X
Edition:
United States

  • Business
    • Business Home
    • Legal
    • Deals
    • Aerospace & Defense
    • Finance
    • Autos
    • Reuters Summits
  • Markets
    • Markets Home
    • U.S. Markets
    • European Markets
    • Asian Markets
    • Global Market Data
    • Indices
    • Stocks
    • Bonds
    • Currencies
    • Comm & Energy
    • Futures
    • Funds
    • Earnings
    • Dividends
  • World
    • World Home
    • U.S.
    • Special Reports
    • Reuters Investigates
    • Euro Zone
    • Middle East
    • China
    • Japan
    • Mexico
    • Brazil
    • Africa
    • Russia
    • India
  • Politics
    • Politics Home
    • Election 2016
    • Polling Explorer
    • Just In
    • What Voters Want
    • Supreme Court
  • Tech
    • Technology Home
    • Science
    • Top 100 Global Innovators
    • Environment
    • Innovation
  • Commentary
    • Commentary Home
    • Podcasts
  • Breakingviews
    • Breakingviews Home
    • Breakingviews Video
  • Money
    • Money Home
    • Retirement
    • Lipper Awards
    • Analyst Research
    • Stock Screener
    • Fund Screener
  • Rio 2016
  • Pictures
    • Pictures Home
    • The Wider Image
    • Photographers
    • Focus 360
  • Video
U.S. utility's control system was hacked, says Homeland Security
  • Africa
    América Latina
  • عربي
    Argentina
  • Brasil
    Canada
  • 中国
    Deutschland
  • España
    France
  • India
    Italia
  • 日本
    México
  • РОССИЯ
    United Kingdom
  • United States
Technology News | Tue May 20, 2014 8:30pm EDT

U.S. utility's control system was hacked, says Homeland Security

The word 'password' on a computer screen is magnified with a magnifying glass in this picture illustration taken in Berlin May 21, 2013. REUTERS/Pawel Kopczynski
The word 'password' on a computer screen is magnified with a magnifying glass in this picture illustration taken in Berlin May 21, 2013. REUTERS/Pawel Kopczynski
By Jim Finkle | BOSTON

BOSTON A sophisticated hacking group recently attacked a U.S. public utility and compromised its control system network, but there was no evidence that the utility's operations were affected, according to the Department of Homeland Security.

DHS did not identify the utility in a report that was issued this week by the agency's Industrial Control Systems Cyber Emergency Response Team, or ICS-CERT.

"While unauthorized access was identified, ICS-CERT was able to work with the affected entity to put in place mitigation strategies and ensure the security of their control systems before there was any impact to operations," a DHS official told Reuters on Tuesday.

Such cyber attacks are rarely disclosed by ICS-CERT, which typically keeps details about its investigations secret to encourage businesses to share information with the government. Companies are often reluctant to go public about attacks to avoid potentially negative publicity.

ICS-CERT said in the report posted on its website that investigators had determined the utility had likely been the victim of previous intrusions. It did not elaborate.

The agency said the hackers may have launched the latest attack through an Internet portal that enabled workers to access the utility's control systems. It said the system used a simple password mechanism that could be compromised using a technique known as "brute forcing," where hackers digitally force their way in by trying various password combinations.

Justin W. Clarke, an industrial control security consultant with security firm Cylance Inc, said it is rare for such breaches to be identified by utilities and even more rare for the government to disclose them.

"In most cases, systems that are so antiquated to be susceptible to such brute forcing technologies would not have the detailed logging required to aid in an investigation like this," Clarke said.

DHS also reported another hacking incident involving a control system server connected to "a mechanical device." The agency provided few details about that case, except to say the attacker had access over an extended period of time, though no attempts were made to manipulate the system.

"Internet facing devices have become a serious concern over the past few years," the agency said in the report.

Last year ICS-CERT responded to 256 cyber incident reports, more than half of them in the energy sector. While that is nearly double the agency's 2012 case load, there was not a single incident that caused a major disruption.

Those incidents include hacking into systems through Internet portals exposed over the Web, injecting malicious software through thumb drives, and exploitation of software vulnerabilities.

(Reporting by Jim Finkle; Editing by Tiffany Wu)

Trending Stories

    Editor's Pick

    LIVE: Election 2016

    Sponsored Topics

    Next In Technology News

    Ford boosts spending, doubles staff for self-driving cars

    DETROIT Ford Motor Co is hiking investments in Silicon Valley technology firms and more than doubling the size of its Palo Alto, California, research team to help speed development of self-driving cars, the automaker said on Tuesday.

    In a shift, Bangladesh Bank says no plans to sue Fed, SWIFT

    DHAKA/NEW YORK Bangladesh's central bank said it has reversed its plans to sue the Federal Reserve Bank of New York and the SWIFT money transfer network, and instead intends to seek their help recovering $81 million stolen by cyber thieves in February.

    Indian messaging platform Hike raises $175 million

    NEW DELHI Indian messaging startup Hike Messenger has raised more than $175 million in a funding round led by Tencent Holdings Limited and Foxconn Technology Group that values the company at nearly $1.4 billion.

    MORE FROM REUTERS

    From Around the Web By Taboola

    Sponsored Content By Dianomi

    X
    Follow Reuters:
    • Follow Us On Twitter
    • Follow Us On Facebook
    • Follow Us On RSS
    • Follow Us On Instagram
    • Follow Us On YouTube
    • Follow Us On LinkedIn
    Subscribe: Feeds | Newsletters | Podcasts | Apps
    Reuters News Agency | Brand Attribution Guidelines | Delivery Options

    Reuters is the news and media division of Thomson Reuters. Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Learn more about Thomson Reuters products:

    Eikon
    Information, analytics and exclusive news on financial markets - delivered in an intuitive desktop and mobile interface
    Elektron
    Everything you need to empower your workflow and enhance your enterprise data management
    World-Check
    Screen for heightened risk individual and entities globally to help uncover hidden risks in business relationships and human networks
    Westlaw
    Build the strongest argument relying on authoritative content, attorney-editor expertise, and industry defining technology
    ONESOURCE
    The most comprehensive solution to manage all your complex and ever-expanding tax and compliance needs
    CHECKPOINT
    The industry leader for online information for tax, accounting and finance professionals

    All quotes delayed a minimum of 15 minutes. See here for a complete list of exchanges and delays.

    • Site Feedback
    • Corrections
    • Advertise With Us
    • Advertising Guidelines
    • AdChoices
    • Terms of Use
    • Privacy Policy