Hackers have a new target: power plants

SAN FRANCISCO — More than half of the operators of U.S. power plants and other “critical infrastructure” say in a new study that their computer networks have been infiltrated by sophisticated adversaries. In many cases, foreign governments are suspected.

The findings come in a survey being released Thursday that offers a rare public look at the damage computer criminals can do to vital institutions such as power grids, water and sewage systems and oil and gas companies. Manipulating the computer systems can cause power outages, floods, sewage spills and oil leaks.

The report was based on an survey completed by 600 executives and technology managers from infrastructure operators in 14 countries. The report was prepared by McAfee Inc., which makes security software, and the Center for Strategic and International Studies in Washington, which analyzed the data and conducted additional interviews. The respondents aren’t named and specifics aren’t given about what happened in the attacks.

The report comes as concerns are growing about state-sponsored hacking and threats to critical infrastructure.

In November, CBS’s “60 Minutes” reported that several Brazilian power outages were caused by hackers — a report that Brazilian officials have played down. Last April, U.S. government officials said that spies hacked into the U.S. electric grid and left behind computer programs that would let them disrupt service. The intrusions were discovered after electric companies gave the government permission to audit their systems.

In the new report, 54 percent of respondents acknowledged that they had been hit by “stealthy infiltration” of their networks. In such break-ins, criminals can plant malicious software to steal files, spy on e-mails and do even scarier things like remotely controlling equipment inside a utility.

Utilities are increasingly using mainstream software and connecting parts of their operations to the Internet so technicians can service problems remotely. Both factors heighten the danger of a hacker break-in.

The same percentage of respondents also said they have experienced large-scale “denial-of-service” attacks, in which a computer network is knocked out of service because of it is flooded with bogus Internet traffic. The infrastructure operators frequently said they believed representatives of foreign governments were involved.

Perhaps even more alarming: Many intruders have apparently done something harmful with the access they’ve stolen. Operators who had experienced denial of service attacks often said the incidents had at least some effect, from minor service interruptions to sustained damage and critical breakdowns.

Extortion is a common motivation, with hackers demanding money to end or agree not to carry out an attack. The power and oil and gas sectors were the most frequently targeted.

Identifying the culprits in such attacks can be next to impossible, because computer attacks are typically routed through multiple layers of infected computers to disguise the source. However, researchers can often learn clues about the attackers’ country of origin by studying the language and other signs in the malicious software’s programming.

Talk to us

More in Herald Business Journal

Members of Gravitics' team and U.S. Rep. Rick Larsen stand in front of a mockup of a space module interior on Thursday, August 17, 2023 at Gravitics' Marysville facility. Left to right: Mark Tiner, government affairs representative; Jiral Shah, business development; U.S. Rep. Rick Larsen; Mike DeRosa, marketing; Scott Macklin, lead engineer. (Gravitics.)
Marysville startup prepares for space — the financial frontier

Gravitics is building space station module prototypes to one day house space travelers and researchers.

Orca Mobility designer Mike Lowell, left, and CEO Bill Messing at their office on Wednesday, Aug. 16, 2023 in Granite Falls, Washington. (Olivia Vanni / The Herald)
Could a Granite Falls startup’s three-wheeler revolutionize delivery?

Orca Mobility’s battery-powered, three-wheel truck is built on a motorcycle frame. Now, they aim to make it self-driving.

Catherine Robinweiler leads the class during a lab session at Edmonds College on April 29, 2021. (Kevin Clark / The Herald)
Grant aids apprenticeship program in Mukilteo and elsewhere

A $5.6 million U.S. Department of Labor grant will boost apprenticeships for special education teachers and nurses.

Peoples Bank is placing piggy banks with $30 around Washington starting Aug. 1.
(Peoples Bank)
Peoples Bank grant program seeks proposals from nonprofits

Peoples Bank offers up to $35,000 in Impact Grants aimed at helping communities. Applications due Sept. 15.

Workers build the first all-electric commuter plane, the Eviation Alice, at Eviation's plant on Wednesday, Sept. 8, 2021 in Arlington, Washington.  (Andy Bronson / The Herald)
Arlington’s Eviation selects Seattle firm to configure production plane

TLG Aerospace chosen to configure Eviation Aircraft’s all-electric commuter plane for mass production.

Jim Simpson leans on Blue Ray III, one of his designs, in his shop on Friday, August 25, 2023, in Clinton, Washington. (Ryan Berry / The Herald)
Whidbey Island master mechanic building dream car from “Speed Racer”

Jim Simpson, 68, of Clinton, is using his knowledge of sports cars to assemble his own Mach Five.

Yansi De La Cruz molds a cheese mixture into bone shapes at Himalayan Dog Chew on Thursday, Sept. 21, 2023 in Arlington, Washington. (Olivia Vanni / The Herald)
Give a dog a bone? How about a hard cheese chew from Arlington instead!

Launched from a kitchen table in 2003, Himalayan Pet Supply now employs 160 workers at its new Arlington factory.

Inside the new Boeing 737 simulator at Simulation Flight in Mukilteo, Washington on Wednesday, Sept. 20, 2023. (Annie Barker / The Herald)
New Boeing 737 simulator takes ‘flight’ in Mukilteo

Pilots can test their flying skills or up their game at Simulation Flight in Mukilteo.

An Amazon worker transfers and organizes items at the new PAE2 Amazon Fulfillment Center on Thursday, Sept. 14, 2023, in Arlington, Washington. (Ryan Berry / The Herald)
Amazon cuts ribbon on colossal $355M fulfillment center in Arlington

At 2.8 million square feet, the facility is the largest of its kind in Washington. It can hold 40 million “units” of inventory.

A computer rendering of the North Creek Commerce Center industrial park in development at 18712 Bothell-Everett Highway. (Kidder Mathews)
Developer breaks ground on new Bothell industrial park

The North Creek Commerce Center on Bothell Everett Highway will provide warehouse and office space in three buildings.

Dan Bates / The Herald
Funko president, Brian Mariotti is excited about the growth that has led his company to need a 62,000 square foot facility in Lynnwood.
Photo Taken: 102312
Former Funko CEO resigns from the Everett company

Brian Mariotti resigned Sept. 1, six weeks after announcing he was taking a six-month sabbatical from the company.

Cash is used for a purchase at Molly Moon's Ice Cream in Edmonds, Washington on Wednesday, Aug. 30, 2023. (Annie Barker / The Herald)
Paper or plastic? Snohomish County may require businesses to take cash

County Council member Nate Nehring proposed an ordinance to ban cashless sales under $200. He hopes cities will follow suit.