• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.
  • We have made minor adjustments to how the search bar works on ResetEra. You can read about the changes here.

GK86

Member
Oct 25, 2017
18,762


Link.

On Monday officials from Pinellas County in Florida announced that an unidentified hacker remotely gained access to a panel that controls the City of Oldsmar's water treatment system, and changed a setting that would have drastically increased the amount of sodium hydroxide in the water supply.

During a press conference, Pinellas County Sheriff Bob Gualtieri said that a legitimate operator saw the change and quickly reversed it, but signaled that the hacking attempt was a serious threat to the city's water supply. Sodium hydroxide is also known as lye and can be deadly if ingested in large amounts.

"The hacker changed the sodium hydroxide from about one hundred parts per million, to 11,100 parts per million," Gualtieri said, adding that these were "dangerous" levels. When asked if this should be considered an attempt at bioterrorism, Gualtieri said, "What it is is someone hacked into the system not just once but twice ... opened the program and changed the levels from 100 to 11,100 parts per million with a caustic substance. So, you label it however you want, those are the facts."

In smaller quantities, sodium hydroxide can cause severe skin burns and eye damage. Small amounts of sodium hydroxide are put in some cities' drinking water supplies to prevent corrosion to pipes and to bring the pH up (it is a strong base).

Gualtieri said that on Friday at 8am a plant operator at the Oldmar's water treatment facility noticed someone remotely accessing the system that he was monitoring. The system was deliberately set up with a piece of remote access software so that "authorized users could troubleshoot system problems from other locations," Gualtieri added.

That instance of remote access was brief, but then it happened again at 1:30 p.m., and the hacker changed the sodium hydroxide levels, Gualtieri said.

"The intruder exited the system, and the plant operator immediately reduced the level back to the appropriate amount of one hundred," Gualtieri added. Gualtieri said that steps were taken to "stop further remote access to the system" and that there are other safeguards to protect the water integrity in place.

The employee is a hero.
 

Poltergust

One Winged Slayer
Member
Oct 25, 2017
11,829
Orlando, FL
Why the fuck would someone do something like that

What a psychopath. I wonder if the source of the hack can be traced.
 

entremet

You wouldn't toast a NES cartridge
Member
Oct 26, 2017
60,069
Thank God they were caught.

Reminds of this:

HhdfiAjjoA12Ei4fV2u4wgAtKOjRVo5eCCDl8O1rQ7Ad7nwa_Bb_AKH4UYz4EaPVh7fUtjjxg4Dcrrd_N6gZp_EmzZj_ZIweDu0GilXeOBEtlPBPHBUl9NTcV_qYbfT_9InNWLBRUXA
 

NPVinny

Member
Dec 13, 2017
791
Good on the employee for being quick to catch it and act upon it before anyone was hurt.

Why is that even a setting though?
 

platocplx

2020 Member Elect
Member
Oct 30, 2017
36,072
How the hell are these systems that easy to change. There def needs to a way better way to protect critical infrastructure like this.
 

Tbm24

Member
Oct 25, 2017
16,293
I think they need to re-think this article. They're a terrorist who attempted to do this via Hacking. Not a Hacker just doing random bullshit on a computer for giggles.
 

Slayven

Never read a comic in his life
Moderator
Oct 25, 2017
93,085

gozu

Member
Oct 27, 2017
10,329
America
Cyberterrorist is an adequate term when someone fucks with drinking water. I'm fine with him going to prison for life.
 
Oct 27, 2017
5,264
Is it weird that my mind immediately jumped "maga cultist?" That can be a dangerous assumption to make but, also, they are prime assholes of our time.
 

ChippyTurtle

Banned
Oct 13, 2018
4,773
ya, that hacker better flee to another country, the FBI and NSA gonna be on his ass rn. unless he was a state actor in which case, welp.
 

gozu

Member
Oct 27, 2017
10,329
America
If people knew how much of daily life is held together by systems patched together with duct tape, chewing gum, and good intentions they would riot

It's not something that I like to think about, honestly. I just have to be in denial about it 99% of the time because, otherwise, I would be either angry or scared all the time.
 

platocplx

2020 Member Elect
Member
Oct 30, 2017
36,072
Hollywood got people fooled
Yup, prime example you could get into a shit load of buildings just by piggy backing off of someone else badging and pretending you belong. Social engineering works very well all the time lmao.

also just our society in general is all invisible agreements. We could decide tomorrow tin foil shit is currency and go for it.
 

turtle553

Member
Oct 25, 2017
2,226
Having worked on water and waste water treatment control systems, the input should have been capped to eliminate someone fat fingering an unsafe level setpoint. Of course if you knew the system better, there would be other ways to mess up supply without being so obvious.
 

Slayven

Never read a comic in his life
Moderator
Oct 25, 2017
93,085
Yup, prime example you could get into a shit load of buildings just by piggy backing off of someone else badging and pretending you belong. Social engineering works very well all the time lmao.

also just our society in general is all invisible agreements. We could decide tomorrow tin foil shit is currency and go for it.
My old job had RFID badges and if you lost them you would have to pay for a new one before you were allowed in. If i left mine at home I would just wait for someone to go in and look like i am busy as hell and follow them. Top Flight Security wouldn't even look at you
 

Valkyr Junkie

Member
Oct 27, 2017
853
Apparently the control system had an externally facing VNC instance, and the technician noticed the mouse cursor moving on its own. Lovely.
 
Oct 27, 2017
6,891
This s*** is terrifying. This is the kind of terrorist act I'll be trying to stop.

Currently trying to get all of my relevant certs and training for Cyber Security.