Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a234340fd81ba9c0

Jump to content

Cyberattacks against infrastructure

From Wikipedia, the free encyclopedia

Infrastructures such as control systems, energy resources, finance, telecommunications, transportation, and water facilities become critical targets of cyberattacks in times of conflict. A report on industrial cybersecurity problems by the British Columbia Institute of Technology and the PA Consulting Group, using data from as far back as 1981, has found a 10-fold increase in the number of successful cyberattacks on Supervisory Control and Data Acquisition (SCADA) systems infrastructure since 2000.[1] Cyberattacks that have adverse physical effects are known as cyber-physical attacks.[2]

Control systems

[edit]

Control systems are responsible for activating and monitoring industrial or mechanical controls. Many devices are integrated with computer platforms to control valves and gates to certain physical infrastructures. Control systems are usually designed as remote telemetry devices that link to other physical devices through internet access or modems. Little security can be offered when dealing with these devices, enabling many hackers or cyberterrorists to seek out systematic vulnerabilities. Paul Blomgren, manager of sales engineering at a cybersecurity firm, explained how employees drove to a remote substation, saw a wireless network antenna, and immediately plugged in their wireless LAN cards. They took out their laptops and connected to the system because it wasn't using passwords. "Within 10 minutes, they had mapped every piece of equipment in the facility", Blomgren said. "Within 15 minutes, they mapped every piece of equipment in the operational control network. Within 20 minutes, they were talking to the business network and had pulled off several business reports. They never even left the vehicle."[3]

Energy

[edit]

Energy is considered an infrastructure that could be attacked[4] and is broken down into two categories: electricity and natural gas.

Electricity powers machines and other mechanisms used in day-to-day life. In the US,cyberterrorists can access data through the Daily Report of System Status that shows power flows throughout the system and can pinpoint the busiest sections of the grid. By disabling those sections, they can locate critical areas of operation to initiate further attacks.

Cyberattacks on natural gas installations are similar, as cyberterrorists can shut down the installations or reroute gas flows to another section. In Russia, a gas supplier known as Gazprom lost control of its central switchboard, which routes gas flow, after an inside job and Trojan horse program bypassed security.[3] The 2021 Colonial Pipeline cyberattack caused a sudden shutdown of the pipeline that carried 45% of the gasoline, diesel, and jet fuel consumed on the East Coast of the United States.

Wind farms, both onshore and offshore, are also at risk. In February 2022, a German wind turbine maker, Enercon, lost remote connection to approximately 5,800 turbines following a large-scale disruption of satellite links. In April 2022, another company, Deutsche Windtechnik, also lost control of roughly 2,000 turbines due to a cyberattack. While the wind turbines were not damaged during these incidents, these attacks show how vulnerable these companies' computer systems are.[5]

Finance

[edit]

Financial infrastructures are increasingly vulnerable to cyberattacks due to their reliance on interconnected computer systems. The financial system's complexity and the constant flow of transactions make it an attractive target for cybercriminals. A significant breach could lead to massive financial losses, erode public trust, and destabilize economies.

The landscape of cyber threats has changed exponentially during the last few years, with threat actors becoming more sophisticated. Estimates from 2014 institutions are subjected to an average of 1,275 cyberattacks per week, a 72% increase since 2019.[6]

A cyberattack on a financial institution or its transactions may be referred to as a "cyber heist". These attacks often begin with phishing campaigns that exploit social engineering tactics to deceive employees into divulging sensitive information. Once inside the network, attackers can deploy keyloggers to capture login credentials and gain unauthorized access to banking systems.

In May 2013, a gang executed a US$40 million cyber heist from the Bank of Muscat.[7] More recently, in March 2025, the hacker collective "Codebreakers" breached Iranian Bank Sepah, exposing over 42 million customer records, including sensitive financial data.[8][circular reference]

Transportation

[edit]

Transportation infrastructure mirrors telecommunication facilities. Impeding transportation in a city or region has economic consequences. Successful cyber attacks can impact scheduling and accessibility, creating a disruption in the economic chain. In January 2003, during the "slammer" virus, Continental Airlines was forced to cancel flights due to computer problems.[3] In May 2015, Chris Roberts, a former cyber consultant, revealed to the FBI that from 2011 to 2014, he had allegedly repeatedly managed to hack into Boeing and Airbus flights' controls via the onboard entertainment system, and had at least once ordered a flight to climb. The FBI, after detaining him in April 2015 in Syracuse, had interviewed him about the allegations.[9]

Water

[edit]

Attacks on water-related infrastructure are the greatest security hazards among all computer-controlled systems. Massive amounts of water unleashed into unprotected areas can cause loss of life and property damage. Sewer systems can be compromised too. The estimated cost to replace critical water systems could be in the hundreds of billions of dollars.[3] Most of these water infrastructures are well developed, making it hard for cyberattacks to cause any significant damage. But equipment failure can occur and cause power outlets to be disrupted temporarily.

In 2024, multiple US water facilities had their industrial equipment compromised by hackers to display anti-Israel messages. Although it resulted in no major damage, the mass attack revealed security vulnerabilities in the United States' water facilities due to a lack of funding and resources.[10]

Waste management

[edit]

In 2023, the Radio Waste Management (RWM) company, owned by the government of the United Kingdom, experienced an unsuccessful cybersecurity breach through LinkedIn. The attack attempted to identify and access the people who were part of the business.[11]

In 2023, Sellafield, the UK's largest and most hazardous nuclear waste disposal site, was targeted by hackers linked to Russia and China. Sleeper malware was discovered inside the site's networks, and it is unknown how long it had been installed or if it had been fully removed. The full extent of the weak security was exposed when staff found they could access Sellafield's servers from outside the site. Reports in 2012 and 2015 reported that the company and its senior management had been aware of the security vulnerabilities, but failed to report or spend resources to address them. As a result, Sellafield's sensitive documents, such as their foreign attack or disaster emergency defense plans and radioactive waste management, may have been compromised.[12]

It is possible for smaller-scale electronics in e-waste to become targets of cyberattacks as well. The PwC estimates that by 2030, the number of Internet of Things (IoT) devices owned around the world would reach over 25 billion. And of that, 70 million tonnes of e-waste will be generated and disposed of. Although only based on anecdotal evidence, it is estimated that the majority of this e-waste may contain components that retain sensitive information and personal data. Cyber criminals may target e-waste from individuals or organizations to gain access to sensitive data that isn't as securely guarded as that on active devices.[13]

Hospitals and medical facilities

[edit]

Cyberattacks on hospital infrastructure could directly lead to deaths. The cyberattacks are designed to deny hospital workers access to critical care systems. Amidst the COVID-19 pandemic, there was a major increase in cyberattacks against hospitals. Hackers locked up networks and demanded ransoms to return access to these systems.[14]

Hospitals and medical facilities have seen increases in ransomware attacks in which criminals encode Protected Health Information (PHI) and other personally identifiable information. When the ransom is paid, the money is exchanged for a key to decode the information and to return the stolen data.[15] Access points into hospital infrastructure are often through third-party companies that hospitals may contract jobs through. The HIPAA Omnibus Rule created in 2013 requires all contracted businesses to perform work for hospitals where patient information would be required to be held to the same standards of security.[16]

An increasingly common access point has been through cameras and security systems that are added to the hospitals' networks. As more outside companies and devices become connected through the internet, the risks for cyberattacks increases. The increase in attacks during the COVID-19 pandemic led researchers to conclude that increased remote work heightened potential areas of vulnerability.[17] One tactic that has been effective in preventing cyberattacks in the healthcare industry is the Zero Trust method, where users known and unknown are viewed as a potential threat and requires everyone to verify their identity with the appropriate credentials.[15]

The increased use of Electronic Medical Records (EMR) required a greater need for security to protect patient information and privacy.[16] When a hospital experiences a data breach in the United States, the facility is required to report the breach to the people impacted under the Health Information Technology for Economic and Clinical Health Act, also called the HITECH ACT, as it has the Breach Notification Rule. The rule states that facilities are required to report data breaches if the facility provides patient care under HIPAA guidelines. The Health Insurance Portability and Accountability Act protects patients' right to privacy regarding their Protected Health Information (PHI).[18] Accessing PHI can be very lucrative for cybercriminals as this information can contain home addresses, Social Security numbers, banking information, and other personally identifiable information.[15]

See also

[edit]

References

[edit]
  1. Linden, Edward. Focus on Terrorism. New York: Nova Science Publishers, Inc., 2007. Web.
  2. Loukas, George (June 2015). Cyber-Physical Attacks A growing invisible threat. Oxford, UK: Butterworh-Heinemann (Elsevier). p. 65. ISBN 978-0-12-801290-1.
  3. 1 2 3 4 Lyons, Marty. United States. Homeland Security. Threat Assessment of Cyber Warfare. Washington, D.C.:, 2005. Web.
  4. Trakimavicius, Lukas. "Protect or Perish: Europe's Subsea Lifelines". Center for European Policy Analysis. Retrieved 2023-07-26.
  5. Trakimavicius, Lukas. "Predators Will Circle Baltic Power Farms". Center for European Policy Analysis. Retrieved 2023-07-26.
  6. Barnes, R.; Chen, L. (2024). "Financial services under siege: Analysis of cyber attack trends 2020–2024". Journal of Financial Security. 8 (2): 112–135. Retrieved 2025-06-24.
  7. "Indian Companies at Center of Global Cyber Heist". onlinenewsoman.com. Retrieved 2025-06-24.
  8. "Codebreakers attack on Bank Sepah". Wikipedia. Retrieved 2025-06-24.
  9. Evan Perez (18 May 2015). "FBI: Hacker claimed to have taken over flight's engine controls". CNN.
  10. Lyngaas, Sean (2024-03-19). "Cyberattacks are hitting water systems throughout US, Biden officials warn governors | CNN Politics". CNN. Retrieved 2024-04-23.
  11. Lawson, Alex; Isaac, Anna (2023-12-31). "Cyber-hackers target UK nuclear waste company RWM". The Guardian. ISSN 0261-3077. Retrieved 2024-04-23.
  12. Isaac, Anna; Lawson, Alex (2023-12-04). "Sellafield nuclear site hacked by groups linked to Russia and China". The Guardian. ISSN 0261-3077. Retrieved 2024-04-23.
  13. PricewaterhouseCoopers. "Critical infrastructure and the e-waste data security threat". PwC. Retrieved 2024-04-23.
  14. "Cyber Daily: Human-Rights Groups Want Law Enforcement to Do More to Stop Hospital Cyberattacks". Wall Street Journal. June 2020. Retrieved 1 June 2020.
  15. 1 2 3 Vukotich, George (2023). "Healthcare and cybersecurity: Taking a Zero trust approach". Health Services Insights. 16. doi:10.1177/11786329231187826. PMC 10359660. PMID 37485022.
  16. 1 2 Yaraghi, Niam (2018). "The Role of HIPAA Omnibus Rules in Reducing the Frequency of Medical Data Breaches: Insights From an Empirical Study". The Milbank Quarterly. 96 (1): 144–166. doi:10.1111/1468-0009.12314. PMC 5835681. PMID 29504206.
  17. Wiggen, Johannes (2020). "The Impact of COVID-19 on Cyber Crime and State-Sponsored Cyber Activities". Konrad Adenauer Stiftung.
  18. Dolezal, Diane (2023). "Effects of internal and external factors on hospital data breaches: Quantitative study". Journal of Medical Internet Research. 25 e51471. doi:10.2196/51471. PMC 10767628. PMID 38127426. ProQuest 2917629718.