HomeSecurityHackers accidentally modified water treatment parameters

Hackers accidentally modified water treatment parameters

A group of hackers, who had previously been involved in various hacktivism campaigns, mistakenly accessed an ICS/SCADA system installed at a water treatment facility and changed critical settings that control the amount of chemicals used to treat tap water.

This bizarre hacking incident was described in the 2016 Data Breach Digest (page 38, Scenario 8), a collection of case studies that the company's RISK team came to investigate.

Hackers accidentally modified water treatment parameters

The victim of the breach is a company that Verizon has identified as Kemuri Water Company (KWC). As the RISK team explains, the company noticed that, for a week or two, its water treatment center was behaving erratically, with chemical values ​​changing out of nowhere.

Suspecting that something was wrong – and something that its IT staff was unable to detect – the company brought in Verizon to investigate.

Initially, the RISK team identified a number of issues. First of all, KWC was using extremely outdated computer systems, some of which were running operating systems that were up to ten years old.

Furthermore, the entire IT network revolved around a single piece of equipment, an AS400 system, which was connected to the company's internal IT network and the SCADA systems managing the water treatment plant (a big no-no from a security perspective!).

Even worse, the same AS400 was exposed to the Internet because it routed traffic to a Web server, where KWC customers could check their monthly water bill, their current level of water consumption, and even pay bills through a special payment application.

hackers-modify-water-treatment-parameters-by-accident-502043-3
But Verizon was in for a bigger surprise, because the company's investigation also discovered that there was only one KWC employee managing the AS400 system, meaning that cyberattacks, when the employee was off duty, would have gone undetected and could have easily destroyed the company's business.

After gathering all the basic elements of the network architecture, Verizon’s RISK team proceeded to inspect the logs of the AS400 equipment. By comparing the IPs that had access to the device, security experts quickly found four IPs that were associated with hacktivism campaigns.

Looking deeper into the matter, the RISK team discovered that hackers first breached the system through Web-accessible payment applications, searching for sensitive information about the company's customers.

It appears that the hackers discovered a vulnerability in the payment system, which they used to gain access to the Web server, where they also found an INI file containing administrator credentials, in plain text, for the AS400 equipment.

As their curiosity was piqued, the hackers entered the AS400 system, from where they ended up in the SCADA system and began to modify parameters randomly, unknowingly changing the water treatment values.

Secondary security measures allowed KWC to detect anomalies in the levels of released chemicals, and it was canceled at the hackers' direction, but this happened enough times to raise suspicions that this had to be more than just a malfunction.

After Verizon concluded its investigation, the RISK team assured that there was no malicious activity on the part of the hackers. They also informed the water treatment company that the hackers had access to over 2.5 million personal and financial information of customers and provided technical knowledge on how KWC could patch IT system to prevent similar incidents.

A few weeks ago, there was another breach for Verizon Data Breach Digest, where pirates hired a hacker to break into a shipping company's CMS and steal information about ship routes so they could plan their attacks and go after the most valuable cargo.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS