April 8, 2009 at 5:54 pm #3666ThegmandriveParticipant
WASHINGTON — Cyberspies have penetrated the U.S. electrical grid and left behind software programs that could be used to disrupt the system, according to current and former national-security officials.
The spies came from China, Russia and other countries, these officials said, and were believed to be on a mission to navigate the U.S. electrical system and its controls. The intruders haven’t sought to damage the power grid or other key infrastructure, but officials warned they could try during a crisis or war.
“The Chinese have attempted to map our infrastructure, such as the electrical grid,” said a senior intelligence official. “So have the Russians.”
The espionage appeared pervasive across the U.S. and doesn’t target a particular company or region, said a former Department of Homeland Security official. “There are intrusions, and they are growing,” the former official said, referring to electrical systems. “There were a lot last year.”
Question of the Day
Vote: How worried are you that a cyberattack could damage U.S. infrastructure?Very | Somewhat | Not at all worried
Join the discussion.More
Environment: Will a Smart Grid Repel Attacks?Many of the intrusions were detected not by the companies in charge of the infrastructure but by U.S. intelligence agencies, officials said. Intelligence officials worry about cyber attackers taking control of electrical facilities, a nuclear power plant or financial networks via the Internet.
Authorities investigating the intrusions have found software tools left behind that could be used to destroy infrastructure components, the senior intelligence official said. He added, “If we go to war with them, they will try to turn them on.”
Officials said water, sewage and other infrastructure systems also were at risk.
“Over the past several years, we have seen cyberattacks against critical infrastructures abroad, and many of our own infrastructures are as vulnerable as their foreign counterparts,” Director of National Intelligence Dennis Blair recently told lawmakers. “A number of nations, including Russia and China, can disrupt elements of the U.S. information infrastructure.”
Officials cautioned that the motivation of the cyberspies wasn’t well understood, and they don’t see an immediate danger. China, for example, has little incentive to disrupt the U.S. economy because it relies on American consumers and holds U.S. government debt.
But protecting the electrical grid and other infrastructure is a key part of the Obama administration’s cybersecurity review, which is to be completed next week. Under the Bush administration, Congress approved $17 billion in secret funds to protect government networks, according to people familiar with the budget. The Obama administration is weighing whether to expand the program to address vulnerabilities in private computer networks, which would cost billions of dollars more. A senior Pentagon official said Tuesday the Pentagon has spent $100 million in the past six months repairing cyber damage.
U.S. Intelligence Detects Cyber Spies
WSJ’s Intelligence Reporter Siobhan Gorman says that Intelligence officials have found cyber spies lurking in the U.S. electrical infrastructure.
Overseas examples show the potential havoc. In 2000, a disgruntled employee rigged a computerized control system at a water-treatment plant in Australia, releasing more than 200,000 gallons of sewage into parks, rivers and the grounds of a Hyatt hotel.
Last year, a senior Central Intelligence Agency official, Tom Donahue, told a meeting of utility company representatives in New Orleans that a cyberattack had taken out power equipment in multiple regions outside the U.S. The outage was followed with extortion demands, he said.
The U.S. electrical grid comprises three separate electric networks, covering the East, the West and Texas. Each includes many thousands of miles of transmission lines, power plants and substations. The flow of power is controlled by local utilities or regional transmission organizations. The growing reliance of utilities on Internet-based communication has increased the vulnerability of control systems to spies and hackers, according to government reports.
The sophistication of the U.S. intrusions — which extend beyond electric to other key infrastructure systems — suggests that China and Russia are mainly responsible, according to intelligence officials and cybersecurity specialists. While terrorist groups could develop the ability to penetrate U.S. infrastructure, they don’t appear to have yet mounted attacks, these officials say.
It is nearly impossible to know whether or not an attack is government-sponsored because of the difficulty in tracking true identities in cyberspace. U.S. officials said investigators have followed electronic trails of stolen data to China and Russia.
Russian and Chinese officials have denied any wrongdoing. “These are pure speculations,” said Yevgeniy Khorishko, a spokesman at the Russian Embassy. “Russia has nothing to do with the cyberattacks on the U.S. infrastructure, or on any infrastructure in any other country in the world.”
A spokesman for the Chinese Embassy in Washington, Wang Baodong, said the Chinese government “resolutely oppose
any crime, including hacking, that destroys the Internet or computer network” and has laws barring the practice. China was ready to cooperate with other countries to counter such attacks, he said, and added that “some people overseas with Cold War mentality are indulged in fabricating the sheer lies of the so-called cyberspies in China.”
Utilities are reluctant to speak about the dangers. “Much of what we’ve done, we can’t talk about,” said Ray Dotter, a spokesman at PJM Interconnection LLC, which coordinates the movement of wholesale electricity in 13 states and the District of Columbia. He said the organization has beefed up its security, in conformance with federal standards.
In January 2008, the Federal Energy Regulatory Commission approved new protection measures that required improvements in the security of computer servers and better plans for handling attacks.
Last week, Senate Democrats introduced a proposal that would require all critical infrastructure companies to meet new cybersecurity standards and grant the president emergency powers over control of the grid systems and other infrastructure.
Specialists at the U.S. Cyber Consequences Unit, a nonprofit research institute, said attack programs search for openings in a network, much as a thief tests locks on doors. Once inside, these programs and their human controllers can acquire the same access and powers as a systems administrator.
The North American Electric Reliability Corporation on Tuesday warned its members that not all of them appear to be adhering to cybersecuirty requirements. Read the letter.
The White House review of cybersecurity programs is studying ways to shield the electrical grid from such attacks, said James Lewis, who directed a study for the Center for Strategic and International Studies and has met with White House reviewers.
The reliability of the grid is ultimately the responsibility of the North American Electric Reliability Corp., an independent standards-setting organization overseen by the Federal Energy Regulatory Commission.
The NERC set standards last year requiring companies to designate “critical cyber assets.” Companies, for example, must check the backgrounds of employees and install firewalls to separate administrative networks from those that control electricity flow. The group will begin auditing compliance in July.
—Rebecca Smith contributed to this article.
Write to Siobhan Gorman at email@example.com
Corrections & Amplifications
Central Inteligence Agency official Tom Donahue’s last name was misspelled in a previous version of this article.
April 9, 2009 at 1:55 am #23617
Ya, I saw this go by too. Particularly interesting since large parts of the electrical grid are very difficult to start back up once they go down. Similarly for sewage treatment plants, once they’re without power for a while, the contents become toxic waste. Bad news all the way around.
April 9, 2009 at 3:10 am #23618timmedinParticipant
Last year the CIA reported that power grids around the world had been shut down and been extorted. Not suprised this is happening in the US.
April 9, 2009 at 4:30 am #23619
Commentary from Threat Level on this:
April 10, 2009 at 5:32 am #23620ThegmandriveParticipant
I’m just surprised that this wasn’t , say “Bigger New’s” that is a huge threat to our country, I mean our whole country is pretty much run on electronics of some sort. Just think though if say a well placed EMP went off in the united states. Most cars are now run with computer chips, if those chips were fried, your getting know were fast. 😮 Just freaks me out if all the power went out say in a major city like New York, people would go crazy, and there would be riots… If China wanted to start a war all they would have to do is shut down our power and we would start killing ourselves. LoL enough with my conspiracy theories 🙂
April 11, 2009 at 3:18 am #23621
Yup, its a scary scenario. Check out a novel called Alas Babylon sometime.
April 11, 2009 at 3:20 am #23622crkParticipant
Anyone here read the book “Black Ice”? This is the problem that the entire book is talking about…in it they predicted that cyberterrorism would be picking up in early ’09…guess they were right.
I suppose it doesn’t help that the U.S. is slated to implement that new electrical grid. I think there was something the other day in the Times about how vulnerable to attack such a system would be.
April 13, 2009 at 5:01 pm #23623Don DonzalKeymaster
Here’s a couple more interesting reads from InfoWorld’s Security Newsletter:
CYBER WARS: TURN OUT THE LIGHTS, THE PARTY’S OVER
Actually, don’t bother hitting the light switch, Vladimir or Wen Jiabao will be happy to do it for you. The news this week that our power grid has been infiltrated by bots deposited by Russia, China, and Lord knows who else has put more than a few peoples’ boxers in a bunch. Read on:
CHINA DENIES CYBERATTACKS ON U.S. POWER GRID
Malware attacks from China and Russia designed to shut down the U.S. electrical grid in a time of war did not occur, China said Thursday.”The incident of attacks on the U.S. electrical grid from China and Russia simply does not exist,” Chinese foreign ministry spokeswoman Jiang Yu told reporters. Read on:
Hurry before the power goes out. :'(
April 14, 2009 at 5:41 pm #23624crkParticipant
Interesting side note- There’s an article in this month’s Popular Science about our Chinese hacker problem. Everyone has been blaming the Chinese government for the attacks on the U.S., but evidently one of PopSci’s journalists has come to the conclusion that the problem isn’t the government, it’s ultra patriotic Chinese citizens and underground hacker groups.
April 15, 2009 at 3:31 am #23625timmedinParticipant
A lot of what I have read is saying that it may not be the Chinese in these attacks (I do think it is them attacking the Dhali Lama).
China has a huge number of pirated copies of Windows that they can’t update which translates to massive pwnage, a zombie army, or a good proxy.
- You must be logged in to reply to this topic.