Print | Send on Yahoo! | PDF version | Feed RSS | Filed Under: MISCELLANEOUS

Insider Indicted For SCADA Tampering

Date: 03/20/2009
Author: RAZVAN STOICA

A man stands indicted of a single count of having "caused damage by impairing the integrity and availability of data", to the tune of "thousands of dollars".

We're reporting on this partly because it's such a rare event - most true "hack attacks" either go un-reported or un-prosecuted, if they are successful in causing some harm. What's more, it's also what ze Germans would call "echt typisch", a veritable poster-child of a case where an insider with access and a chip on his shoulder goes to town on company servers.

The case is also interesting from another perspective - there seems to be a massive security blunder to be found between the lines of the press release, here:

"Azar helped set up a computer system that PER used to communicate between its offices and its oil platforms. The computer system also served a “leak detection” function for PER".

In other words, it appears that SCADA and regular IP traffic were made, by design, to share the same lines and systems. This is a big no-no, as nuclear powerplant operators in the US have already found to their expense.
 
It will be interesting to watch this case and find out whether an uncontained oil spill was a possibility at any point.
Share our story:
DiggStumbleUpondel.icio.usYahooMyWebFurlGoogle

Comment on this:
Name:
Email:
Your email address will not be published!

Please enter the code from the image below.
The code is not case sensitive
Verification Image
Reload image
 
 
Calendar
March 2010
MoTuWeThFrSaSu
1234567
891011121314
15161718192021
22232425262728
293031    
« Feb March Apr »
Tag Claud
worm data infected computer conficker messages word windows file system bitdefender pharmacy review rogue downadup security online antivirus files virus exploit software trojan spam message twitter omelette canadian microsoft malware