Small power station hack shutdown
Small power station hack shutdown
Author
Discussion

Getragdogleg

Original Poster:

10,166 posts

211 months

Iran-linked hackers behind cyber attack that shut down power plant, reports say - BBC News https://share.google/J4Gadtfq3b3Bl29Xq

This is an interesting story, not a big headline event but nonetheless a topic well worth keeping in mind while the current US president is busy making distractions waves in the middle east.

We are probably underprepared and woefully underfunded to protect ourselves from this sort of thing.

seabod91

1,065 posts

90 months

Quite worrying no ?

What will our response be, harsh letter and a pocket full of sanctions.

butchstewie

67,020 posts

238 months

The devil will likely be in the detail here.

You real all sort of stories all the time about control systems being left exposed to the Internet with vulnerabilities or default credentials.

I suppose I'm just making a point that it may not have been quite the high tech event the media reports can portray - either way whatever they did and however they did it it clearly isn't good.

JoshSm

4,764 posts

65 months

Meh, it's usually just crappy implementations that a child could hack, stuff put in an accessible place that shouldn't ever be, so someone can remote manage it.

Sounds like it was a little auxiliary plant so not a shock it was half arsed.

I'm just impressed that the gear supported enough logging & forensics to know it was Iranians that did it and not the usual Russians/Ukrainians/Chinese or local kiddies.

Iranian hackers is good for the current news cycle but hardly the most frequent source of threat.

Getragdogleg

Original Poster:

10,166 posts

211 months

Where did you get 4 years ago from?

it was reportedly last month and shut the plant for 4 days.

ETA; I see you have done an edit to remove the 4 year claim.

valiant

14,042 posts

188 months

seabod91 said:
Quite worrying no ?

What will our response be, harsh letter and a pocket full of sanctions.
We could bomb them. That’s worked out quite well for the Americans…

rodericb

8,825 posts

154 months

Yesterday (03:09)
quotequote all
seabod91 said:
Quite worrying no ?

What will our response be, harsh letter and a pocket full of sanctions.
Click the Update button in the software.

HiAsAKite

2,549 posts

275 months

Yesterday (09:21)
quotequote all
A few years back there was the revelation that Sellafield had been hacked by suspected Russians & Chinese groups for "a significant period of time: "https://www.theguardian.com/business/2023/dec/04/sellafield-nuclear-site-hacked-groups-russia-china

So this recent news should not be a surprise, our entire national infrastructure is under constant probing and attack from numerous nation state based groups...

And this is recognised- with significant efforts raising awareness and bolstering our (cyber) defences, but it is a very big job

pghstochaj

3,709 posts

147 months

Yesterday (14:01)
quotequote all
I project manage the construction of power stations up to about 100 MW (as the owner's engineer), so I can speak with some knowledge of this topic. Operators want remote access (either from their office or at home on the toilet) and some subcontractors need access to some systems (weighbridges, building management system, CCTV, combustion control, steam turbine control etc.) therefore there will always be an element of the plant being visible to the outside world.

We minimise that risk by having various tiers of networks (safety PLC, main plant control system (DCS), other equipment such as access control and CCTV, corporate network). Roughly speaking, the former are "OT" and the latter "IT".

The safety PLC is isolated from the internet completely and USB etc. access is strongly restricted, this controls functions to stop major risks to the asset or life safety, e.g. plant trips for over-pressure.

The DCS is normally read-only except when you are logged into an operator work station. Read only access is usually provided via something like Secomea. This is where you could shut the plant down (and cause some short term harm) but on modern plants, this would be very difficult (you would need to get onto the system via the Secomea type system and then know how to create harm despite read only access). A modern power station is generally designed so that if anything looks wrong it trips to a safe state. Causing a shutdown is therefore far easier than causing physical damage.

The next level is where the risk lies as third parties need access and there is talking between this network and the DCS (e.g. for emissions information). Normally we limit access to this via VPNs, only turn it on for short periods of time and limit access from this network to the DCS to very limited traffic.

The corporate network is just like your standard office network, it is not connected to the above levels of network (except via the Socomea, VPN etc.) - for all intents and purposes, it may as well be an office network anywhere in the world.

For me, all recent stations have high levels of cyber security. The main risk would be that somebody does something stupid (leaves access open to a certain network, shares passwords, connects the networks up by mistake (e.g. when sharing a fire alarm signal with the DCS to trip the plant) or that they use a denial of service type attack on a plant which must have outside monitoring (e.g. small unmanned gas engines, solar farms, wind farms etc.). Alternatively, a weaker part of a plant (e.g. the emissions monitoring of weighbridge) could be attacked and taken offline and whilst the station can continue, in effect it prevents the plant from operating legally (can't receive fuel, can't record or report emissions etc.). We try to make it that those systems can work without the internet (and that the plant can continue without those systems if they are compromised).


However, 15-20 years ago this was not the case and we used remote desktops like logmein. I was always of the view that a typical hacker might be able to get onto the system but only to steal data, BUT if they were an expert in the control software (Siemens, Valmet etc.) as well as a general hacker then they might be able to do more harm.

I am also nervous that plants get built and then cybersecurity is considered "done" (like it was considered "done" 15 years ago). That is, no substantial updates to reflect the changing risks. The network architecture of a power station is complicated so people do not want to go near it when it is working. Without those updates I suspect plants that appear strong today might be weak in 15 years time.

I don't know which station has been brought offline just yet but I would purely speculate as follows:

- >10-15 years old and not updated to reflect changing risks;
- very small scale power plant installed to a budget and not really of material risk to the distribution or transmission grid; and/or
- a very small power plant (e.g. unmanned solar or wind, or gas engine) which has had a denial of service type attack and it has gone into a form of safe mode due to a lack of visibility with its main control hub.

sparta6

5,524 posts

128 months

Yesterday (14:06)
quotequote all
valiant said:
seabod91 said:
Quite worrying no ?

What will our response be, harsh letter and a pocket full of sanctions.
We could bomb them. That s worked out quite well for the Americans
Not worth the effort.

Iran's real shakers and movers live in central London

ukwill

10,113 posts

235 months

Yesterday (14:14)
quotequote all
I'm not at all concerned. The public sector has robust Cyber Security - truly, the cream of the crop would have their head turned by roles like this:


sparta6

5,524 posts

128 months

Yesterday (14:20)
quotequote all
ukwill said:
I'm not at all concerned. The public sector has robust Cyber Security - truly, the cream of the crop would have their head turned by roles like this:

Head of UK Cyber Security, less than £60k in London.

Outstanding.




snuffy

13,121 posts

312 months

Yesterday (14:25)
quotequote all
ukwill said:
I'm not at all concerned. The public sector has robust Cyber Security - truly, the cream of the crop would have their head turned by roles like this:

It seems it was from 2023, but even so:

https://therecord.media/head-of-cyber-role-salary-...

NRS

26,152 posts

229 months

Yesterday (14:35)
quotequote all
Aren't you guys normally complaining about the public salary wage bill? What do you want, a bill that gets the best candidates or one that is less money?

pghstochaj

3,709 posts

147 months

Yesterday (14:37)
quotequote all
sparta6 said:
ukwill said:
I'm not at all concerned. The public sector has robust Cyber Security - truly, the cream of the crop would have their head turned by roles like this:

Head of UK Cyber Security, less than £60k in London.

Outstanding.
We only pay MPs £90k, people get mad about high public sector salaries, so you get a situation like this. Of course some people on here say that the civil service pension makes the salary worth it...

honest_delboy

1,738 posts

228 months

Yesterday (16:44)
quotequote all
Thanks pghstochaj for your post. One of the great bits on PH is when someone pitches up and says "i do this for a living and this is what actually happens"

Getragdogleg

Original Poster:

10,166 posts

211 months

Yesterday (18:30)
quotequote all
honest_delboy said:
Thanks pghstochaj for your post. One of the great bits on PH is when someone pitches up and says "i do this for a living and this is what actually happens"
Seconded, its lovely when you can actually learn from a poster!


ukwill

10,113 posts

235 months

Yesterday (22:04)
quotequote all
NRS said:
Aren't you guys normally complaining about the public salary wage bill? What do you want, a bill that gets the best candidates or one that is less money?
Personally I’d be content with less ridiculous strawmen.

That is, unless the public sector is one giant amorphous blob, simply incapable of allocating budgets/resources appropriately. But if that were the case, there wouldnt be analyst roles paying £55-60k in local councils.

hidetheelephants

35,572 posts

221 months

Yesterday (23:11)
quotequote all
HiAsAKite said:
A few years back there was the revelation that Sellafield had been hacked by suspected Russians & Chinese groups for "a significant period of time: crap Sellafield security.

So this recent news should not be a surprise, our entire national infrastructure is under constant probing and attack from numerous nation state based groups...

And this is recognised- with significant efforts raising awareness and bolstering our (cyber) defences, but it is a very big job
Grauniad said:
In one highly embarrassing incident last July, login details and passwords for secure IT systems were inadvertently broadcast on national TV by the BBC One nature series Countryfile, after crews were invited into the secure site for a piece on rural communities and the nuclear industry.
hehe Cyber security begins with not employing people who can't count without moving their lips and using their fingers.

Jazzy Jag

3,679 posts

119 months

The password was Password1!

Had to include a capital, a number and a special character