Categories: All - medical - malware - access - employee

by Robert Behny 3 years ago

194

Events

Various incidents highlight the vulnerabilities in systems ranging from medical devices to industrial controls. One notable event was the 2008 Spanair flight crash due to a lack of pre-takeoff alarms, resulting in 154 fatalities.

Events

Events

Action

Denial
Deception
Setting

Thermostat

2011 Malware - On August 20, 2008 Spanair flight 5022 crashed just after takeoff from Madrid-Brajas International Airport killing 154. 3 Alarms were not provided to pilots prior to takeoff.

Modification
Function
Settings

Environmental

2009 Security guard accessed Texas hospital’s utilities including pumps and chillers in the operating room. Changed alarms and settings

2012 A computer glitch caused the Superman: Ultimate Flight rollercoaster to become stuck at the top of a 150 foot hill.

RF Crane modification/ movement https://documents.trendmicro.com/assets/white_papers/wp-a-security-analysis-of-radio-remote-controllers.pdf

Vehicle

Jeep Hack https://usa.kaspersky.com/blog/blackhat-jeep-cherokee-hack-explained/5749/

Pump Systems

2012 Nuclear plant water pump shutdown https://www.dailyitem.com/news/computer-problem-prompts-nuclear-reactor-shutdown-at-berwick-area-plant/article_c640a196-f589-5a46-8260-acf037e0d26c.html

2012 A major sewage spill sent 2 million gallons of raw sewage into the Tijuana River in San Ysidro, California. A programmable logic controller failed shutting down pumps and controls.

2021 Florida water treatment plant

Destruction
Direct

printer

Norsk Hydro

Indirect

thermostat

Grocery Store Refrigeration

Shionogi, Inc. OT systems deleted (Pharma) IT servers deleted by former employee. The attack effectively froze operations for a number of days. The company suffered at least $800,000 in losses. 2011

Disk erasing attack - Business IT systems deleted https://en.wikipedia.org/wiki/Shamoon

Stuxnet

Access

open access
intercept/ replay
employee
current
former
hack

Delivery

Remote access
Personal Medical devices

pacemaker

insulin pump

2009 Texas Hospital HVAC operating room
Radio frequency

RF Crane modification

Physical access