DHS Officials: Hundreds of US Utility Victims Infiltrated by Russian Hackers
Federal government officials up their count of US energy sector victims from dozens to hundreds, according to a Wall Street Journal report.
The US Department of Homeland Security, which earlier this year warned of Russian nation-state hacking teams targeting energy and other critical infrastructure organizations, in a briefing this week provided more details on the attack campaign.
The Wall Street Journal reported that DHS officials said there were hundreds of victims: an increase from their original count of a few dozen targets who had been hacked by Dragonfly, aka Energetic Bear, via supply-chain attacks.
The attackers hopped from commercial supplier networks to the energy organizations and siphoned information on how the utility sites operate and were trying to remain under the radar, appearing as "people who touch these systems on a daily basis," Jonathan Homer, chief of industrial-control-system analysis for DHS told the WSJ.
"The DHS has done a great job amplifying what was previously identified by the private sector and adding their own information. This relates to activity already previously communicated to the electric community, but highlighting ongoing risk is important," said Rob Lee, CEO of Dragos.
But, Lee says, the WSJ report's reference to "throwing switches" and "causing blackouts" was misleading. It's more of a cyber espionage operation: "What was observed is incredibly concerning, but images of imminent blackouts are not representative of what happened which was more akin to reconnaissance into sensitive networks," Lee says.
Read more here.
Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.
About the Author
You May Also Like
Unleashing AI to Assess Cyber Security Risk
Nov 12, 2024Securing Tomorrow, Today: How to Navigate Zero Trust
Nov 13, 2024The State of Attack Surface Management (ASM), Featuring Forrester
Nov 15, 2024Applying the Principle of Least Privilege to the Cloud
Nov 18, 2024The Right Way to Use Artificial Intelligence and Machine Learning in Incident Response
Nov 20, 2024