# FBI announces ongoing Russian attacks against American electric grid, water processing, air

**URL:** <https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635>\
**Category:** Great Debates\
**Created:** [March 16, 2018, 2:01am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635 "2018-03-16T02:01:37Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sunny\_Daze](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunny_daze/32/438_2.png) [@Sunny\_Daze](https://boards.straightdope.com/u/Sunny_Daze)\
**Post date:** [March 16, 2018, 2:01am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/1 "2018-03-16T02:01:37Z")

</div>

[Bloomberg reports that](https://www.bloomberg.com/news/articles/2018-03-15/russian-hackers-attacking-u-s-power-grid-aviation-fbi-warns)

> [@](#):
>
> Russian hackers are conducting a broad assault on the U.S. electric grid, water processing plants, air transportation facilities and other targets in rolling attacks on some of the country’s most sensitive infrastructure, U.S. government officials said Thursday.

These attacks have been traced back to at least March 2016.

> [@](#):
>
> The hackers deliberately selected targets and methodically went after initial victims as a way to reach their ultimate prizes, including industrial control systems used by power plants and other infrastructure. Their tactics included sending spear-phishing emails and embedding malicious content on informational websites to obtain security credentials they could then leverage for more information and access.

There are side references to the cyberattacks in the US sanctions that were just issued. I don’t think those sanctions alone will be enough to stop Russia from continuing to run roughshod over the world. They just keep pushing: An airliner shot down here; A peninsula annexed there; A few assassinations between “friends”. We’re in a new type of war, we’re noticing years too late, and it’s not clear yet whether we’re even going to fight. I’m feeling decidedly gloomy about this whole matter.

How’s your Russian?

---

<div class="post-metadata">

**Author:** ![Aspenglow](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aspenglow/32/76_2.png) [@Aspenglow](https://boards.straightdope.com/u/Aspenglow)\
**Post date:** [March 16, 2018, 2:09am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/2 "2018-03-16T02:09:43Z")

</div>

I just made a post about this in the Clusterfuck thread.

Maddow clarified that the hacking and control is not limited to administrative penetration. The Russians have penetrated actual control of facilities – including nuclear facilities.

---

<div class="post-metadata">

**Author:** ![HurricaneDitka](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@HurricaneDitka](https://boards.straightdope.com/u/HurricaneDitka)\
**Post date:** [March 16, 2018, 2:37am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/3 "2018-03-16T02:37:55Z")

</div>

> [@Aspenglow](#):
>
> … Maddow clarified that the hacking and control is not limited to administrative penetration. The Russians have penetrated actual control of facilities – including nuclear facilities.

Is there a more credible source confirming this?

---

<div class="post-metadata">

**Author:** ![Procrustus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/procrustus/32/2994_2.png) [@Procrustus](https://boards.straightdope.com/u/Procrustus)\
**Post date:** [March 16, 2018, 2:38am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/4 "2018-03-16T02:38:43Z")

</div>

> [@HurricaneDitka](#):
>
> Is there a more credible source confirming this?

New York Times

---

<div class="post-metadata">

**Author:** ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)\
**Post date:** [March 16, 2018, 2:41am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/5 "2018-03-16T02:41:48Z")

</div>

I don’t in any way want to minimize the danger of attacks in the systems controlling our infrastructure. And my limited knowledge of the information security controls at nuclear power plants leads me to believe that the level of security protection of those facilities is really, really lacking. That said, what the Bloomberg article describes sounds like the typical attacks that have been going on for years. US organizations, including privately run infrastructure providers, have been deluged by phishing attacks and watering hole attacks for at least as long as I’ve been in the information security field (10ish years). And almost every network of any degree of complexity is always in some state of compromise. This is not to say we have no reason to worry, just that Russia and China and the DPRK and I’m sure other rivals and enemies of the US have been at this a long time. And, to be fair, I’m sure we’ve been doing it too. We unleashed the Stuxnet attack on Iran, and I doubt we called it quits after that.

---

<div class="post-metadata">

**Author:** ![Aspenglow](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aspenglow/32/76_2.png) [@Aspenglow](https://boards.straightdope.com/u/Aspenglow)\
**Post date:** [March 16, 2018, 2:48am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/6 "2018-03-16T02:48:48Z")

</div>

> [@Bayard](#):
>
> I don’t in any way want to minimize the danger of attacks in the systems controlling our infrastructure. And my limited knowledge of the information security controls at nuclear power plants leads me to believe that the level of security protection of those facilities is really, really lacking. That said, what the Bloomberg article describes sounds like the typical attacks that have been going on for years. US organizations, including privately run infrastructure providers, have been deluged by phishing attacks and watering hole attacks for at least as long as I’ve been in the information security field (10ish years). And almost every network of any degree of complexity is always in some state of compromise. This is not to say we have no reason to worry, just that Russia and China and the DPRK and I’m sure other rivals and enemies of the US have been at this a long time. And, to be fair, I’m sure we’ve been doing it too. We unleashed the Stuxnet attack on Iran, and I doubt we called it quits after that.

The distinction was made that the attacks occurring now are different. There was a private warning made by Homeland Security/FBI last July about how the attacks had changed from attacks on administrative offices to direct control over the infrastructure plants themselves – meaning the ability to turn them on and off. In the Bloomberg piece cited above by **Sunny Daze** , it is noted that this new control includes one nuclear power plant in Kansas.

This new warning jointly issued by Homeland Security/FBI is public, and it includes code that all power plant operators should report if it is found in their systems.

---

<div class="post-metadata">

**Author:** ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)\
**Post date:** [March 16, 2018, 2:49am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/7 "2018-03-16T02:49:18Z")

</div>

BTW, the Bloomberg article mentions that “an industry-government partnership provided potential indicators of compromise” this week. My guess is that they’re referring to InfraGard, which is a partnership between the FBI and private industry, where each shares security information. I’ve been a member off and on for some time. The FBI frequently circulates new attack information to InfraGard members. They’ve been talking about threats to utilities and other services for years. The threat is real, just not in any way new or surprising.

---

<div class="post-metadata">

**Author:** ![HurricaneDitka](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@HurricaneDitka](https://boards.straightdope.com/u/HurricaneDitka)\
**Post date:** [March 16, 2018, 2:53am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/8 "2018-03-16T02:53:46Z")

</div>

[Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors | CISA](https://www.us-cert.gov/ncas/alerts/TA18-074A) appears to be the actual report. I’d politely submit to you that Rachel Maddow and the NYT are full of shit (at least on this point). They don’t appear to have “penetrated actual control of facilities – including nuclear facilities.”

ETA: but I get it, what’s a bit of scare-mongering between friends to sell some advertising, right?

---

<div class="post-metadata">

**Author:** ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)\
**Post date:** [March 16, 2018, 2:57am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/9 "2018-03-16T02:57:22Z")

</div>

> [@Aspenglow](#):
>
> The distinction was made that the attacks occurring now are different. There was a private warning made by Homeland Security/FBI last July about how the attacks had changed from attacks on administrative offices to direct control over the infrastructure plants themselves – meaning the ability to turn them on and off. In the Bloomberg piece cited above by **Sunny Daze** , it is noted that this new control includes one nuclear power plant in Kansas.
> 
> This new warning jointly issued by Homeland Security/FBI is public, and it includes code that all power plant operators should report if it is found in their systems.

It’s late and I’m into my third pint…but my reading of the article is that the plant in Kansas was attacked, and some systems may have been compromised, but I don’t get the sense that anyone has compromised these facilities to the point that they can actually shut them down (yet). And the sharing of code (“Indicators of Compromise”) is a routine part of what InfraGard does.

Again, compromise of critical infrastructure is a real threat, and the bad guys are attempting it every single day. I just don’t see anything in the article that is much different from what we’ve been living with for the better part of a decade.

There may well be Russians lurking around every corner, but these Russians have been lurking around this corner a long time.

---

<div class="post-metadata">

**Author:** ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)\
**Post date:** [March 16, 2018, 3:01am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/10 "2018-03-16T03:01:11Z")

</div>

> [@HurricaneDitka](#):
>
> [Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors | CISA](https://www.us-cert.gov/ncas/alerts/TA18-074A) appears to be the actual report. I’d politely submit to you that Rachel Maddow and the NYT are full of shit (at least on this point). They don’t appear to have “penetrated actual control of facilities – including nuclear facilities.”
> 
> ETA: but I get it, what’s a bit of scare-mongering between friends to sell some advertising, right?

That CERT alert is like 100 I’ve seen before. It’s not that you should now be scared as much as you should have been scared for the past 10 years.

---

<div class="post-metadata">

**Author:** ![Sunny\_Daze](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunny_daze/32/438_2.png) [@Sunny\_Daze](https://boards.straightdope.com/u/Sunny_Daze)\
**Post date:** [March 16, 2018, 3:02am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/11 "2018-03-16T03:02:38Z")

</div>

I also pointed out that we’re seeing an escalation in real world threats in alignment with the cyber attacks, and have been for years if you look back.

2006 Litvenko is killed in Britain with polonium  
2008 Russia invaded Georgia, a pro-West country.  
2014 Russia invades the Ukraine and annexes Crimea (after the Obama reset)  
2014 Malaysian passenger aircraft is shot down over Ukraine  
2016 Election meddling in the US  
[The Washington Post](https://www.washingtonpost.com/news/worldviews/wp/2018/01/10/everything-we-know-so-far-about-russian-election-meddling-in-europe/?utm_term=.f3ff555927cc) printed a story on Russian meddling in 19 other countries, including an attempted coup in Montenegro (?)  
March 2016 cyber hacking attacks on US power grid with the intent to control the infrastructure itself  
March 2017 Russia uses nerve agent in attack on former Russian agent and his daughter in Britain

Step by step they are testing their boundaries and we let them.

All of this in aid of what? Destabilization of the US and her allies at the very least. I would also venture that Russia hopes to expand back to the former borders and status of the USSR. Furthermore, they are attacking us, and our allies, at home. Somehow, here in the US, this has become a conversation about our internal politics and it should not be. It has fuck-all to do with our internal politics, other than that they are a weakness that has been pinpointed very successfully. We are in dismaying disarray.

---

<div class="post-metadata">

**Author:** ![Aspenglow](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aspenglow/32/76_2.png) [@Aspenglow](https://boards.straightdope.com/u/Aspenglow)\
**Post date:** [March 16, 2018, 3:09am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/12 "2018-03-16T03:09:27Z")

</div>

**Bayard** , I’m aware of your points… have a close friend who worked for our little local electric cooperative for years who was also privy to the information you’re sharing. She was quite unnerved by how far the penetration had already gotten, and this was several years ago, as you point out.

This new report was characterized as different, because Russians have apparently now gained the ability to remote-control the actual plants, not just some administrative-type functions. But I’ll be quite happy to be full of shit on this point and defer to your experience.

Are you saying they’ve always been able to remote-control the powering up or shutting down of power infrastructure? Or that it hasn’t actually gotten that far – in which case, why are Bloomberg and other news outlets making it a story, do you think?

---

<div class="post-metadata">

**Author:** ![Aspenglow](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/aspenglow/32/76_2.png) [@Aspenglow](https://boards.straightdope.com/u/Aspenglow)\
**Post date:** [March 16, 2018, 3:27am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/13 "2018-03-16T03:27:13Z")

</div>

**Sunny Daze** , I think all your points are well made. Russia has the West on the ropes and they will take full advantage for as long as we let them.

---

<div class="post-metadata">

**Author:** ![Sunny\_Daze](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunny_daze/32/438_2.png) [@Sunny\_Daze](https://boards.straightdope.com/u/Sunny_Daze)\
**Post date:** [March 16, 2018, 3:27am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/14 "2018-03-16T03:27:47Z")

</div>

**Bayard** I agree with **Aspenglow**. This sounded more like stuxnet-level shenanigans (not necessarily stuxnet-type, if you follow me). That said, I’ve only seen a few press pieces, and the Maddow interview to date.

---

<div class="post-metadata">

**Author:** ![HurricaneDitka](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@HurricaneDitka](https://boards.straightdope.com/u/HurricaneDitka)\
**Post date:** [March 16, 2018, 3:37am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/15 "2018-03-16T03:37:06Z")

</div>

> [@Aspenglow](#):
>
> … Are you saying they’ve always been able to remote-control the powering up or shutting down of power infrastructure? Or that it hasn’t actually gotten that far – in which case, why are Bloomberg and other news outlets making it a story, do you think?

I know this wasn’t addressed to me, but I’m saying it hasn’t actually gotten that far. As for why the media is making a story out of it, I can only speculate, but I speculate that either they believe exaggerating this threat serves their purpose of undermining President Trump, or they’re playing for ratings.

---

<div class="post-metadata">

**Author:** ![Sunny\_Daze](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunny_daze/32/438_2.png) [@Sunny\_Daze](https://boards.straightdope.com/u/Sunny_Daze)\
**Post date:** [March 16, 2018, 3:56am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/16 "2018-03-16T03:56:16Z")

</div>

> [@HurricaneDitka](#):
>
> I know this wasn’t addressed to me, but I’m saying it hasn’t actually gotten that far. As for why the media is making a story out of it, I can only speculate, but I speculate that either they believe exaggerating this threat serves their purpose of undermining President Trump, or they’re playing for ratings.

Your speculation sounds as though you believe this to be fake news.

I am finding accounts of this across most major media now, with varying degrees of detail.

[The Guardian](https://www.theguardian.com/us-news/2018/mar/15/russia-sanctions-energy-sector-cyber-attack-us-election-interference) includes the detail that

> [@](#):
>
> The sanctions were also imposed for the role of Russian intelligence in distributing the NotPetya malware and ransomware which US officials attributed to Moscow in February.
> 
> Officials said it was initially targeted at Ukraine but was allowed to “propagate recklessly without bounds” and caused an estimated $10bn in damage around the world, making it the most damaging cyber-attack in history.

[The New York Times](https://www.nytimes.com/2018/03/15/us/politics/russia-cyberattacks.html)

> [@](#):
>
> The Trump administration accused Russia on Thursday of engineering a series of cyberattacks that targeted American and European nuclear power plants and water and electric systems, and could have sabotaged or shut power plants off at will.
> 
> United States officials and private security firms saw the attacks as a signal by Moscow that it could disrupt the West’s critical facilities in the event of a conflict.

And

> [@](#):
>
> Still, new computer screenshots released by the Department of Homeland Security on Thursday made clear that Russian state hackers had the foothold they would have needed to manipulate or shut down power plants.

The BBC, The FT, and so on, and so on.

I disagree with you as to the motivation of the media for sharing this information. It seems important to me.

---

<div class="post-metadata">

**Author:** ![Mosier](https://avatars.discourse-cdn.com/v4/letter/m/7ea924/32.png) [@Mosier](https://boards.straightdope.com/u/Mosier)\
**Post date:** [March 16, 2018, 4:04am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/17 "2018-03-16T04:04:19Z")

</div>

That NYT article is promising. The Trump administration placing blame on Russia for this sounds like he may be coming around on the Russia issue. I was afraid he would make the same mistake Obama did with ISIS by underestimating them.

---

<div class="post-metadata">

**Author:** ![HurricaneDitka](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@HurricaneDitka](https://boards.straightdope.com/u/HurricaneDitka)\
**Post date:** [March 16, 2018, 4:05am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/18 "2018-03-16T04:05:28Z")

</div>

> [@Sunny\_Daze](#):
>
> Your speculation sounds as though you believe this to be fake news. …

There’s a portion of the story here that I believe to be exaggerated / false. It’s this:

> [@Aspenglow](#):
>
> … The Russians have penetrated actual control of facilities – including nuclear facilities.

> [@Aspenglow](#):
>
> … direct control over the infrastructure plants themselves – meaning the ability to turn them on and off. In the Bloomberg piece cited above by **Sunny Daze** , it is noted that this new control includes one nuclear power plant in Kansas. …

I don’t think the Russians have the ability to shut down any of our power plants at will. The actual alert doesn’t seem to indicate they do. Some shoddy “journalism” seems to have taken some wild-eyed sky-is-falling interpretation of that report and exaggerated it into “Russians can shut down our power plants at will”.

---

<div class="post-metadata">

**Author:** ![Sunny\_Daze](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunny_daze/32/438_2.png) [@Sunny\_Daze](https://boards.straightdope.com/u/Sunny_Daze)\
**Post date:** [March 16, 2018, 4:08am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/19 "2018-03-16T04:08:53Z")

</div>

Perhaps you missed this portion of The New York Times article, from post 16, above

> [@](#):
>
> Still, new computer screenshots released by the Department of Homeland Security on Thursday made clear that Russian state hackers had the foothold they would have needed to manipulate or shut down power plants.

The DHS believes that they do. Considering that we were able to do this to Iran, I don’t find this farfetched in the least.

---

<div class="post-metadata">

**Author:** ![HurricaneDitka](https://avatars.discourse-cdn.com/v4/letter/h/96bed5/32.png) [@HurricaneDitka](https://boards.straightdope.com/u/HurricaneDitka)\
**Post date:** [March 16, 2018, 4:25am UTC](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635/20 "2018-03-16T04:25:42Z")

</div>

> [@Sunny\_Daze](#):
>
> Perhaps you missed this portion of The New York Times article, from post 16, above
> 
> The DHS believes that they do. Considering that we were able to do this to Iran, I don’t find this farfetched in the least.

Let’s start with the basics. The alert opens with this:

> [@](#):
>
> **Systems Affected**
> 
> - Domain Controllers
> - File Servers
> - Email Servers

Do you know a lot of power plants that can be shut down via email?

If they’d actually compromised SCADA systems, why wouldn’t DHS have listed that?

Further down in the alert, at the screenshot portion, it says this:

> [@](#):
>
> In multiple instances, the threat actors accessed workstations and servers on a corporate network that contained data output from control systems within energy generation facilities. The threat actors accessed files pertaining to ICS or supervisory control and data acquisition (SCADA) systems. Based on DHS analysis of existing compromises, these files were named containing ICS vendor names and ICS reference documents pertaining to the organization (e.g., “SCADA WIRING DIAGRAM.pdf” or “SCADA PANEL LAYOUTS.xlsx”).

Please pay attention to this. They got “files pertaining to” control systems. That’s not the same as direct control of the control systems themselves.

I suspect the (heavily redacted) “screenshot” they show is something like one of those Excel spreadsheets or PDFs.

It’s kind of like the difference between having a picture of a nuclear warhead and having the actual nuclear warhead.

[Next page](https://boards.straightdope.com/t/fbi-announces-ongoing-russian-attacks-against-american-electric-grid-water-processing-air/810635.md?page=2)
