Florida Water Plant Targeted With Cyberattack

Share post:

According to security firm Dragos, an employee in Oldsmar, Florida, visited a malicious website targeting water utilities on May 18, just hours before a person entered the city’s water treatment plant and tried to poison the drinking water.

The site did not play a role in the incident, but the situation was worrying, the security firm said.

“Watering-hole attacks” have become relatively common in computer hacking crimes targeting specific industries and users.

Florida is often a target.

The site is owned by a water utility in Florida and was compromised in December by hackers with malicious code targeting water utilities.

During the 58 days the site was infected, more than 1,000 computers visited the site.

One visit by an unauthorized person used the site to adjust chemicals that treat drinking water for about 15,000 residents of a small town northwest of Tampa.

The change was immediately recognized and canceled.

According to Dragos, the malicious code collected more than 100 pieces of detailed information about visitors.

Information such as CPU type, operating system, browser, time zone, and geolocation were just a few examples of information that the code could access.

The code also led visitors to two different websites that collected cryptographic hashes that uniquely identified each connecting device and uploaded fingerprints to a database.

Although the safety flaws did not cause extreme damage, as the majority of the attacks were caught immediately, Dragos researcher Kent Backman said this should be a wake-up call for water plants.

For more information, read the original story in arstechnica. 

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 15, 2024 – Ebury botnet still exploits Linux servers, Microsoft, SAP and Apple issue security updates

The Ebury botnet continues to exploit Linux servers, Microsoft, SAP and Apple issue security updates, and more. Welcome to...

Employee errors still predominant cause of data breaches: Verizon Report

In the latest 2024 Verizon Data Breach Report (DBIR), it has been revealed that employee errors remain the...

Black Basta has compromised over 500 organizations globally:CISA

The Cybersecurity and Infrastructure Security Agency (CISA) along with the FBI reported that the Black Basta ransomware group...

Cyber Security Today, May 10, 2024 – Patches for F5’s Next Central Manager released, Dell discovers data theft covering millions, and more

Patches for F5's Next Central Manager are released, Dell discovers data theft covering millions of buyers, and more Welcome...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways