惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Y
Y Combinator Blog
F
Fortinet All Blogs
H
Hackread – Cybersecurity News, Data Breaches, AI and More
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
aimingoo的专栏
aimingoo的专栏
博客园 - Franky
T
The Blog of Author Tim Ferriss
D
DataBreaches.Net
量子位
博客园 - 三生石上(FineUI控件)
I
InfoQ
Engineering at Meta
Engineering at Meta
WordPress大学
WordPress大学
阮一峰的网络日志
阮一峰的网络日志
爱范儿
爱范儿
D
Docker
美团技术团队
雷峰网
雷峰网
U
Unit 42
Stack Overflow Blog
Stack Overflow Blog
Recent Announcements
Recent Announcements
人人都是产品经理
人人都是产品经理

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Cybercriminals are interested in your SCADA systems
Intel 471 · 2021-02-13 · via Intel 471 Blog

The public learned this week of an alarming cybersecurity incident that could have physically harmed people: Someone managed to access a system that controlled a Florida city’s water treatment plant, temporarily adjusting sodium hydroxide levels to amounts that could have made the population sick had the chemicals been introduced into the water supply. While city officials caught the action and reversed it within minutes, further reporting has shown the plant had an austere cybersecurity profile that is sadly familiar for public-sector organizations: use of outdated operating systems, disregard for best practices, and lack of a budget to support any real upgrade or staff additions.

The actors in the cybercriminal underground understand that profile fits thousands of enterprises around the world, which gives them a rich target to set their sights on. Within the last year, Intel 471 has seen financially-motivated actors attempt to sell access to SCADA systems tied to water treatment plants. In May 2020, we observed a likely Iranian actor attempt to sell access to a U.S. “hydroelectric power plant.” Further investigation found that what the actor was actually advertising was access to a water treatment plant in Florida, via a virtual network computing (VNC) permission that granted system access to a “Groundwater Recovery & Treatment System.” Additionally, one screenshot showed levels and controls for a sodium hydroxide pump.

To be clear: Although Intel 471 could not definitively confirm or deny a link between the access offered by the actor and the Oldsmar, Florida incident, there was no information that directly tied the two events together at the time this report was published.

The actor shared this information in a Telegram channel that is known for cyberattacks and account cracking. It’s the same channel that has been tied to a December 2020 incident where actors allegedly had access to an unprotected human-machine interface (HMI) system at an Israeli water reservoir.

Although threat actors do not often openly discuss this type of activity, there are those who seek to target ICS or SCADA systems in order to build credibility in the cybercriminal underground. Actors with even a rudimentary understanding of how to use Shodan, a search engine designed to find internet-connected systems, or where to find stolen or default credentials can obtain access to industrial control systems that could lead to incidents like what happened in Oldsmar, Florida.

Internet-connected systems like those that power critical infrastructure sectors are not regarded as a primary target for financially-motivated criminals. However, actors are always refining their methods to find a way to make as much money as possible and boost their reputation and notoriety in the cybercrime ecosystem. Given the wide amount of poorly-guarded systems connected to the internet, it is not without reason to suggest it’s only a matter of time before someone on the cybercriminal underground turns ICS system access to a lucrative pipeline.