DHS Dismisses Anonymous SCADA Threat

The “hacktivist” collective Anonymous is capable of crippling critical infrastructure, but the odds of developing a Stuxnet-style attack on industrial Supervisory Control and Data Acquisition (SCADA) systems were slim, according to a Department of Homeland Security (DHS) bulletin.

The four-page report from the department’s National Cyber-Security and Communications Integration Centre was posted on the Public Intelligence Website. The DHS evaluated the collective’s potential to disrupt critical infrastructure in the Assessment of Anonymous Threat to Control Systems report, dated 17 September.

Limited ability of Anonymous

Even though hacktivist groups are increasingly more active in their attacks, DHS said actual threats to control systems do not seem to have increased. Anonymous currently has a “limited ability” to conduct attacks that target industrial control systems, the DHS found. The group has the capability to disrupt operations with distributed denial-of-service attacks, but it does not currently have the necessary skills to take over critical infrastructure, according to the DHS.

“However, experienced and skilled members of Anonymous … could be able to develop capabilities to gain access and trespass on control system networks very quickly,” according to the DHS bulletin.

DHS evaluated the group after a known Anonymous member posted on Twitter on 19 July a directory tree for Siemens Simatic control system software, according to the report. “This is an indication in a shift toward interest in control systems by the hacktivist group,” the report said.

Critical infrastructure refers to the systems and networks that power communications, energy, financial systems, food, government operations, health care systems, transportation and water.

The vast majority of the infrastructure is currently controlled by the private sector. There are several bills in Congress proposing some form of government oversight to protect critical infrastructure, but disagreements remain as to who should be in charge and the role government should play.

Monsanto attack shows intent

The idea that Anonymous might target critical infrastructure is not far-fetched. Members have called for attacking energy companies and on 11 July, some members of the collective attacked biotechnology seed company Monsanto. As part of the attack, Monsanto’s Web infrastructure had been disabled for two days, email servers disabled for three days and data on 2,500 employees and partners stolen.

Groups such as Anonymous and LulzSec choose to “harass and embarrass their targets using rudimentary attack methods”, DHS said. All the information released by Anonymous and LulzSec indicated that the groups showed “no indication of exploitation capability”, according to the report.

While the risks currently are low, there was a “moderate likelihood” that future protests could be accompanied by attacks on core infrastructure in the future.

The group can become more interested, especially as they realise how poorly these systems are secured in the first place, the report warned. Members can study industrial control systems using publicly available information and develop malware to exploit well-known vulnerabilities, according to the federal agency.

The DHS report still warned that even though Anonymous may not attack the control systems, all businesses should still make sure their IT systems are protected. Attackers can easily locate and access industrial control systems with “minimal skills” using Internet search engine tools and applications to carry out “nefarious activities” or conduct reconnaissance activities to launch other attacks, the department warned.

Oil and gas companies are potentially attractive targets as the collective supports the “green energy” agenda and has opposed pipeline projects in the past.

Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

View Comments

  • It was June 11 & Monsanto was only down for a few hours, as was email. Those 2500 users were off of a third party supported server and didn't amount to shit. They tried all weekend and the Anons got bitchslapped!!!!

Share
Published by
Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

Recent Posts

Craig Wright Sentenced For Contempt Of Court

Suspended prison sentence for Craig Wright for “flagrant breach” of court order, after his false…

2 days ago

El Salvador To Sell Or Discontinue Bitcoin Wallet, After IMF Deal

Cash-strapped south American country agrees to sell or discontinue its national Bitcoin wallet after signing…

2 days ago

UK’s ICO Labels Google ‘Irresponsible’ For Tracking Change

Google's change will allow advertisers to track customers' digital “fingerprints”, but UK data protection watchdog…

2 days ago

EU Publishes iOS Interoperability Plans

European Commission publishes preliminary instructions to Apple on how to open up iOS to rivals,…

3 days ago

Momeni Convicted In Bob Lee Murder

San Francisco jury finds Nima Momeni guilty of second-degree murder of Cash App founder Bob…

3 days ago