Low-sophistication operational technology (OT) attacks grew in frequency and relative severity over the previous few years, according to Mandiant. In doing so, they broadened the type of threat against which companies and governments need to defend their OT assets. Attackers in this area target critical infrastructure. Their attacks can have a physical effect on employees and other people around the affected area.

Read on to learn what these attacks look like and how some of them aren’t always as they appear.

Attackers With Limited OT Expertise

When it comes to OT, threat actors don’t always want to disrupt or modify a control process. Sometimes, they want to take control of internet-facing OT assets. From there, they can leverage that access to spread their political ideas, extort owners or secure bragging rights.

In the past, most amateur OT attacks observed by Mandiant were done by attackers looking for money. More recently, the firm has seen a surge in attempts where attackers are trying to gain control of and scout out critical infrastructure.

Attackers targeted solar energy panels, building automation systems (BAS) and home security systems across a variety of industries.

In March 2020, for instance, Mandiant analyzed screenshots shared by a threat actor who claimed to have compromised dozens of control systems. The unknown attacker also shared a video of what they claimed was a compromised Dutch-language temperature control system.

Another threat actor shared a video in which they used remote connections from their desktop to make set point changes to compromised human-machine interfaces. At one point, that attacker appeared to have accessed a BAS at an Australian hotel.

Not everyone always knows what they’re doing, or, for that matter, what they’re even seeing when it comes to critical infrastructure. In one example cited by Mandiant, for instance, a threat actor claimed to have compromised the control system for a German-language railway. A closer look revealed the attacker had really compromised a command system used with model train sets.

In a similar case, someone claimed they had compromised an Israeli ‘gas system.’ It turned out that they had really taken control of a kitchen fan system at a restaurant in Israel.

A Broader View of the Critical Infrastructure Threat Landscape

The amateur attacks fit into a larger trend of increasing threats involving OT systems. Between 2018 and 2020, for instance, researchers saw a 2,000% increase in threat actors’ attempts to target OT assets and industrial control systems. Many of those attacks relied on vulnerabilities in supervisory control and data acquisition systems and brute force attempts.

The events of 2020 didn’t slow attackers down, either. According to Fortinet, nine out of 10 organizations faced an incident involving their OT in the past year. This finding matched the firm’s 2020 study. Moreover, Fortinet observed that more than half (58%) of these victims had reported a phishing attack — up from 43% a year earlier.

Defending Against OT Attacks

Even amateur OT attacks are nothing to dismiss. They give attackers a chance to learn more about critical infrastructure for staging more campaigns in the future. They normalize OT attacks and thereby invite copycat threat actors. And they could disrupt a physical process that’s essential to the business or nation.

So, organizations need to defend themselves against amateur OT attacks. They can do this by using network segmentation to isolate critical infrastructure OT assets from public-facing networks wherever feasible and using access controls to protect those systems that require remote access. They can also use threat intelligence to keep track of threat actors’ interest in OT assets. They can then implement the right defense measures and run a penetration test as a means of checking those controls.

More from News

More School Closings Coast-to-Coast Due to Ransomware

Instead of snow days, students now get cyber days off. Cyberattacks are affecting school districts of all sizes from coast-to-coast. Some schools even completely shut down due to the attacks. The federal government recently warned that K-12 schools face a growing threat from cyber groups. According to the FBI, school districts often have limited cybersecurity protections, which makes them even more vulnerable. The FBI also says it anticipates the number of threats to increase. In a recent warning, the nation’s…

Hackers are Increasingly Targeting Auto Dealers

Auto dealerships are increasingly concerned with cybersecurity in the face of new regulations and an alarming rise in cyberattacks. The Second Annual Global State of Cybersecurity Report by CDK Global found that 85% of dealerships say cybersecurity is very or extremely important relative to other operational areas. Additionally, 89% say cybersecurity is more important than last year, a 12% increase. Not surprisingly, only 37% of auto retailers are confident in the current protection, which is a 21% decrease from 2021.…

LastPass Breaches Cast Doubt on Password Manager Safety

In 2022, LastPass suffered a string of security breaches which sparked concern among cyber professionals and those impacted by the intrusions. Some called into question the way LastPass handled and responded to the incident. In addition, the situation ignited a wider conversation about the risks linked to utilizing password managers. A password manager helps users generate strong passwords and safeguards them within a digital locker. A master password secures all data, which enables users to conveniently access all their passwords…

Good Guys Decrypt Ransomware Targeting Charitable Groups

Imagine you’re an IT manager amid a ransomware attack. While your team scrambles for solutions, the intruders demand a ransom. Of course, you don’t want to pay; you just want your files back. But as time ticks by and the extortionists turn up the heat, your bosses are about to give in and pay the ransom. But then, the FBI calls. “Don’t pay,” the agent says. “We’ve found someone who can crack the encryption.” Sound too good to be true?…