Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

Zorro

(15,749 posts)
Mon Feb 8, 2021, 02:55 PM Feb 2021

Someone tried to poison Oldsmar's water supply during hack, Sheriff says

Source: Tampa Bay Times

Pinellas Sheriff Bob Gualtieri said the attacker tried to raise levels of sodium hydroxide, also known as lye, by a factor of more than 100.

Local and federal authorities are investigating after an attempt Friday to poison the city of Oldsmar’s water supply, Pinellas County Sheriff Bob Gualtieri said.

Someone remotely accessed a computer for the city’s water treatment system and briefly increased the amount of sodium hydroxide, also known as lye, by a factor of more than 100, Gualtieri said at a news conference Monday. The chemical is used in small amounts to control the acidity of water but it’s also a corrosive compound commonly found in household cleaning supplies such as liquid drain cleaners.

The city’s water supply was not affected. A supervisor working remotely saw the concentration being changed on his computer screen and immediately reverted it, Gualtieri said. City officials on Monday emphasized that several other safeguards are in place to prevent contaminated water from entering the water supply and said they’ve disabled the remote-access system used in the attack.

The Pinellas County Sheriff’s Office is investigating, along with the FBI and the Secret Service, Gualtieri said.

Read more: https://www.tampabay.com/news/pinellas/2021/02/08/someone-tried-to-poison-oldsmars-water-supply-during-hack-sheriff-says/



This is a clear example of how vulnerable SCADA systems that control our vital infrastructure elements are.

There are no doubt thousands of systems just as vulnerable.
26 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Someone tried to poison Oldsmar's water supply during hack, Sheriff says (Original Post) Zorro Feb 2021 OP
Holy crap. BusyBeingBest Feb 2021 #1
TrumpDeadenderTimothyMcVeigh type psychos will be among us for a time. nt oasis Feb 2021 #2
Wtf?!! Horrific! Hopefully the prep will caught quickly. electric_blue68 Feb 2021 #3
The perp is probably in Russia. lagomorph777 Feb 2021 #8
Oh.... may be, since a person can often hack from anywhere electric_blue68 Feb 2021 #9
Why would a perp in Russia do this specifically? LeftInTX Feb 2021 #14
To see it show up in the news. lagomorph777 Feb 2021 #17
And the US can do exactly that to him. paleotn Feb 2021 #22
I hope you are correct. lagomorph777 Feb 2021 #26
Amateurs fooling around..... paleotn Feb 2021 #21
Next question jmowreader Feb 2021 #4
Yah, that's my take packman Feb 2021 #5
Remote operations... pfitz59 Feb 2021 #6
remote workers WhiteTara Feb 2021 #7
Not necessarily connected to the Internet. We had SCADA systems long before progree Feb 2021 #13
One problem is that many SCADA systems have been connected to the Internet whopis01 Feb 2021 #15
What's not connected to the internet? paleotn Feb 2021 #23
What's wrong with people? LeftInTX Feb 2021 #10
That's my thought as well. Dem2theMax Feb 2021 #11
If the system was hacked, we have to infer the poisoning was deliberate msfiddlestix Feb 2021 #12
90% White...13,000 K suburb of St Petersburg, FL..probably GOP area... LeftInTX Feb 2021 #16
I just thought of something: The Super Bowl! LeftInTX Feb 2021 #19
This is chilling. From a NYT article this weekend 3littlebeans Feb 2021 #18
The software program is TeamViewer dalton99a Feb 2021 #20
Word on Rachel is that this is suspected to be the Russians pecosbob Feb 2021 #24
Good old Team Viewer - is that even a hack? swag Feb 2021 #25

LeftInTX

(25,572 posts)
14. Why would a perp in Russia do this specifically?
Mon Feb 8, 2021, 05:48 PM
Feb 2021

If they were trolling for insecure sites, they probably would just done a small change and watched if the water district responded.

lagomorph777

(30,613 posts)
17. To see it show up in the news.
Mon Feb 8, 2021, 05:57 PM
Feb 2021

To remind us that Putin has hacked just about everything in the USA, and he can throw us into the stone age at the flip of a switch.

lagomorph777

(30,613 posts)
26. I hope you are correct.
Tue Feb 9, 2021, 09:56 AM
Feb 2021

I assume Trump did everything in his power to neuter our cyber capability; Biden will have a big, urgent job to repair it.

paleotn

(17,989 posts)
21. Amateurs fooling around.....
Mon Feb 8, 2021, 09:06 PM
Feb 2021

or professionals making a point. Hard to tell. If it is professionals, like nation state professionals, they have to know that with a few key strokes the US can turn off the lights in Moscow for a very, very long time. In cyberspace, we're back to mutually assured destruction.

 

packman

(16,296 posts)
5. Yah, that's my take
Mon Feb 8, 2021, 03:39 PM
Feb 2021

Letting the fox into the hen house - venerability level on the internet is high

pfitz59

(10,396 posts)
6. Remote operations...
Mon Feb 8, 2021, 04:08 PM
Feb 2021

Most large water treatment systems have remote monitoring and operation programming. Valves, reservoirs, treatments, alarms can all be remotely accessed and controlled. Too expensive to have every station manned 24/7. This applies to potable water supplies, sewerage and storm drains.

progree

(10,920 posts)
13. Not necessarily connected to the Internet. We had SCADA systems long before
Mon Feb 8, 2021, 05:46 PM
Feb 2021

the Internet ... well there was Arpanet, but our SCADA systems didn't utilize it.

Spoken from an electric utility perspective.

When I put in the title, "Not necessarily connected to the Internet", I was being cautious, who knows what shortcuts they took.

whopis01

(3,523 posts)
15. One problem is that many SCADA systems have been connected to the Internet
Mon Feb 8, 2021, 05:56 PM
Feb 2021

Either directly or indirectly.

"the operator watched as someone took control of the mouse, directed it to the software that controls water treatment, worked inside it for three to five minutes and increased the amount of sodium hydroxide from 100 parts per million to 11,100 parts per million."


That sounds to me like they have a control interface running on a typical PC, which is likely connected to the Internet. So the SCADA system itself might not be directly connected to the Internet - but computers that can talk to it are.


msfiddlestix

(7,286 posts)
12. If the system was hacked, we have to infer the poisoning was deliberate
Mon Feb 8, 2021, 05:43 PM
Feb 2021

So why would someone want to deliberately poison an entire community?

Someone who is mentally deranged? But what's the motive? Is it political? Is this community primarily people of color? Democratic stronghold (voters)? Is this an Elite community? Predominately White? Republican holdout?

Just curious as to motive.

LeftInTX

(25,572 posts)
16. 90% White...13,000 K suburb of St Petersburg, FL..probably GOP area...
Mon Feb 8, 2021, 05:57 PM
Feb 2021

Probably just another day in Florida man's life.....that's my hunch....some people just are sick

LeftInTX

(25,572 posts)
19. I just thought of something: The Super Bowl!
Mon Feb 8, 2021, 06:03 PM
Feb 2021

Although a suburb, maybe this was the only system they could hack?

3littlebeans

(9 posts)
18. This is chilling. From a NYT article this weekend
Mon Feb 8, 2021, 06:01 PM
Feb 2021

"The hubris of American exceptionalism — a myth of global superiority laid bare in America’s pandemic death toll — is what got us here. We thought we could outsmart our enemies. More hacking, more offense, not better defense, was our answer to an increasingly virtual world order, even as we made ourselves more vulnerable, hooking up water treatment facilities, railways, thermostats and insulin pumps to the web, at a rate of 127 new devices per second.

At the N.S.A., whose dual mission is gathering intelligence around the world and defending American secrets, offense eclipsed defense long ago. For every hundred cyberwarriors working offense — searching and stockpiling holes in technology to exploit for espionage or battlefield preparations — there was often only one lonely analyst playing defense to close them shut."

https://www.nytimes.com/2021/02/06/technology/cyber-hackers-usa.html#click=https://t.co/q9B9rHnsZv

dalton99a

(81,617 posts)
20. The software program is TeamViewer
Mon Feb 8, 2021, 08:33 PM
Feb 2021
https://www.reuters.com/article/us-usa-cyber-florida/hackers-try-to-contaminate-florida-towns-water-supply-through-computer-breach-idUSKBN2A82FV

February 8, 202 13:28 PM Updated an hour ago
Hackers try to contaminate Florida town's water supply through computer breach
By Christopher Bing

(Reuters) - Hackers broke into the computer system of a facility that treats water for about 15,000 people near Tampa, Florida and sought to add a dangerous level of additive to the water supply, the Pinellas County Sheriff said on Monday.

The attempt on Friday was thwarted. The hackers remotely gained access to a software program, named TeamViewer, on the computer of an employee at the facility for the town of Oldsmar to gain control of other systems, Sheriff Bob Gualtieri said in an interview.

“The guy was sitting there monitoring the computer as he’s supposed to and all of a sudden he sees a window pop up that the computer has been accessed,” Gualtieri said. “The next thing you know someone is dragging the mouse and clicking around and opening programs and manipulating the system.”

The hackers then increased the amount of sodium hydroxide, also known as lye, being distributed into the water supply. The chemical is typically used in small amounts to control the acidity of water, but at higher levels is dangerous to consume.

The plant employee alerted his employer, who called the sheriff. The water treatment facility was able to quickly reverse the command, leading to minimal impact.

TeamViewer, which says on its website that its software has been installed on 2.5 billion devices worldwide, enables remote technical support among other applications.

The FBI and Secret Service have been called in to assist in an investigation. Gualtieri said he does not know who is responsible for the cyberattack.

pecosbob

(7,545 posts)
24. Word on Rachel is that this is suspected to be the Russians
Mon Feb 8, 2021, 11:06 PM
Feb 2021

I wonder if this is in retaliation to the U.S. moving strategic bombers to Norway...

Latest Discussions»Latest Breaking News»Someone tried to poison O...