CISA Issues Alert On Cyberattacks Targeting Oil And Gas Infrastructure

Photo by Zbynek Burival on Unsplash

CISA Issues Alert On Cyberattacks Targeting Oil And Gas Infrastructure

Reading time: 2 min

The Cybersecurity and Infrastructure Security Agency of the United States (CISA) issued an alert on Tuesday, warning that cyber actors are targeting oil and natural gas infrastructure. While the techniques used are not advanced, the agency raises concerns over “poor cyber hygiene” within companies and organizations in the sector.

In a rush? Here are the quick facts:

  • CISA issued an alert warning about basic cyberattacks targeting oil and gas infrastructure.
  • The agency raised concerns over “poor cyber hygiene” within companies in the industry.
  • Owners and operators have been encouraged to review a document with mitigation recommendations and take action.

According to the alert, titled Unsophisticated Cyber Actor(s) Targeting Operational Technology, the malicious actors have been focusing on energy and transportation systems.

“Although these activities often include basic and elementary intrusion techniques, the presence of poor cyber hygiene and exposed assets can escalate these threats, leading to significant consequences such as defacement, configuration changes, operational disruptions, and, in severe cases, physical damage,” states the document.

CISA shared a fact sheet with guidelines on how to mitigate risks, Primary Mitigations to Reduce Cyber Threats to Operational Technology, and urged infrastructure owners and operators in the industry to read it and act to improve cybersecurity as soon as possible.

The document, issued by CISA, the FBI, EPA, and DOE, contains mitigation recommendations such as removing operational technology connections to the public internet, using strong, unique passwords, securing remote access, and maintaining manual controls operational.

“Cyber threat actors use simple, repeatable, and scalable toolsets available to anyone with an internet browser,” reads the document regarding data accessible through the public internet. “Critical infrastructure entities should identify their public-facing assets and remove unintentional exposure.”

The governmental agencies also advise owners and operators to communicate with third-party system services providers about this alert, get guidance, and work together to safeguard operational technologies.

Although the threats are not serious, as they involve basic attacks using rudimentary technology, institutions remain alert to these and other threats. A few weeks ago, two chief architects behind CISA’s Secure by Design program resigned and urged companies to build safe products.

Did you like this article? Rate it!
I hated it I don't really like it It was ok Pretty good! Loved it!

We're thrilled you enjoyed our work!

As a valued reader, would you mind giving us a shoutout on Trustpilot? It's quick and means the world to us. Thank you for being amazing!

Rate us on Trustpilot
0 Voted by 0 users
Title
Comment
Thanks for your feedback