2:15pm UK, Wednesday November 23, 2011
Hannah Thomas-Peter, US reporter
The FBI and the Department of Homeland Security (DHS) are looking into what could be the first known foreign cyber attack to damage an American industrial system.
Federal investigators confirmed to Sky News they were examining reports that a foreign hacker or hackers managed to remotely gain access to a water facility in Illinois and shut down a pump on November 8.
The incident came to light after prominent cyber security expert Joe Weiss obtained a report written by the Illinois Statewide Terrorism and Intelligence Centre.
According to Mr Weiss, who specialises in protecting industrial control systems from electronic threats, the report confirms the cyber attack was traced back to a computer in Russia.
He told Sky News: "The report says 'An information technology services and computer repair company checked the computer logs of the system and determined the computer had been hacked into from an internet provider address located in Russia.'"
DHS spokesman Peter Boogaard said: "At this time there is no credible corroborated data that indicates a risk to critical infrastructure entities or a threat to public safety."
Mr Weiss, a control systems cyber security consultant and managing partner at Applied Control Solutions based in California, said he did not understand the equivocation from DHS, and that the report was definitive, even if it did not explain the attacker's motives.
He said: "The title of the report is Public Water District Cyber Intrusion. That's kind of hard to work around. Something happened."
The cyber attack reportedly targeted a water facility in a rural area west of the state capital, Springfield.
Don Craven, a lawyer and a trustee for the Curran-Gardner Township Public Water District, said: "We are aware there may have been a successful or unsuccessful attempt to hack into the system.
"It came through a software system that's used to remotely access the pumps," he said. "A pump is burned out."
According to the report obtained by Mr Weiss, the attackers got into the company's network using credentials stolen from a firm that makes software used to control industrial systems.
Mr Weiss explained: "The problem is that a software system used by that little company in Illinois is the same system used by chemical plants, refineries, gas pipelines, electrical plants, in New York, London, Liverpool, everywhere.
A virus attack hit an Iranian nuclear plant last year
"If someone has potentially worked out how to compromise it remotely and in the way described in the report, then every company and utility relying on that software is vulnerable."
The system he is referring to is called Supervisory Control and Data Acquisition (SCADA), a highly specialised computer system that is used to control critical infrastructure.
It was in the headlines last year after a Stuxnet virus attack on a centrifuge at a uranium enrichment facility in Iran.
Representative Jim Langevin, a Democrat from Rhode Island, said that the report of the attack proved the need to improve cyber security of America's critical infrastructure.
In a statement he said: "The stakes are too high for us to fail, and our citizens will be the ones to suffer the consequences of our inaction."
Hannah Thomas-Peter, US reporter
The FBI and the Department of Homeland Security (DHS) are looking into what could be the first known foreign cyber attack to damage an American industrial system.
Federal investigators confirmed to Sky News they were examining reports that a foreign hacker or hackers managed to remotely gain access to a water facility in Illinois and shut down a pump on November 8.
The incident came to light after prominent cyber security expert Joe Weiss obtained a report written by the Illinois Statewide Terrorism and Intelligence Centre.
According to Mr Weiss, who specialises in protecting industrial control systems from electronic threats, the report confirms the cyber attack was traced back to a computer in Russia.
He told Sky News: "The report says 'An information technology services and computer repair company checked the computer logs of the system and determined the computer had been hacked into from an internet provider address located in Russia.'"
DHS spokesman Peter Boogaard said: "At this time there is no credible corroborated data that indicates a risk to critical infrastructure entities or a threat to public safety."
Mr Weiss, a control systems cyber security consultant and managing partner at Applied Control Solutions based in California, said he did not understand the equivocation from DHS, and that the report was definitive, even if it did not explain the attacker's motives.
He said: "The title of the report is Public Water District Cyber Intrusion. That's kind of hard to work around. Something happened."
The cyber attack reportedly targeted a water facility in a rural area west of the state capital, Springfield.
Don Craven, a lawyer and a trustee for the Curran-Gardner Township Public Water District, said: "We are aware there may have been a successful or unsuccessful attempt to hack into the system.
"It came through a software system that's used to remotely access the pumps," he said. "A pump is burned out."
According to the report obtained by Mr Weiss, the attackers got into the company's network using credentials stolen from a firm that makes software used to control industrial systems.
Mr Weiss explained: "The problem is that a software system used by that little company in Illinois is the same system used by chemical plants, refineries, gas pipelines, electrical plants, in New York, London, Liverpool, everywhere.
"If someone has potentially worked out how to compromise it remotely and in the way described in the report, then every company and utility relying on that software is vulnerable."
The system he is referring to is called Supervisory Control and Data Acquisition (SCADA), a highly specialised computer system that is used to control critical infrastructure.
It was in the headlines last year after a Stuxnet virus attack on a centrifuge at a uranium enrichment facility in Iran.
Representative Jim Langevin, a Democrat from Rhode Island, said that the report of the attack proved the need to improve cyber security of America's critical infrastructure.
In a statement he said: "The stakes are too high for us to fail, and our citizens will be the ones to suffer the consequences of our inaction."