Critical infrastructure’s long, undefended tail exposed by UK energy attack
BreachA cyberattack that forced a small British electricity generator offline for four days caused no power outage, threatened no part of the national grid, and may not even have been carried out by the Iran-linked hackers initially blamed. But the incident illustrates a consequential weakness in Western critical infrastructure. Thousands of small generators, water systems, and other industrial sites have aging operational technology — exposed programmable logic controllers, cellular modems, remote management systems — connected to the internet without the security programs protecting their larger counterparts, leaving easy targets during a period of geopolitical conflict. British newspapers reported that Iran-linked hackers attacked the unidentified generator in July. The UK government confirmed an incident occurred but has not identified the facility, disclosed what the attackers did, or attributed the attack to Iran. Energy Minister Michael Shanks sought to tamp down some of the more alarming coverage, saying the generator was “tiny” compared with what most people would consider a power plant. The government nevertheless briefed energy executives and began working with regulators and the National Cyber Security Centre to assess the threat and strengthen protections. The limited public information makes it impossible to determine whether the incident was an Iranian operation, an opportunistic intrusion by another actor, or something else entirely. An online persona calling itself APT Iran has denied responsibility. “We don’t have any forensic evidence of what actually happened,” Josh Picolet, VP of detection and S2 threat analysis at Team Cymru, tells CSO. “Without that, you have to assume it was serious enough to take offline.” Phil Tonkin, field CTO at Dragos, tells CSO that the available information nevertheless indicates that the incident involved operational equipment and was similar to attacks targeting programmable logic controllers (PLCs) at US water facilities. But Tonkin cautions that the public account grew more dramatic as it passed among news organizations — evolving from an incident at a small energy facility into reports of an attack on a power plant or gas-fired peaking plant, despite the absence of official information supporting those descriptions. “What we’ve seen reported so far seems to have been a collection of hypotheses being reported and scaling,” he says. From US water systems to UK generator Whatever happened in Britain, it fits a pattern documented more concretely in the United States. The FBI and Environmental Protection Agency said on July 30 that water and wastewater utilities in at least seven states had reported attacks against internet-facing Rockwell Automation MicroLogix 1100 and 1400 PLCs. Attackers changed IP addresses and passwords, causing operators to lose monitoring and control of connected equipment. CISA has since put the campaign’s scale much higher, saying it observed malicious activity targeting more than 100 internet-exposed water-sector systems in July. Sean Tufts, field CTO at Claroty, tells CSO the security firm saw indicators of compromise on roughly 40 to 50 clients in the same campaign, a handful of which require formal incident response. “We’re seeing them hit and have success,” he says. Some attacks caused loss of water pressure and flooding, according to the agencies. At least one victim found altered PLC project files and discrepancies in the ladder logic controlling equipment. The operational consequences varied depending on what the controller managed and whether the facility could switch to manual operation. The government has not formally attributed all of those incidents publicly to Iran. But an earlier multi-agency advisory described Iranian-affiliated actors exploiting exposed PLCs and using configuration software to make malicious changes. The reported number of affected states has also become disputed. APT Iran has acknowledged attacks in fewer states than some media accounts have reported while denying the UK intrusion — a curious combination of claiming some operations and disavowing others. “When we see groups like APT Iran or CyberAv3ngers self-attributing attacks, that doesn’t mean it is the Iranian government,” Tonkin says. “It doesn’t really matter in terms of the defender. The defender needs to know what is vulnerable and how to defend those assets, because anybody can copy these methods.” The ambiguity may itself benefit Iran. Relatively unsophisticated attacks can create headlines, uncertainty, and political pressure without producing the forensic clarity that might prompt a forceful government response. For attackers unable to match the conventional military power of the United States and its allies, cyber operations also offer a comparatively inexpensive way to bring a conflict into an adversary’s home territory. “If you pull it off in a meaningful way, it could be devastating,” Picolet says. The intent, he speculates, could be “to cause harm to your adversaries or maybe break your will” by bringing the fight domestically, even if it remains in cyberspace. For now, the operations have been more disruptive than destructive. Their immediate value may lie in creating anxiety and earning publicity by displaying screenshots of compromised industrial systems. Critical infrastructure’s long tail The more significant commonality between the UK and US incidents is not necessarily the attacker. It’s the target. In both countries, large electric utilities, oil and gas companies, and major manufacturers generally operate under regulations, formal risk-management programs, and security architectures designed to prevent industrial equipment from being placed directly on the public internet. Small municipal water systems, rural cooperatives, and community-owned facilities often have none of those advantages. Their digitization has produced real benefits. An engineer no longer needs to drive to a remote pumping station or generator to inspect its status. A cellular modem and remote-management interface allow equipment to be monitored and adjusted from miles away. The same connection can expose equipment designed decades ago, when its manufacturers never contemplated that it would face internet-based attackers. “The thing that brought the efficiency has made those assets exposed,” Tonkin says. “In smaller organizations, there is no governance to stop an engineer from doing it. Thousands and thousands of very vulnerable devices are connected straight to the internet.” These smaller systems may individually be inconsequential to a national grid or water supply. Collectively, however, they create opportunities for widespread disruption, particularly if an attacker coordinates operations across numerous sites or exploits dependencies among power, water, manufacturing, transportation, and communications providers. Tufts points to Colonial Pipeline as a preview of that dynamic, wherein a ransomware attack on a single company operating one pipeline rippled into fuel shortages well beyond its own customers. “It was interrupting the super majors,” he says. Get PLCs off the public internet — and prepare for manual operation The most urgent protective measures are neither novel nor technically complicated. The FBI and EPA recommend removing PLCs from direct internet exposure and placing remote access behind a monitored gateway. Operators should secure cellular modems, replace default or weak passwords, restrict communications through firewalls or access-control lists, and place physical or software key switches in the run position to prevent unauthorized changes. Facilities should also preserve known-good copies of PLC programs, inspect running logic for alterations, and test their ability to operate equipment manually. Equipment that does not need to be exposed to the internet should be disconnected or placed behind a controlled management interface, Picolet says. Where equipment cannot be disconnected, operators need a tested alternative, he adds. “If you say you can’t turn it off, then you better have a plan to go to manual mode or disable it if an event happens,” Picolet says. Operators should identify exposed systems before an attacker does and make sure employees have practiced switching them into a safe manual state. That can be difficult for small utilities with few employees, limited technical expertise, and budgets funded by local ratepayers. Unlike major power companies, community-owned facilities may lack both a formal risk-management process and the economies of scale needed to build a conventional OT security program. The White House is now preparing a program that would enlist private cybersecurity companies to help water utilities identify and remediate exposed equipment. Larger infrastructure operators have a role as well. Although their CISOs do not directly control the security of a rural water plant or independently owned generator, their organizations may depend on those facilities — or be connected to them physically or digitally. “CISOs and larger organizations can do a lot to think about who they are actually dependent on in their energy supply chain, and how they can bring those partners along,” Tonkin says. He compared the needed approach with the mutual-aid agreements electric utilities use after major storms. Line crews from across the country help restore service in affected areas rather than leaving each utility to cope on its own. “I think there’s a big need for us to do more as a community in cyberspace to address some of these problems, because these smaller entities are very, very difficult to support,” Tonkin says. “They haven’t got the budgets, and they haven’t got the resources.” At the same time, those operators must protect themselves from risks they cannot directly manage, regardless of who the threat actor is. “From a cyber defender standpoint, we don’t care; it could be Martians, it could be Iranians, it could be Americans,” Tufts says. “We need to be better, and if someone’s proving they have these capabilities, then we need to take that warning.”
Read full story at CSO Online →