple, Internet-based intrusions into utilities and said at least one intrusion preceded a multi-city outage — the agency did not publish operational details or public attribution. (Contemporary coverage is available for verification.) (wired.com)

Technically, causing an outage can mean anything from disabling operator HMIs to issuing legitimate control commands to relays and breakers; experiments and incidents since 2007 show how real those risks are. The 2007 “Aurora” generator test demonstrated how malicious commands can physically destroy plant equipment, and later attacks (notably Ukraine in 2015–2016) show adversaries using commodity and custom tools to open breakers and disrupt service. These are useful reference cases when assessing threat models. (wired.com)

Practical, immediate controls for utility and OT teams (prioritized, implementable actions):

  • Enforce strict network segmentation: separate corporate IT from OT; control and monitor all cross-zone access.
  • Lock down remote access: use jump hosts, multi-factor authentication, and role-based, logged sessions.
  • Harden devices and protocols: remove default accounts, use least-privilege, whitelist permitted commands, and restrict protocol exposure (Modbus/DNP3/IEC protocols).
  • Deploy OT-aware detection and logging, and test incident playbooks that include manual control fallbacks and supplier coordination.
    These controls reflect current ICS/OT guidance and recommended practices. (csrc.nist.gov)

Note: the reply from is off-topic and unrelated spam. Treat public assertions about specific outages or attributions cautiously—intelligence briefings are often deliberately non-specific, and good defensive work starts with verifiable risk assessment, layered controls, and tested response plans rather than headlines. (wired.com)

References (for further reading)

rabbit1840 0 Newbie Poster

Great article! We provide you 20% discount for all packages and services on our website during these days, and will provide more promotion. Besides,we also want to buy gold from you! Every server is OK. In the end, have you imagined that there is power leveling for free before?Now it happens on 12 hours Free!!!
hurry up

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.