Cyber security: CIA warns about industry hacking, extortion risks

SANS Institute comments follow on CIA process control and SCADA security presentation.


The CIA doesn’t normally discuss openly what it sees or what it does. So when a cyber security expert wants to speak publicly and for the record about cyber crime threats in the electric utility industry, people listen. Last month, Tom Donahue, the CIA’s top cyber security analyst, did just that at the SANS Institute 2008 SCADA and Process Control Summit. I caught up with Alan Paller, research director for SANS, and asked him what he carried away from that presentation.

Paller said the CIA asked to make this presentation, but SANS was not allowed to publicize its participation, or even say that Donahue was coming. “The news was that he came prepared and vetted to make the presentation,” Paller notes, “so that means they’ve moved past the stage where this is hypothetical in their minds, and they think it needs to be fixed. I was shocked that they were willing to do that. He said‘you can quote me,’ and he gave it to me in writing and signed it. Their message is that people need to act on this, and they wanted to give it a credible source.”

The substance of the presentation is that there have been actual cyber break-ins at utilities outside the U.S. where hackers have made extortion demands, and in at least one situation they caused an outage that affected multiple cities. The analysts suspect, but cannot confirm, that the hackers had inside knowledge. “The CIA measures the threat, not the vulnerability,” Paller adds. “They’re looking at who’s doing this and what kind of resources they have. If the CIA thinks it matters, it matters, at least to me. Utilities need to act on the threat.

“People pretend it’s not a problem by putting risks in boxes. Either‘I’m protected,’ or ‘They’re not going to target me,’ or ‘It’s not a big enough probability.’ The CIA’s job is to measure the extent to which people, either governments, terrorist groups, or organized crime, have gotten to the point where they know howto do it, can do it, and have figured out that they can make a buck or get data they want doing it. That’s got to be what happened.”

Paller says there are three main ways to make money by hacking. The first is spam, obtaining e-mail addresses for advertising or directly soliciting money. The second is getting into an individual’s machine to steal personal financial information. A new variation on that is “pump and dump,” where people’s online stock trading accounts are hijacked and used to pump up a stock price fraudulently. Those two account for many billions of dollars of illegal gain. Extortion, the third method of hacking is rapidly growing.

“Extortion is the biggest silent threat,” warns Paller. “Banks have been hit by it. Lots of e-commerce sites and virtually all online gambling sites are paying extortion. For utilities, it is the big threat. It has been a major crime category since at least 2001, and a friend of mine who runs this area for the FBI says they learn of at least one new cyber-extortion case every day. It’s a huge thing.”

Is there light at the end of the security tunnel? Paller says there is also good news that came out of the January summit. More on that next month.

The SANS Institute provides a wide variety of training and courses for cyber security. There will be a comprehensive seminar in Orlando, April 18-25 .

—Peter Welander, process industries editor, ,
Process & Advanced Control Monthly
Register here and scroll down to select your choice of free eNewsletters.

No comments
The Engineers' Choice Awards highlight some of the best new control, instrumentation and automation products as chosen by...
The System Integrator Giants program lists the top 100 system integrators among companies listed in CFE Media's Global System Integrator Database.
The Engineering Leaders Under 40 program identifies and gives recognition to young engineers who...
This eGuide illustrates solutions, applications and benefits of machine vision systems.
Learn how to increase device reliability in harsh environments and decrease unplanned system downtime.
This eGuide contains a series of articles and videos that considers theoretical and practical; immediate needs and a look into the future.
Salary and career survey: Benchmarks and advice; Designing controls; Remote data collection, historians; Control valve advances; Hannover Messe; Control Engineering International
System integration: Best practices and technologies to help; Virtualization virtues; Cyber security advice; Motor system efficiency, savings; Product exclusives; Road to Hannover
Collaborative robotics: How to improve safety, return on investment; Industrial Internet of Things, Industrie 4.0: World views; High-performance HMI, Information Integration: OPC and OMG
This article collection contains several articles on the Industrial Internet of Things (IIoT) and how it is transforming manufacturing.
PLCs, robots, and the quest for a single controller; how OEE is key to automation solutions.

Find and connect with the most suitable service provider for your unique application. Start searching the Global System Integrator Database Now!

Getting to the bottom of subsea repairs: Older pipelines need more attention, and operators need a repair strategy; OTC preview; Offshore production difficult - and crucial
Digital oilfields: Integrated HMI/SCADA systems enable smarter data acquisition; Real-world impact of simulation; Electric actuator technology prospers in production fields
Special report: U.S. natural gas; LNG transport technologies evolve to meet market demand; Understanding new methane regulations; Predictive maintenance for gas pipeline compressors
click me