Home » Illinois Water Hack Causes Confusion
Illinois Water Hack Causes Confusion
ControlGlobal.com
12/05/2011
Was the tiny Curran-Gardner Townships Public Water District (www.currangardner.com) in downstate Illinois the victim of a foreign-based cyber attack or not? As of press time, that seems to be the question.
What we do know is this: The Illinois Statewide Terrorism and Intelligence Center reported that "Sometime during the day of Nov. 8, 2011, a water district employee noticed problems with a SCADA system. An information technology service and repair company checked the computer logs of the SCADA system, and determined the system had been remotely hacked into from an Internet provider address located in Russia…
"Over a period of 2-3 months, minor glitches have been observed in remote access to the water district's SCADA system. Recently, the SCADA system would power on and off, resulting in the burnout of a water pump."
No motive was given for the attack.
Don Craver, chairman of the Curran-Gardner Water District reported to ABC affiliate, WLS TV, Chicago, that "There's some indication there was a breach of some sort into a software program—the SCADA system—that allows remote access to the wells, and the pumps, and those sorts of things."
According to Joe Weiss, principal at Applied Control Systems and ControlGlobal.com's "Unfettered" security blog, the attackers obtained access to the network with credentials stolen from an unnamed SCADA vendor.
The problem is that the FBI and the DHS both have said that, after investigation, they do not believe such an attack occurred.
However, before anyone assumes that this whole issue is overblown, within days of the Curran-Gardner scare, a home-grown hacker calling himself "pr0f" or "@pr0f_srs" announced that he had hacked into the South Houston Water Utility in Texas, and he posted several screenshots of the system on the Internet.
Pr0f himself went public with the attack and explained his motives clearly—to demonstrate just how insecure such systems are. (Apparently South Houston's system was accessible via a simple, three-letter password.)
He said, "I'd like to go on record and say that the main reason I did what I did yesterday was essentially because I know I am not the only person with an interest in these systems. I also know I am not the only person who has explored them and read up on them. I don't think I am alone in suggesting that the gravity of the problem is more serious than ICS-CERT and similar [sic] are equipped to deal with. I'd love to see some real reform and discussions between the government, manufacturers of ICSs and people who use these systems happening, because there seems to be a huge disconnect between the parties involved."
More News:
- 05/23/2012 MESA, WBF to merging, expanding operations, B2MML focus
- 05/23/2012 IFS acquires mobile field service vendor Metrix LLC
-
05/21/2012
Eaton to Acquire Cooper Industries
Complementary Products and Markets Create Opportunities for Growth in Global Electrical Industr
-
05/15/2012
ISA, Automation Federation and FIRST Championships Inspire Kids to Be Interested in Automation Careers
ISA and the Automation Federation Join FIRST Championship to Talk About Careers in Automation. Meet the 2012 Team Winners
-
05/10/2012
Process Fieldbus Implementation and Operational Aspects Survey
Participate in this survey on process fieldbus selection criteria, installation, and challenges associated with the implementation and operational phase of the technology
-
05/09/2012
Emerson acquires ISE Magtech
Deal Enables Emerson Process Management to Provide Complete Liquid Level Measurement Solutions Across the Process Industry.
-
05/08/2012
Yokogawa to Host Cybersecurity Webcast
Yokogawa Introduces Its Cybersecurity Strategy on Multiple Levels to Prevent Cybercrime
-
05/07/2012
Yokogawa, Sensorex Earn Lloyds and ISO Certifications
Two Process Automation Product and Systems Providers Have Been Tapped by Certification Organizations in Recognition of Their Product and Production Quality
-
05/07/2012
Complimentary Energy Management System Webinar from InduSoft
Explore How Energy Management Systems (EMS) Can Be Created Using InduSoft Web Studio, With Guest Speaker Tom Ellingson of Noble Conservation Solutions!
-
05/07/2012
Attend the SCADA MENA 2012 Summit
Optimize Your Operational Performance Through Advanced SCADA/DCS Applications to Maximize Your Process Control
- All news »
Sponsored Links
Control Digital Edition
Access the entire print issue on-line and be notified each month via e-mail when your new issue is ready for you. Subscribe today.
- Featured White Papers

Print page