Cyber Hackers Infiltrate Illinois Water Utility: ‘This Could Get Ugly’
- Posted on November 19, 2011 at 12:00am by
Liz Klimas
- Print »
- Email »
Just last month The Blaze reported that cyber attacks on U.S. utilities are on the rise, as more and more hook up to the Internet to synchronize systems. Well, here’s the latest case-in-point.
Wired’s Threat Level reports that attackers with IP addresses based in Russia infiltrated the control system of a water utility in Springfield, Illinois, and destroyed a pump last week. But even though employees at the utility report noticing something fishy, they thought it was just a glitch in the system and analysis has shown the initial hack could have happened in September.
Wired has more:
The hackers were discovered on Nov. 8 when a water district employee noticed problems in the city’s Supervisory Control and Data Acquisition System (SCADA). The system kept turning on and off, resulting in the burnout of a water pump.
[...]
The hackers stole usernames and passwords that the vendor maintained for its customers, and then used those credentials to gain remote access to the utility’s network.
The theft of credentials raises the possibility that other customers using the vendor’s SCADA system may be targeted as well.
“It is unknown, at this time, the number of SCADA usernames and passwords acquired from the software company’s database and if any additional SCADA systems have been attacked as a result of this theft,” the report states, according to Joe Weiss, managing partner of Applied Control Solutions, who obtained a copy of the document and read it to Threat Level.
In the “Public Water District Cyber Intrusion” report released by the Illinois Statewide Terrorism and Intelligence Center, the utility is not named and Weiss expressed frustration, according to CNET, over other utilities not being alerted of the threat. CNET continues:
“This is a really big deal,” said Weiss. The incident has not been disclosed by the Department of Homeland Security’s ICS-CERT (Industrial Control Systems Cyber Emergency Response Team) or any other officials, he said, adding “What are we doing with disclosure?”
The DHS said in a statement to CNET that it was investigating the incident but declined to comment on whether a security breach had occurred.
“DHS and the FBI are gathering facts surrounding the report of a water pump failure in Springfield Ill.,” DHS spokesman Peter Boogaard said in a statement. “At this time there is no credible corroborated data that indicates a risk to critical infrastructure entities or a threat to public safety.”
Weiss said that the statement was “inconsistent” with the report. According to Wired, the report states that the hacked SCADA software vendor that compromised the Illinois utility is located inside the U.S.:
“One thing that is important to find out is whose SCADA system this is,” Weiss said. “If this is a [big software vendor], this could be so ugly, because a biggie would have not only systems in water utilities but a biggie could even be [used] in nukes.”
According to a blog post by Weiss on Control Global, here are actions he thinks should come of this:
- Provide better coordination and disclosure by the government.
- Provide better information sharing with industry.
- Provide control system cybersecurity training and policies.
- Implement control system forensics.
The Blaze’s previous article on infrastructure vulnerability stated that under the current law, it’s completely voluntary for utilities to report threats or hacks to their system.





















Submitting your tip... please wait!
Comments (83)
Pattondog
Posted on November 19, 2011 at 10:02amInteresting Comment:
DHS spokesman Peter Boogaard said in a statement. “At this time there is no credible corroborated data that indicates a risk to critical infrastructure entities or a threat to public safety.”
Why you ask? becuase no one asked them if thier was “a risk to critical infrastructure entities or a threat to public safety” they just said it with out being asked?
Report Post »can you read between the lines, glad my water doenst come from springfield IL. dont worry yet this is just a dry run, no pun intended!
The-Monk
Posted on November 20, 2011 at 11:57pmShould I say OMG or OWS? Either way, I hope Chicago is the first and last to run out of clean water. They deserve no better than the people they are voting for. Right Obama?
Report Post »dizzyinthedark
Posted on November 19, 2011 at 9:41amYou can have these meters removed from your house by calling your power company and demanding they be removed as they are against the law. These meters are NOT federally mandated, the feds can mandate these for federal buildings NOT private residences and businesses!! They emit pulsed radio frequency waves, able to break the blood brain barrier (caution expectant mothers, children, elderly and those with metal implanted in their bodies), FCC data is outdated (1984), pulsed RF waves continually create health hazards and are higher than what your cell phone emits. People experience headaches, migraines, insomnia, dizziness, memory issues, tumors, cancer. Make the call to your power companies, I urge all!!
Report Post »macpappy
Posted on November 19, 2011 at 1:43pmYou could not be more wrong. The meters were installed here in Texas where I live; there was no recourse, and we were even billed for the change. When confronted about the bill, they said that was how it was and if a customer wanted the meter removed, they would be glad to do so. However, the obselite meters were discontinued and could not be replaced. So, go along or go without.
Report Post »Doug in Seattle
Posted on November 19, 2011 at 7:53pmAnd one has to use tin foil hats to avoid one’s thoughts being stolen. Seriously, telemetry breaks the blood-brain barrier?
It’s one thing to be worried about internet based technologies being susceptible to hacking, but you are way out there with your conspiracy bs.
Report Post »just happy
Posted on November 24, 2011 at 10:57amyou can refuse them in Maine. And they will let you keep the old meter. AND if you want to continue to receive power from the same source,( and there is no other option because of the monopoly they are allowed to have), you must pay a one time $40.oo charge, and a $12.50 per month service charge for their having to do more “work” to service your account. More incentive to cut back and find alternatives NOW while we still have a little choice instead of waiting till everything stops under the coming colapse.
Report Post »BurntHills
Posted on November 19, 2011 at 9:28amstock up on water ..that is what we all need after AIR.
Report Post »Gary S
Posted on November 19, 2011 at 2:25pmI pump my own water out of the ground and I poop in the ground. Don’t be a city kitty. Get the H*** out.
Report Post »MachIV
Posted on November 19, 2011 at 4:45pmUnless you own one of the Great Lakes, there is only so much water you can stock up on. A better approach would be storing 10 gallons or so, then having a way to purify your own water. A number of methods and equipment are available to do this.
Report Post »angelonquest2000
Posted on November 19, 2011 at 7:09pm6-8 drops of bleach will purify 1 gallon of water.
Report Post »dalefar
Posted on November 19, 2011 at 9:18amWhat do you expect from an O’Dumbo state.
Report Post »number9
Posted on November 19, 2011 at 8:54amP.S- Stock up on water.
Report Post »jgaltwhois
Posted on November 19, 2011 at 8:18amInvestigate the “smart meter” monitoring devices being forced upon all of us! The City of Naperville owns the electric company and it will be collecting, storing, and sharing each family’s moment to moment electric use without our consenting against our will. A vast military grade wireless network is being installed over our entire city which will gather wirelessly the data from our homes and send it to the city. 57,000 points of entry for hackers. Get the story out about citizens taking action with 4,200 petitions signed in 25 days. napervillesmartmeterawareness.org
Report Post »100 Million Patriots Standing
Posted on November 19, 2011 at 8:44amThere are also Smart Appliances that communicate with that meter which will send out information to the grid. Privacy in your home will be non existent. It will eventually come to the time that you receive a warning and fined for a violation such as falling asleep with the TV on.
If I use $400 worth of electricty in my home for the month of December….There is not one person on earth who needs to know exactly where I used that energy. Keep the h*ll out of my home.
And know that this is a part of the Socialist ‘collective beliefs’. And the United Nations creeping into our bedrooms via Agenda 21….Sustainabliity issues used as a reason to topple our Constitution and freedom.
Report Post »number9
Posted on November 19, 2011 at 8:52amThanks for the web site. Link it to all the local papers and web sites (patch.com, etc), write to them (as if they’d report on it anyhow.) We need to get the word out. ComEd just raised our rates to get this program started and alot of people aren’t aware or just too dang stupid or lazy to care. The control freaks can go pound sand. I’m ticked. Thanks again @JGALTWHOIS! (and I know who in my district voted for this and I’m going to let ALL my neighbors know.)
Report Post »Perspective
Posted on November 19, 2011 at 2:21pmAlso remember that the smart meters are remote control. They can kill your electricity with a keystroke.
Report Post »UrbanCombatSurvivor
Posted on November 19, 2011 at 5:43pmSounds like someone needs to get this information to Anonymous…
Report Post »EqualJustice
Posted on November 19, 2011 at 8:18amI have my chrystal ball… “I see a CRISIS that will NOT be wasted and big brother will take over more of the internet…”
Report Post »BIBLESnGUNS
Posted on November 19, 2011 at 8:13amJust a little food for thought…. People, we live in an open society. Our water supply, as stated many times, should never ever be connected to the internet. Municiple water supplies need to be fenced, and guarded(with weapons). How much chaos could be caused by a very small number of zealots with toxic substances getting at our water supplies???? Entire towns could be wiped out!! Water is the life blood of all of us. In the town which I live, the well fields are about 1.5 miles away from town. Guarding them has never been topic of discussion at a council meeting, I guarantee it! There is great evil running loose in our land, the first step is to recognize it. Get out of the cities if you can, because they are all soft targets if you but know where to hit them. Lock and Load people, this is going to get very ugly before it gets better.
Report Post »yetinate
Posted on November 19, 2011 at 10:34amDid you know? Fencing and guarding a water tower is not as effective as you think. As a FF I realize that every fire hydrant is a weak point in a public system. A $12 dollar wrench is all you need to open a hydrant and put poisin in it that could affect every user downstream. If you dont have a really good filter on hand you will be at the mercy of any 2-bit terrorist. If I can figure this out, the schemers already have. Check out bio filters on line. You can make them out of buckets and gravel. It can clean rainwater runoff. $10 bucks and a little work and you can rest easier with regard to water systems.
PS throw them all out
Report Post »VApatriot2
Posted on November 19, 2011 at 7:50amHmmm, something tells me it’s “BY DESIGN”. No food, (Agriculture Dept. is on top of that one along with Dept. of Energy and FDA), No water….Top down, Bottom Up, Inside out! Please, Mr. Gman, can we have s’more?
Scarey. Preparation should be the word of the day.
Report Post »southernORcobra
Posted on November 19, 2011 at 7:39amwhy the hell is the plant connected to the internet in the first friggin place?
Report Post »Perspective
Posted on November 19, 2011 at 2:29pmMost commercial building systems are controlled by computerized systems and all the rage is making connectivity easier by allowing technicians to log on from anywhere. I have Installed/repaired DDC systems in many applications from clean room labs,OR’s,heating/cooling/lighting,nuclear labs,etc. All these systems can be accessed across the internet if one has the proper codes/passwords. It makes my job easier but also there is a risk that most people discount as “it’ll never happen to us”. I sometimes will program in secondary password routines to lock someone out unless they know the specific passwords that only I know.
Report Post »BloodSweatandTears
Posted on November 20, 2011 at 2:21am@perspective. Thanks for the info. Now if only the passwords could be randomly and routinely changed more often it might add a layer of security. A friend at MIT in computer science is always anxious about the insecurity and weakness of passwords.
Report Post »smackdown33
Posted on November 19, 2011 at 7:24amSpringfield, Illinois, the place where Obama got his start. That would qualify as a stupid place.
Report Post »Carl McPherson
Posted on November 19, 2011 at 6:59amThe water plant deserves to get hacked if they are this stupid.
My professional career is working in drinking water plants as an operator and using SCADA systems.
Rule #1: Never ever hook up the SCADA control system to the internet. EVER! It is completely isolated and separate from the internet so it is physically impossible for a hack to EVER happen.
If this water plant in any way hooked their SCADA system up to the internet their should be a great many people losing their jobs.
This is like running around naked in the mall and getting upset that someone looked at you and took a picture with their phone camera. Utterly retarded !!!
Report Post »Tagudinian
Posted on November 19, 2011 at 7:19amAmen.
Report Post »The-Monk
Posted on November 21, 2011 at 12:48am@Carl McPherson
Report Post »I took one look at your picture and the mask you are wearing and I will call you a LIAR. You don’t work for any water utility and if you do you should be fired. YOU ARE AN OWS COMMUNIST.
I’m sure that GB and team can check out if any “Carl McPherson” works at any water plant in Chicago. SORRY, BUT YOU ARE A BOLD FACED LIAR. Your infiltration of The Blaze is exposed.
dizzyinthedark
Posted on November 19, 2011 at 6:02amThe question posed is “Why is the power grid internet technology?” All part of Barry’s plan to get ALL of the US on board and connected to other nations so we could start buying and selling energy with the world. $3.4 billion was given out by Dept. of Energy to tech companies to develop the technology to handle Smart Meters, electric cars, solar, wind energies, Smart Gas and water meters too. The IEC (International Electrotechnical Commission) laid out a global roadmap to insure interoperability of Smart Grid systems between nations. Once all of America is under the Smart Grid our energy supply and demand will be integrated with all nations. There’s the potential to make billions by controlling the energy of the world to buy and sell. Energy or carbon credits will be the ‘money’ of the future. Remember Moochelle’s words, “Barack knows that we are going to have to make sacrifices; we are going to have to change our conversation; we’re going to have to change our traditions, our history; we’re going to have to move into a different place as a nation.”!!! Barry stated under his plan energy rates will necessarily skyrocket. Get rid of your Smart Meters because they need these meters in order to ‘monitor’ you. Wireless network adds direct linkage to your PC’s and data stored in them. They need every home in America to have a Smart Meter in order for the Grid to be complete. Who will control the world?
Report Post »welloddyfriggindah
Posted on November 19, 2011 at 6:39amThanks for posting.
Report Post »Tagudinian
Posted on November 19, 2011 at 7:25amAmericans always fall victim to the “We are doing this because we are looking out for you,” gambit. Liberals are the masters of this approach and while the country is sleeping they go about with their plans, their schemes with government backing them of course. Behind closed doors the likes of Pelosi, Obama, Barney Frank, Reid, Henry “Nostrilitis” Waxman, Schumer, Clinton, etc. legislate these monstrous bills. One can imagine Gulliver being tied down with a million threads of twine by the Liliputians… America – bound, gagged, close to asphyxiating under this regime!
Report Post »dirtypolitics
Posted on November 19, 2011 at 5:17amSo does it mean that the Obama admin should control or shut down the Internet? NO!
Report Post »dagney tagart
Posted on November 19, 2011 at 4:59amAm I the only one that suspected a cyber attack as the cause of the gulf oil spill. I believe the valves that failed were linked to the internet also. Seemed very convenient to those opposed to drilling but who knows? Just wondering……
Report Post »spirited
Posted on November 19, 2011 at 11:36amNo –you are not alone.
Report Post »UrbanCombatSurvivor
Posted on November 19, 2011 at 5:40pmDefine “cyber attack” here…
I find it pretty damn interesting that TWO HOURS before the “oil spill” there were technicians from Haliburton on that rig servicing the very valves that “broke.”
Report Post »UrbanCombatSurvivor
Posted on November 19, 2011 at 3:46amDoesn’t anyone else find it odd that, yet again, some mysterious thing is coming out of…Chicago? Doesn‘t anyone else think it’s pretty odd that:
The carbon exchange was slated to be based in Chicago.
Report Post »ALL of Cain’s accusers are from…Chicago.
There’s a mysterious “attack” on our power grid in…Chicago, right when Komander Obama is trying to force an internet kill switch “for our protection.”
There sure does seem to be a sudden focus on Obama’s home town, doesn’t there?
fixer
Posted on November 19, 2011 at 10:52amyou’re right!
Report Post »BrianA
Posted on November 19, 2011 at 3:10amI‘ve asked it before and I’ll ask it again…why is any part of our grid connected to the internet?
Report Post »MrMagoo
Posted on November 19, 2011 at 3:26amAn excellent question! WHY?
Report Post »Lord_Frostwind
Posted on November 19, 2011 at 4:04amThe only reason I could imagine would be “convience.” But, that is a pretty weak reason.
There is only one guaranteed 100% effective way to prevent external hacks, and that is using a system that is completely isolated and does not have any connections to outside networks. I’m pretty sure that this is impossible to do with wireless, it would have to be a hard wired system.
Security, it is a serious pain in the neck, especially when a bunch of tech junkies love to make your life difficult.
Report Post »Carl McPherson
Posted on November 19, 2011 at 7:03amIt is not. It is my profession and career as an operator of city drinking water treatment plants that use SCADA systems to control the facility.
You NEVER EVER EVER EVER hook your water system SCADA system up to the internet.
It’s Rule #1 ! NEVER EVER EVER.
This story stinks in 100 different ways. A SCADA system is NEVER hooked up to the internet.
Report Post »The story here is ‘why is the government trying to make people think their water systems are vulnerable to internet hacks’. They are not.
Perspective
Posted on November 19, 2011 at 2:39pmI can answer that. Practically all commercial buildings systems are run by Direct Digital Control systems or Programmable Logic Controllers,DDC and PLC. The rage is sconnecting systems to the internet so that technicians can log onto them from anywhere. I’ve installed/repaired these systems for over 20 yrs in everything from clean labs,lab hoods,heating/cooling systems,domestic water systems,nuclear labs,security access systems, etc. Every sytem I’ve ever worked on was able to be accessed remotely either across phone lines(slightly more secure) or internet. It helps the technician who has to work on the systems but as far as security goes it is a weak spot. I will sometimes program in secondary password routines so that if you don’t know the passwords I created you will be locked out of the system.
Report Post »BloodSweatandTears
Posted on November 20, 2011 at 2:11amThe article stated for synchronization. For waters flowing through and from upstream cities this seems to make sense.
Report Post »The-Monk
Posted on November 21, 2011 at 12:19am@Carl McPherson YOU ARE A LIAR!!!!!
Report Post »After looking at the picture you posted of yourself do you expect any of us to believe you? You are a liar. HEY EVERYONE, LOOK AT HIS PICTURE BEFORE YOU BELIEVE HIS LIES. He does not work for any water utility and if he does…. he is poisoning the water. Just look at his photo. Do you recognize the MASK?
The-Monk
Posted on November 21, 2011 at 1:03am@Carl McPherson
Report Post »I saved a screen shot of your post along with your picture and sent it to http://www.scadasystems.net/
If you do work with these people… you won’t be working there for long or with any company associated with their standards of water control. Love your mask, it says soooo much about you!
TH30PH1LUS
Posted on November 19, 2011 at 3:03amIF you think the Occu-pooper riots are bad now, just wait until a city’s water supply gets shut down. The thin mask of “civilization” will be pulled away, and it will be obvious to all who was ready and who was not.
Report Post »50BMG
Posted on November 19, 2011 at 5:59amBeing prepared is not enough. You also have to be prepared to defend what you have, or to remove yourself, your family, and your emergency supplies to a safe location. If the Occupier mentality should teach us anything, it is that those without always seek – by force, if necessary – to take from those who have.
Report Post »Risagx6
Posted on November 19, 2011 at 1:46amDefinately treason! Everyone from the top down should be replaced!
Report Post »ramburner
Posted on November 19, 2011 at 6:36pmI agree! Does anyone remember what the consequences are for Treason? I think not. Too many would put these people in prison and wait until they break out. I would bring them out back and get the job done just like what was done to Saddam Hussein. Get the gallows ready in every city, this will take months non-stop! Our nation has been infiltrated with Marxist Communists since the 1940′s or even before. Every person who claims to be Progressive is a target. Route them ALL out and replace them in the next election and the elections that follow. We NEED a clean house. Elect Tea Party Candidates from either Party, Republican or Democrat, at least we know they will listen to each other and do what the country needs based on logic and not Party affiliation. Let the Tea Party organization be the screening house for all Candidates in the future. Elect Cain in 2012. Implement Term Limits on the House and Senate and 4 yr terms for both. Maximum 2 terms per person in either, NOT BOTH, the House or Senate. Bring our taxes under control with a VAT on everything – eliminating the income tax in every state and the Fed. Leave the internet alone!
Report Post »Gypsy123
Posted on November 19, 2011 at 1:37amSounds like our country was not prepared for what was coming. Thanks to those at the top.
Report Post »UrbanCombatSurvivor
Posted on November 19, 2011 at 3:48amYou really think some mysterious hacker group of terrorists decided to attack a plant in…Chicago?? Really? Not NY, or LA, or Philadelphia. No city in a foreign country to test the hack…just magically in Obama’s home town?
Report Post »Carl McPherson
Posted on November 19, 2011 at 7:06amWater SCADA systems are not connected to the internet in any way. They are completely hard wire separated from the internet. Never ever ever do you connect them to the internet.
It’s been my profession and career since 1992 to be an operator at a drinking water treatment plant and to use SCADA every day.
You NEVER ever ever attach it to the internet. That’s like asking an electrician to only use wire without insulation or asking a plumber to never use glue or to solder his joints. It’s a professionally forbidden ignorance beyond logic… it goes against every rule… every rule. It just does NOT happen.
Report Post »The-Monk
Posted on November 21, 2011 at 12:51am@Carl McPherson
Report Post »Liar liar face on fire. You are one of the OWS idiots. Too bad you decided to use that mask for your pictuer. We all know exactly who you are now.
plastinoid
Posted on November 19, 2011 at 12:33amDHS is clueless! I am beginning to think that every government employee and agency is conspiring to destroy this country. Why are people who are in charge of these agencies not on trial for either complete incompetency or treason? Can these people really be this stupid? I think it’s time we all buy a pitchfork.
Report Post »CatB
Posted on November 19, 2011 at 12:42amI vote Treason .. even government workers should not be this inept.
TEA!
Report Post »Baddoggy
Posted on November 19, 2011 at 1:00amTreason? Really? No absolute government stupidity and laziness. The Government cant even run a friggin’ post office. This is tad amount to a hole being dug with a backhoe with 5 government employees leaning on shovels watching. They are inept, have no incentive and have lots of power to stop a citizen from saying a damn thing. Bottom line, Government workers SUCK.
Report Post »Snowleopard {gallery of cat folks}
Posted on November 19, 2011 at 1:35amTreason, start with Obama and head downward.
Report Post »pamela kay
Posted on November 19, 2011 at 2:00amThis is only part of the bigger picture that the progressive agenda has instore for us. What a wild ride yet to come.
Report Post »Dalady
Posted on November 19, 2011 at 12:29amAre you prepared?
Report Post »Uncurable wound
Posted on November 19, 2011 at 1:32amCanned squirrels,and plenty to spare!
Report Post »http://www.internet-grocer.net/squirrel.htm
MrMagoo
Posted on November 19, 2011 at 3:28am@Uncurable Wound
From your link:
“Each carcass is inspected twice by line workers to be sure it is hair-free.” LOL:)
Report Post »Y59559
Posted on November 19, 2011 at 12:26amNot sure it is true but South Houston, tx was also hit.
Report Post »Baddoggy
Posted on November 19, 2011 at 7:11amMaybe they willl take out the 5th ward.
Report Post »Stoic one
Posted on November 19, 2011 at 12:15amOh yea the fed is involved..expect the highest efficiency since they are involved.
Report Post »KingCanon
Posted on November 19, 2011 at 12:11amCould get ugly? What a government! Worse, computers will be the death of us all in one way or another.
Report Post »