NATIONAL NEWS

In Florida City, Hackers Try To Poison Drinking Water

Feb 9, 2021, 6:00 AM

(Pinellas County Sheriff's Office)...

(Pinellas County Sheriff's Office)

(Pinellas County Sheriff's Office)

A hacker gained unauthorized entry to the system controlling the water treatment plant of a Florida city of 15,000 and tried to taint the water supply with a caustic chemical, exposing a danger cybersecurity experts say has grown as systems become both more computerized and accessible via the internet.

The hacker who breached the system at the city of Oldsmar’s water treatment plant on Friday using a remote access program shared by plant workers briefly increased the amount of sodium hydroxide by a factor of one hundred (from 100 parts per million to 11,100 parts per million), Pinellas County Sheriff Bob Gualtieri said during a news conference Monday.

Sodium hydroxide, also called lye, is used to treat water acidity but the compound is also found in cleaning supplies such as soaps and drain cleaners. It can cause irritation, burns and other complications in larger quantities.

Fortunately, a supervisor saw the chemical being tampered with — as a mouse controlled by the intruder moved across the screen changing settings — and was able to intervene and immediately reverse it, Gualtieri said. Oldsmar is about 15 miles (25 kilometers) northwest of Tampa.

Gualtieri said the public was never in danger.

But he did say the intruder took “the sodium hydroxide up to dangerous levels.”

Oldsmar officials have since disabled the remote-access system, and say other safeguards were in place to prevent the increased chemical from getting into the water. Officials warned other city leaders in the region — which was hosting the Super Bowl — about the incident and suggested they check their systems.

Experts say municipal water and other systems have the potential to be easy targets for hackers because local governments’ computer infrastructure tends to be underfunded.

Robert M. Lee, CEO of Dragos Security, and a specialist in industrial control system vulnerabilities, said remote access to industrial control systems such as those running water treatment plants has become increasingly common.

“As industries become more digitally connected we will continue to see more states and criminals target these sites for the impact they have on society,” Lee said.

The leading cybersecurity firm FireEye attributed an uptick in hacking attempts it has seen in the last year mostly to novices seeking to learn about remotely accessible industrial systems. Many victims appear to have been selected arbitrarily and no serious damage was caused in any of the cases — in part because of safety mechanisms and professional monitoring, FireEye analyst Daniel Kapellmann Zafra said in a statement.

“While the (Oldsmar) incident does not appear to be particularly complex, it highlights the need to strengthen the cybersecurity capabilities across the water and wastewater industry,” he said.

What concerns experts most is the potential for state-backed hackers intent on doing serious harm targeting water supplies, power grids and other vital services.

In May, Israel’s cyber chief s aid the country had thwarted a major cyber attack a month earlier against its water systems, an assault widely attributed to its archenemy Iran. Had Israel not detected the attack in real time, he said chlorine or other chemicals could have entered the water, leading to a “disastrous” outcome.

Tarah Wheeler, a Harvard Cybersecurity Fellow, said communities should take every precaution possible when using remote access technology on something as critical as a water supply.

“The systems administrators in charge of major civilian infrastructure like a water treatment facility should be securing that plant like they’re securing the water in their own kitchens,” Wheeler told the Associated Press via email. “Sometimes when people set up local networks, they don’t understand the danger of an improperly configured and secured series of internet-connected devices.”

A plant worker first noticed the unusual activity at around 8 a.m. Friday when someone briefly accessed the system but thought little of it because co-workers regularly accessed the system remotely, Gualtieri told reporters. But at about 1:30 p.m., someone accessed it again, took control of the mouse, directed it to the software that controls water treatment and increased the amount of sodium hydroxide.

The sheriff said the intruder was active for three to five minutes. When they exited, the plant operator immediately restored the proper chemical mix, he said.

Other safeguards in place — including manual monitoring — likely would have caught the change in the 24 to 36 hours it took before it reached the water supply, the sheriff said.

Investigators said it wasn’t immediately clear where the attack came from — whether the hacker was domestic or foreign. The FBI, along with the Secret Service and the Pinellas County Sheriff’s Office are investigating the case.

Russian state-backed hackers have in recent years penetrated some U.S. industrial control systems, including the power grid and manufacturing plants while Iranian hackers were caught seizing control of a suburban New York dam in 2013. In no case was damage inflicted but officials say they believe the foreign adversaries have planted software boobytraps that could be activated in an armed conflict.

—-

Bajak reported from Boston.

KSL 5 TV Live

National News

FILE: Recording Artist Dickey Betts at the press confrence for the Gibson Custom Southern Rock trib...

Steven Wine and Russ Bynum

Allman Brothers Band co-founder and legendary guitarist Dickey Betts dies at 80

Guitar legend and Allman Brothers Band co-founder Dickey Betts has died at age 80. The Rock & Roll Hall of Famer wrote the band's biggest hit, “Ramblin’ Man.”

5 minutes ago

NEW YORK, NEW YORK - APRIL 18: Former U.S. President Donald Trump sits in the courtroom during his ...

Michael R. Sisak, Jennifer Peltz, Eric Tucker and Jake Offenhartz

2 jurors dismissed from Trump hush money trial as prosecutors seek to hold ex-president in contempt

A second juror was dismissed in Trump's hush money case after prosecutors raise concerns about the accuracy of his answers.

1 hour ago

Bryan Kohberger arrives September 13 for a hearing in Latah County District Court in Moscow, Idaho....

Taylor Romine

Expert will testify Bryan Kohberger’s cell phone was outside Moscow on night of Idaho murders

The filing is the latest turn in the high-profile case against Bryan Kohberger, who is accused of fatally stabbing four Idaho college students in November 2022.

6 hours ago

FILE - Chad Daybell is on trial for the murders of his wife Lori Vallow Daybell's two children, Jos...

Lauren Steinbrecher

Defense: Chad Daybell didn’t steal money from wife’s dead children

Chad Daybell's trial continues on Day 5, as the court discussed evidence that possibly connects Daybell to insurance fraud, with funds that were meant for Lori Vallow Daybell's murdered children.

17 hours ago

FILE - Celina Washburn protests outside the Arizona Capitol to voice her dissent for an abortion ru...

Arit John and Cheri Mossburg, CNN

Lawmakers vote against hearing Arizona bill repealing abortion ban on House floor

The Republican-controlled Arizona House of Representatives once again failed to advance a repeal of the state’s 160-year-old abortion ban Wednesday

21 hours ago

Starting pitcher Trevor Bauer #27 of the Los Angeles Dodgers reacts after giving up a two run home ...

Associated Press

A woman who accused Trevor Bauer of sex assault is now charged with defrauding the ex-MLB player

An Arizona woman who accused former major league pitcher Trevor Bauer of sexual assault has been charged with defrauding the baseball player.

22 hours ago

Sponsored Articles

Women hold card for scanning key card to access Photocopier Security system concept...

Les Olson

Why Printer Security Should Be Top of Mind for Your Business

Connected printers have vulnerable endpoints that are an easy target for cyber thieves. Protect your business with these tips.

Modern chandelier hanging from a white slanted ceiling with windows in the backgruond...

Lighting Design

Light Up Your Home With These Top Lighting Trends for 2024

Check out the latest lighting design trends for 2024 and tips on how you can incorporate them into your home.

Technician woman fixing hardware of desktop computer. Close up....

PC Laptops

Tips for Hassle-Free Computer Repairs

Experiencing a glitch in your computer can be frustrating, but with these tips you can have your computer repaired without the stress.

Close up of finger on keyboard button with number 11 logo...

PC Laptops

7 Reasons Why You Should Upgrade Your Laptop to Windows 11

Explore the benefits of upgrading to Windows 11 for a smoother, more secure, and feature-packed computing experience.

Stylish room interior with beautiful Christmas tree and decorative fireplace...

Lighting Design

Create a Festive Home with Our Easy-to-Follow Holiday Prep Guide

Get ready for festive celebrations! Discover expert tips to prepare your home for the holidays, creating a warm and welcoming atmosphere for unforgettable moments.

Battery low message on mobile device screen. Internet and technology concept...

PC Laptops

9 Tips to Get More Power Out of Your Laptop Battery

Get more power out of your laptop battery and help it last longer by implementing some of these tips from our guide.

In Florida City, Hackers Try To Poison Drinking Water