Two U.S. Power Plants Infected With USB Malware Last Year
January 17, 2013 3:01 PM
Origin of the attacks was not revealed
Illustrating why it might be a good idea to
ban external media
particularly in high-security environments
, the U.S. Industrial Control Systems Cyber Emergency Response Team (ICS-CERT) -- a sub-agency of the U.S. Department of Homeland Security (DHS) -- released a newsletter this week revealing that two power plants in the U.S. suffered malware infections last year thanks to infected thumb drives.
ICS-CERT officials write:
[In the first incident] the malware was discovered when an employee asked company IT staff to inspect his USB drive after experiencing intermittent issues with the drive's operation. The employee routinely used this USB drive for backing up control systems configurations within the control environment.
[During the second incident] a third-party technician used a USB-drive to upload software updates during a scheduled outage for equipment upgrades.
Unknown to the technician, the USB-drive was infected with crimeware.
The infection resulted in downtime for the impacted systems and delayed the plant restart by approximately three weeks.
Most power providers in the U.S. are privately owned, thus the government
does not have the ability to order them what to do
security wise. But in its newsletter it firmly suggests adopting stricter restrictions on external media, commenting, "Such practices will mitigate many issues that could lead to extended system downtime."
A pair of breaches at U.S. power plants in 2012 via USB sticks, highlight the growing danger to the U.S. power grid. [Image Source: Reuters]
The U.S. federal government knows a think or two about the dangers of external media and writeable media. In 2008, the Pentagon suffered a major cyberattack that
originated from a single USB stick
plugged into a secured system. The malware, believed to have originated in Russia, quickly spread, compromising systems.
And in perhaps the most severe data loss incident in U.S. history, U.S. SPC Bradley Manning, a low-ranking U.S. Army Officer downloaded hundreds of thousands of classified documents and burned them to a CD-RW. He then allegedly
passed the documents to
, a site that has fixated on publishing supposedly "incriminating" material on the U.S. government.
The recent report on the power plant hacks did not mention where the malware appeared to originate from or the extent of the compromise. The specific malware used in each intrusion was also not revealed.
Chinese university researchers have published information suggesting an attack scheme in which malware is planted on power plant systems, only to be activated at a later date
causing catastrophic failures of the power grid
, crippling the nation a war scenario. In 2011 there was an alleged security breach
at a wind power facility
in the U.S., but that was believed to be the work of a disgruntled employee.
“And I don't know why [Apple is] acting like it’s superior. I don't even get it. What are they trying to say?” -- Bill Gates on the Mac ads
6 Common-Sense Security Measures Every Business Should Adopt
December 27, 2012, 8:45 AM
U.S., Britain Doing Little to Protect Power, Gas, Water From Cyberattacks
April 19, 2011, 9:28 AM
Anonymous Hacker Threatens System Security Breach at U.S. Wind Facility
April 19, 2011, 8:36 AM
Whitelisting: Ban Those "Naughty" Devices and Beef up Security
December 14, 2010, 12:17 PM
USB Stick Led to Worst Cyber Attack on U.S. Military; Russia Suspected
August 26, 2010, 9:57 AM
PIQ ROBOTTM reveals its new artificial intelligence software
November 29, 2016, 12:59 AM
One more time - Happy Thanksgiving to Everyone Around the World
November 24, 2016, 4:00 AM
Google’s Smart Contact Lens Project gets halted for 2016
November 20, 2016, 7:00 AM
Cell Research Study shows African Americans have greater immune response to infection
November 10, 2016, 1:00 AM
UTHealth Clinical Trial Shows Progress Using Stem Cells to Treat Traumatic Brain Injury
November 8, 2016, 1:00 AM
Uber Partners with Circulation to Pilot Program Connecting Transportation and Digital Health Care
November 6, 2016, 5:00 AM
Most Popular Articles
What is the Apple’s iPhone 8 specifications and release date?
April 14, 2017, 5:43 AM
Meet the Smartphone with four cameras - Alcatel Flashphone
April 5, 2017, 11:20 AM
Vivo V5 Plus – the Selfie Softlight is on You.
April 17, 2017, 7:05 AM
Moto G4 Plus - Powerful Unlocked Convenience
April 12, 2017, 6:25 AM
Microsoft releases details of Project Scorpio console
April 7, 2017, 7:50 AM
Latest Blog Posts
Sound Bars and the Costs?
Apr 23, 2017, 6:30 AM
Link your Brain to Your Computer – In Four Years…Maybe
Apr 22, 2017, 7:03 AM
Google Home can now identify users by their voice.
Apr 21, 2017, 7:15 AM
Amazon Lex – Now Available for Developers.
Apr 20, 2017, 6:58 AM
You can now use Instagram offline on your Android Smartphone
Apr 19, 2017, 8:00 AM
Now you can livestream to YouTube from your mobile device.
Apr 18, 2017, 8:05 AM
Google Home – Is It a Spy Device?
Apr 17, 2017, 7:30 AM
Apple added to self –driving test permit list
Apr 15, 2017, 6:21 AM
Project Scorpio – Coming on June 11
Apr 14, 2017, 6:20 AM
Looks Like Samsung Has Been Forgiven.
Apr 13, 2017, 6:50 AM
United Airlines - Blasted on China’s Social Network and the Stock Market
Apr 12, 2017, 6:50 AM
Amazon's Third-Party Sellers Hacked
Apr 11, 2017, 6:25 AM
Microsoft Surface Pro5 Details Revealed
Apr 9, 2017, 6:41 AM
Own An Android Phone? Then you could be hacked over Wi-FI
Apr 7, 2017, 6:47 AM
Apple confirms iOS 10.3 bug and its effect on iCloud Services
Apr 6, 2017, 6:30 AM
Apple Rolls Out New Version of Apple Music
Apr 5, 2017, 10:35 AM
Apple in the News
Apr 4, 2017, 9:03 AM
Apple iPhones Will Soon Feature Graphics Chips Designed BY Apple
Apr 3, 2017, 6:23 AM
AMD Ryzen Desktop Processors Performance
Apr 2, 2017, 6:30 AM
What makes a camera Lensless?
Apr 1, 2017, 7:45 AM
Google halts Android Wear 2.0 Update Due to Bug
Mar 31, 2017, 7:27 AM
Uber Technologies Inc Driverless Car hit by Human-driver
Mar 30, 2017, 8:00 AM
More Blog Posts
Copyright 2017 DailyTech LLC. -
Terms, Conditions & Privacy Information