惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
WordPress大学
WordPress大学
小众软件
小众软件
云风的 BLOG
云风的 BLOG
IT之家
IT之家
人人都是产品经理
人人都是产品经理
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Last Week in AI
Last Week in AI
博客园 - 【当耐特】
T
Tailwind CSS Blog
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
宝玉的分享
宝玉的分享
博客园 - Franky
F
Fortinet All Blogs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
GbyAI
GbyAI
Hugging Face - Blog
Hugging Face - Blog
Jina AI
Jina AI
D
Docker
博客园 - 聂微东
C
Check Point Blog
H
Help Net Security

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Cybercriminals are interested in your SCADA systems
Intel 471 · 2021-02-13 · via Intel 471 Blog

The public learned this week of an alarming cybersecurity incident that could have physically harmed people: Someone managed to access a system that controlled a Florida city’s water treatment plant, temporarily adjusting sodium hydroxide levels to amounts that could have made the population sick had the chemicals been introduced into the water supply. While city officials caught the action and reversed it within minutes, further reporting has shown the plant had an austere cybersecurity profile that is sadly familiar for public-sector organizations: use of outdated operating systems, disregard for best practices, and lack of a budget to support any real upgrade or staff additions.

The actors in the cybercriminal underground understand that profile fits thousands of enterprises around the world, which gives them a rich target to set their sights on. Within the last year, Intel 471 has seen financially-motivated actors attempt to sell access to SCADA systems tied to water treatment plants. In May 2020, we observed a likely Iranian actor attempt to sell access to a U.S. “hydroelectric power plant.” Further investigation found that what the actor was actually advertising was access to a water treatment plant in Florida, via a virtual network computing (VNC) permission that granted system access to a “Groundwater Recovery & Treatment System.” Additionally, one screenshot showed levels and controls for a sodium hydroxide pump.

To be clear: Although Intel 471 could not definitively confirm or deny a link between the access offered by the actor and the Oldsmar, Florida incident, there was no information that directly tied the two events together at the time this report was published.

The actor shared this information in a Telegram channel that is known for cyberattacks and account cracking. It’s the same channel that has been tied to a December 2020 incident where actors allegedly had access to an unprotected human-machine interface (HMI) system at an Israeli water reservoir.

Although threat actors do not often openly discuss this type of activity, there are those who seek to target ICS or SCADA systems in order to build credibility in the cybercriminal underground. Actors with even a rudimentary understanding of how to use Shodan, a search engine designed to find internet-connected systems, or where to find stolen or default credentials can obtain access to industrial control systems that could lead to incidents like what happened in Oldsmar, Florida.

Internet-connected systems like those that power critical infrastructure sectors are not regarded as a primary target for financially-motivated criminals. However, actors are always refining their methods to find a way to make as much money as possible and boost their reputation and notoriety in the cybercrime ecosystem. Given the wide amount of poorly-guarded systems connected to the internet, it is not without reason to suggest it’s only a matter of time before someone on the cybercriminal underground turns ICS system access to a lucrative pipeline.