{"id":14050,"date":"2021-02-09T12:16:22","date_gmt":"2021-02-09T17:16:22","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=14050"},"modified":"2023-04-10T17:04:46","modified_gmt":"2023-04-10T21:04:46","slug":"hacker-breaches-florida-water-treatment-plant-adds-lye-to-citys-water-supply","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/hacker-breaches-florida-water-treatment-plant-adds-lye-to-citys-water-supply\/","title":{"rendered":"Hacker Breaches Florida Water Treatment Plant, Adds Lye to City\u2019s Water Supply"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-an-unknown-hacker-virtually-infiltrated-the-city-of-oldsmar-s-water-treatment-plant-twice-to-increase-its-levels-of-sodium-hydroxide-lye-before-super-bowl-sunday-weekend\">An unknown hacker virtually infiltrated the city of Oldsmar\u2019s water treatment plant \u2014 twice \u2014 to increase its levels of sodium hydroxide (lye) before Super Bowl Sunday weekend<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Tampa Bay is riding high after Sunday night\u2019s Super Bowl IV win. But things for a lot of residents of the Bay area could have gone in a less-than-celebratory direction if it wasn\u2019t for the keen eye of one water treatment employee.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.pcsoweb.com\/\">Pinellas County Sheriff<\/a> Bob Gualtieri reported a significant security breach during a news conference on Monday. An unknown hacker remotely accessed systems that control the Oldsmar water treatment plant\u2019s operations and treatment chemical levels. The goal? To increase the plant\u2019s level of sodium hydroxide to dangerous levels.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For those of you who bombed your high school science classes, <a href=\"https:\/\/www.atsdr.cdc.gov\/MMG\/MMG.asp?id=246&amp;tid=45\">sodium hydroxide<\/a> \u2014 or what\u2019s also known as lye \u2014 is a highly caustic chemical. In fact, it\u2019s one of the main ingredients of drain cleaners. When used at safe levels, this corrosive material removes metals from drinking water and changes water acidity levels. But when those levels are increased, it can:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Severely damage your lungs when inhaled,<\/li>\n\n\n\n<li>Burn your mouth, tongue, and esophagus when swallowed, and<\/li>\n\n\n\n<li>Cause significant illness, gastrointestinal perforation, and death. &nbsp;<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This topic strikes particularly close to home seeing as how Oldsmar is about a 30-minute drive north of our company\u2019s home office. Luckily for those potentially affected residents of Pinellas County, a plant operator noticed what was happening and managed to catch it before it could do any damage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We\u2019ll give you the lowdown of what occurred and what other municipalities and businesses can do to prevent similar intrusions into their computer systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-breaking-down-the-situation\">Breaking Down the Situation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Although it resembles the plot of the 2005 movie \u201cBatman Forever,\u201d what happened on Feb. 5 was anything but fiction. In a nutshell, an unknown hacker infiltrated the <a href=\"https:\/\/www.myoldsmar.com\/\">city of Oldsmar<\/a>\u2019s computer system via its remote access software to increase levels of a dangerous water treatment chemical.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Like some other cities in Pinellas County, Oldsmar is one that has its own water treatment facility. This dedicated facility provides the drinking water to businesses in the area as well as the city\u2019s <a href=\"https:\/\/datacommons.org\/place\/geoId\/1251350\">nearly 15,000 residents<\/a>. Other cities get their water from the County, which pipes water from Tampa Bay Water.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a quick overview of what occurred:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>At 8 a.m., a plant operator noticed someone briefly accessing the computer system he was monitoring remotely.<\/strong> This system controls the chemicals and water plant operations. This type of activity didn\u2019t really stand out because the system was set up to allow remote access by authorized users. This way, they can troubleshoot issues from other locations.<\/li>\n\n\n\n<li><strong>At 1:30 p.m., someone again remotely accessed the system the same plant operator was monitoring.<\/strong> The access lasted a total of three to five minutes. But in this time, the employee watched the mouse on their screen begin moving. The mouse accessed various software functions that control water treatment functions, including the function that controls the water\u2019s levels of sodium hydroxide. They changed it from 100 parts per million (ppm) to 11,100 ppm. &nbsp;<\/li>\n\n\n\n<li><strong>Once the hacker exited the system, the plant operator immediately changed the chemicals back to their normal levels. <\/strong>After that, he immediately notified his supervisor about what had transpired. Oldsmar City Manager Al Braithwaite says that they\u2019ve disabled the remote access software to prevent this <a href=\"https:\/\/www.thesslstore.com\/blog\/the-top-9-cyber-security-threats-that-will-ruin-your-day\/\">cyber threat<\/a> from reoccurring. He also said they \u201care going to make some upgrades to other parts of the system to try and ensure that it doesn\u2019t happen again.\u201d<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Gualtieri held a press conference on Monday, Feb. 8 to discuss the details of the virtual breach of this city\u2019s critical infrastructure. In it, he offered the following reassurances:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cBecause the operator noticed the increase and lowered it right away, at no time was there a significant adverse effect on the water being treated. More importantly, the public was never in danger. Even if the plant operator had not quickly reversed the increased amount of sodium hydroxide, it would have taken between 24 and 36 hours for that water to hit the water supply system, and there are redundancies in place where the water had been checked before it was released.\u201d<\/em><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s a link to the press conference here so you can see it for yourself (if you\u2019re so inclined):<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Treatment Plant Intrusion Press Conference\" width=\"960\" height=\"540\" src=\"https:\/\/www.youtube.com\/embed\/MkXDSOgLQ6M?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-s-still-unknown\">What\u2019s Still Unknown<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Pinellas County Sheriff\u2019s Office (PCSO) has launched a criminal investigation. They\u2019re working with the FBI and the U.S. Secret Service as part of their investigation. However, some things are still unknown about the attack at this time:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Who is responsible for the breach.<\/strong> Authorities say they\u2019re uncertain about whether one person, two people, or a group of people were involved.<\/li>\n\n\n\n<li><strong>How the breach occurred<\/strong>. They know that the access occurred via the computer system\u2019s remote access software. However, they\u2019ve not disclosed whether the<\/li>\n\n\n\n<li><strong>Whether the attack originated in the U.S. or abroad. <\/strong>Sheriff Gualtieri says that it\u2019s unknown at this time whether the attacker was someone local, elsewhere in the U.S., or if it could be an international or nation-state actor.<\/li>\n\n\n\n<li><strong>No reports of any other systems being unlawfully accessed. <\/strong>The Sheriff and city officials say that they\u2019re unaware of any similar attacks occurring<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-went-well-in-this-situation\">What Went Well in This Situation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Obviously, if things had gone in an entirely wrong direction, then we\u2019d be writing a very different article right now. Thankfully, though, there was an unnamed employee who was actively monitoring the city\u2019s computer systems. The employee recognized the unusual activity and acted quickly to mitigate the threat by reversing the attacker\u2019s changes to the sodium hydroxide levels.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Furthermore, the city has redundancies and sensors in place that would catch the changes in the water before it made it to Oldsmar homes and businesses. So, even if the employee hadn\u2019t observed the attack as it was happening, city official say that the water would have triggered alerts well before it would have posed a danger to residents.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are a lot of different industries that fall under the umbrella of \u201ccritical infrastructure.\u201d For example:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Heathcare and emergency services<\/li>\n\n\n\n<li>Military and defense<\/li>\n\n\n\n<li>Water utilities<\/li>\n\n\n\n<li>Utility companies<\/li>\n\n\n\n<li>Cable providers<\/li>\n\n\n\n<li>Cellular providers<\/li>\n\n\n\n<li>Transportation and roadways<\/li>\n\n\n\n<li>Sanitation organizations<\/li>\n\n\n\n<li>Food and agriculture<\/li>\n\n\n\n<li>Building and structural organizations<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-a-few-key-takeaways\">A Few Key Takeaways<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">So, what are the big takeaways from this situation for governments, businesses and other organizations that manage our local, state, or national critical infrastructure?<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>If you haven\u2019t already done so, draft and implement computer security and monitoring protocols.<\/li>\n\n\n\n<li>Actively review those protocols to ensure they\u2019re up to date and in alignment with current industry best practices.<\/li>\n\n\n\n<li>Have redundancies in place to serve as fail safes. &nbsp;<\/li>\n\n\n\n<li>If you\u2019re using any remote access software, be sure to keep it patched and up to date with the latest manufacturer releases. Also be sure to use very strict access control, such as two-factor authentication (preferably <a href=\"https:\/\/www.thesslstore.com\/blog\/put-your-risk-on-mute-using-pki-to-simplify-remote-workforce-security\/\">PKI and\/or hardware token-based<\/a>).<\/li>\n\n\n\n<li>The same can be said with other IT hardware and software updates \u2014 don\u2019t wait until there\u2019s another Eternal Blue situation. Regularly perform updates and patching to keep your systems in tip-top shape.&nbsp;<\/li>\n\n\n\n<li>Run vulnerability and risk assessments to discover any exploits that cybercriminals can use to breach your network and other systems.<\/li>\n\n\n\n<li>Provide cyber awareness training to your employees and other system users. This way, they are less likely to fall for any <a href=\"https:\/\/www.thesslstore.com\/blog\/10-types-of-phishing-attacks-and-phishing-scams\/\">phishing scams<\/a> that could result in credential theft or disclosure.<\/li>\n<\/ul>\n\n\n<span style=\"display:none\" class=\"tl-placeholder-f-type-shortcode_12768\"><\/span>\n\n\n<p class=\"wp-block-paragraph\">To wrap up this article, it\u2019s fitting to include one last quote from Sheriff Gualtieri to help drive home the importance of making these preparations:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><em>\u201cThis type of activity in this type of hacking of critical infrastructure is not necessarily limited to water supply systems. It can be anything. It could be sewer systems, it could be a whole variety of things that could really be problematic, and this is where we want to make sure that we\u2019re paying close attention to all of it.\u201d<\/em><\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>An unknown hacker virtually infiltrated the city of Oldsmar\u2019s water treatment plant \u2014 twice \u2014 to increase its levels of sodium hydroxide (lye) before Super Bowl Sunday weekend Tampa Bay&#8230;<\/p>\n","protected":false},"author":17,"featured_media":14053,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13107,16],"tags":[10272,167,13117],"class_list":["post-14050","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-hashed-out","category-hashing-out-cyber-security","tag-cyber-attacks","tag-cybercrime","tag-hacker","post-with-tags"],"views":13155,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/02\/water-treatment-plant-hacker-breach-feature.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/14050","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=14050"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/14050\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/14053"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=14050"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=14050"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=14050"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}