3 Out Of 4 US Energy Firms Were Hacked In 2016

Authored by Zainab Calcuttawala via OilPrice.com,

Hackers have targeted Russian oil giant Rosneft, the company said on Tuesday, just as Deloitte released a report on cyber-attacks targeting U.S. oil companies.

A “powerful hacker” attacked the company’s server in an assault that, according to TASS news agency, could be related to ongoing legal proceedings.

A Russian court recently froze assets of a holding company called Sistema as part of a suit lodged by Rosneft and Bashneft. The two companies are trying to recover $2.9 billion lost during Sistema’s 2014 restructuring.

Russian companies are not the only ones facing the new frontier in corporate espionage. U.S. consulting major Deloitte released a report on Monday that said American energy companies showed “limited strategic appreciation” for cyber-threats.

Analysts said three of every four U.S. oil and gas companies experienced a cyber-attack in 2016, but only a few firms said the computerized attacks posed a major security risk.

"Whether hackers use spyware targeting bidding data of fields, malware infecting production control systems, or denial of service that blocks the flow of information through control systems, they are becoming increasingly sophisticated and, specifically alarming, launching coordinated attacks on the industry," the report said.

Low crude prices have caused energy companies to focus their spending on operations that maximize value for shareholders, instead of investing in protective cyber security measures.

On the most vulnerable aspects of the oil and gas supply chain, Deloitte wrote:

Among the upstream operations, development drilling and production have the highest cyber risk profiles; while seismic imaging has a relatively lower risk profile, the growing business need to digitize, e-store, and feed seismic data into other disciplines could raise its risk profile in the future.”


Dammit Walter

This is a *very* serious topic.  Hacking a working field or production facility could interrupt oil flow while systems are down, or Denial-of-Service'd.  Worst case, equipment could be permanently damaged, causing long term shutdown, plus costs to replace, causing significant financial impact to the facility owners and potentially those impacted by supply disruption.  Damages could have severe ripple effect.  Imagine if a coordinated attack took out multiple facilities.  You can bet that major powers and maybe rogue associations are testing and probing for weaknesses and collecting information. 

In reply to

SWRichmond Dammit Walter

Within 90 minutes of the beginning of WW3 absolutely nothing will work.  No power, no fuel pumping stations, no internet, no phones, no water / sewer.  Nothing.  It is all pre-hacked, can't be cleaned up, and there's not a fucking thing you can do about it.  Someone just presses the "execute" button and bammo, nothing works.  Mutual Assured Destruction, circa 2017.  Who needs nukes?The awesome part of that would be that 90% of the commies in cities would die, and quickly.

In reply to by Dammit Walter

asteroids

Stop being stupid. Get a real firewall. Properly design your networks. And for Gawd sake get rid of Windows. If you must, virtualize it and put it in an air-gapped sandbox.

SWRichmond asteroids

Stop being stupid. Get a real firewall. Properly design your networks. If you must, virtualize it and put it in an air-gapped sandbox.hahaha you're funny.  "get a real firewall".  You've got to be shitting me.Instead, let's hire a ridiclously expensive consultant who will baffle us with bullshit and some kewl color graphics, especially one associated with a known corrupt accounting firm.JHFC

In reply to by asteroids

decentraliseds… (not verified)

