
Various sources reported that the UK had a power plant taken offline in July due to malicious action by Iran-aligned attackers:
Importantly, the attack was not really too sophisticated…it used programable logic controllers, or PLC’s which were exposed to the Internet and were still using default settings like default passwords, which had never been hardened. It is possible that this attack may have simply been a test to prove that the attack could succeed. If the attack was a basic “proof of concept”, the attackers may have been hitting “soft” targets first to organize the Internet addresses to attack, the credentials to use, and the steps to cover-up the attacker’s identity.
The impact was undeniable – roughly four days were spent regaining control of the compromises systems.
Call Dolce Vita IT Solutions LLC at 405-348-1192 or write to lane.griffing@dvits net for more information on penetration testing and vulnerability scanning.
