FPL wind turbine hack a hoax

Not all reports of cyber incidents are real. Sometimes they turn out to be a hoax.

04/26/2011


Not all reports of cyber incidents are real. Sometimes they turn out to be a hoax.
That is what happened Saturday, April 16th, around 11 a.m. EDT when the Repository for Industrial Security Incidents (RISI) received the following email:

Subject: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

Message: Here comes my revenge for illegitimate firing from Florida Power & Light Company (FPL) … ain’t nothing you can do with it, since NM electricity is turned off !!! In some days this people will know about FLP SCADA security, here is it for you …. Secure SCADA better! Leaked files are attached

With that email message the person attached eight image files of various HMI screens, a Windows Explorer view of computer files and what appear to be views of a maintenance management/work order system. Also attached was a dump of the configuration from a Cisco router with addresses that are part of the Florida Power and Light assigned address space.

The same email was also sent to the seclists.org/fulldisclosure list, so you can view the files.

Since it appeared that the writer was referring to FPL’s New Mexico Wind Energy Center, John Cusimano, the Director of RISI, immediately contacted the ICS-CERT and the New Mexico CERT with the information. The CISO of FPL subsequently contacted Cusimano Sunday morning, informing him the whole event was a hoax.

In investigating this further, most, if not all of the incident was a hoax and an attempt to embarrass FPL, said Eric Byres, chief technology officer at Byres Security. You can tell it was a hoax because the HMI screen shots clearly appear to be samples from a vendor or a student experiment, not real HMI screens from a system the size of the PNM Wind Energy facility.

They also show a SINAMIC 120, which is a drive controller from Siemens and not something one would associate with a wind farm. One final clue is the idea the alarm text in the HMI shots are in German, not the usual language for a facility in New Mexico.

As for the maintenance management/work order system screen shots, these all appear to be from September 2009 from an unrelated FPL facility located in Seabrook Station in New Hampshire.

The router ACLs and the Windows Explorer view of the computer files are the only potentially convincing items in the collection. They did confirm the IP addresses were FPL’s in New Mexico.

For a more complete report, click here for Byres’ report.



No comments
The Engineers' Choice Awards highlight some of the best new control, instrumentation and automation products as chosen by...
Each year, a panel of Control Engineering editors and industry expert judges select the System Integrator of the Year Award winners.
Control Engineering Leaders Under 40 identifies and gives recognition to young engineers who...
Learn more about methods used to ensure that the integration between the safety system and the process control...
Adding industrial toughness and reliability to Ethernet eGuide
Technological advances like multiple-in-multiple-out (MIMO) transmitting and receiving
Big plans for small nuclear reactors: Simpler, safer control designs; Smarter manufacturing; Industrial cloud; Mobile HMI; Controls convergence
Virtualization advice: 4 ways splitting servers can help manufacturing; Efficient motion controls; Fill the brain drain; Learn from the HART Plant of the Year
Two sides to process safety: Combining human and technical factors in your program; Preparing HMI graphics for migrations; Mechatronics and safety; Engineers' Choice Awards
The Ask Control Engineering blog covers all aspects of automation, including motors, drives, sensors, motion control, machine control, and embedded systems.
Join this ongoing discussion of machine guarding topics, including solutions assessments, regulatory compliance, gap analysis...
News and comments from Control Engineering process industries editor, Peter Welander.
IMS Research, recently acquired by IHS Inc., is a leading independent supplier of market research and consultancy to the global electronics industry.
This is a blog from the trenches – written by engineers who are implementing and upgrading control systems every day across every industry.
Anthony Baker is a fictitious aggregation of experts from Callisto Integration, providing manufacturing consulting and systems integration.
Integrator Guide

Integrator Guide

Search the online Automation Integrator Guide
 

Create New Listing

Visit the System Integrators page to view past winners of Control Engineering's System Integrator of the Year Award and learn how to enter the competition. You will also find more information on system integrators and Control System Integrators Association.

Case Study Database

Case Study Database

Get more exposure for your case study by uploading it to the Control Engineering case study database, where end-users can identify relevant solutions and explore what the experts are doing to effectively implement a variety of technology and productivity related projects.

These case studies provide examples of how knowledgeable solution providers have used technology, processes and people to create effective and successful implementations in real-world situations. Case studies can be completed by filling out a simple online form where you can outline the project title, abstract, and full story in 1500 words or less; upload photos, videos and a logo.

Click here to visit the Case Study Database and upload your case study.