Tex. hack may be first disruption of U.S. water system by Russia

Happy Wednesday! National security reporter Ellen Nakashima here filling in for Cristiano and Will. Reach out with news tips at: [email protected].

Tex. hack may be first disruption of U.S. water system by Russia

amazon, microsoft, tex. hack may be first disruption of u.s. water system by russia

Tex. hack may be first disruption of U.S. water system by Russia

In January, an alert citizen in Muleshoe, Tex., was driving by a park and noticed that a water tower was overflowing. Authorities soon determined the system that controlled the city’s water supply had been hacked. In two hours, tens of thousands of gallons of water had flown into the street and drain pipes.

The hackers posted a video online of the town’s water-control systems and a nearby town being manipulated, showing how they reset the controls. In the video on the messaging platform Telegram, they called themselves Cyber Army of Russia Reborn (CARR).

“We’re starting another raid on the USA,” the video caption reads in Russian, with the hackers saying they would show how they exploited “a couple critical infrastructure facilities, namely water supply systems.” It was followed by a smiley face emoji.

That water tank overflow in a Texas panhandle town may well be linked to one of the most infamous Russian government hacking groups, the cybersecurity firm Mandiant said Wednesday.

If confirmed, analysts say it would mark a worrisome escalation by Moscow in its attempts to disrupt critical U.S. infrastructure by targeting one of its weakest sectors: water utilities.

The hacking group, which private sector analysts once dubbed Sandworm, has achieved notoriety for briefly turning out the lights in parts of Ukraine at least three different times; hacking the Olympics Opening Games in South Korea in 2018; and launching NotPetya, one of the most damaging cyberattacks ever that cost businesses worldwide tens of billions of dollars.

Although no one was hurt and service was not interrupted in Muleshoe, the prospect of Sandworm broadening its sites from Ukrainian power grids and French elections to American critical infrastructure is troubling, Mandiant chief analyst John Hultquist said.

The U.S. government assesses Sandworm to be part of the GRU, Russia’s military spy agency.

The team at Mandiant, which is owned by Google, observed social media accounts being created on YouTube for CARR using servers associated with Sandworm, Hultquist said, adding that Mandiant also has found CARR posting Ukrainian government data stolen by Sandworm hackers on Telegram.

“We’ve been saying for a long time that CARR is just a front for the GRU,” Hultquist said. “Then we see them take credit for these acts in the U.S. against water utilities. Is GRU behind these attacks? If it isn’t GRU, whoever is doing this is working out of the same clubhouse. It’s too close for comfort.”

The U.S. intelligence community has not yet made a determination whether CARR is run by the GRU, although intelligence analysts are scouring clues.

Robert M. Lee, CEO and co-founder of Dragos, which specializes in industrial control system cybersecurity, said a team from his firm tracked CARR’s operations in January. He confirmed the water overflow in Muleshoe but could not specify whether this happened in other towns. “The adversary was definitely looking to do disruptions,” he said, noting that the trend over the last several years has been for state actors to seek to disrupt systems, whereas a decade ago, they were interested mostly in espionage.

Another target was the nearby town of Abernathy. The city’s manager, Don Provost, said in an interview that the hack “didn’t interrupt anything.” The FBI and Department of Homeland Security got in touch quickly, he said.

“It actually turned out to be a good thing,” he said. “It showed us where our vulnerabilities were.”

In an interview, Muleshoe’s city manager, Ramon Sanchez, said the hackers brute-forced the password for the system’s control system interface, which was run by a vendor. That password hadn’t been changed in more than a decade, he admitted.

“You don’t think that’s going to happen to you. It’s always going to happen to the other guy,” he said.

The same vendor was used by at least two other towns in the area that were subjected to attempted hacks, Sanchez said.

But the incident also forced changes. “We learned,” Sanchez said. “The biggest lesson is that we have to always be proactive and always update our cybersecurity.”

He thinks Muleshoe was a “victim of opportunity,” adding: “I would have never thought that somebody tied to the Russian military would target Muleshoe.”

Aaron Schaffer contributed to this report.

Inside the industry

Microsoft invests in Arabic AI firm as U.S. tries to limit China’s sway (By Aaron Gregg and Cat Zakrzewski)

AI is creating an influx of child sex abuse images, data shows (Forbes)

Former OpenAI board member calls for audits of top AI companies (Bloomberg News)

Zuckerberg wins bid to avoid personal liability in addiction lawsuits (The Hill)

Musk’s X retreats, pledging to comply with Brazil court orders (Bloomberg News)

Privacy monitor

Some ex-TikTok employees say the social media service worked closely with its China-based parent despite claims of independence (Fortune)

Workforce report

Amazon HQ2 was supposed to add jobs last year. It shed them instead. (By Teo Armus)

Google workers stage sit-ins to protest company’s work with Israel (By Gerrit De Vynck and Caroline O’Donovan)

Trending

What’s with all the black-and-white logos for apps? (By Shira Ovide)

TikTok is obsessed with … premium-grade industrial glycine from China? (By Leo Sands and Lyric Li)

Mentions

Daybook

  • The House Energy and Commerce Committee holds a hearing, “Legislative Solutions to Protect Kids Online and Ensure Americans’ Data Privacy Rights,” Wednesday at 10 a.m.
  • Semafor hosts its World Economy Summit event Wednesday and Thursday at Gallup’s Great Hall and the Mellon Auditorium.

Before you log off

That’s all for today — thank you so much for joining us! Make sure to tell others to subscribe to The Technology 202 here. Get in touch with Cristiano (via email or social media) and Will (via email or social media) for tips, feedback or greetings!

News Related

OTHER NEWS

Lawsuit seeks $16 million against Maryland county over death of pet dog shot by police

A department investigator accused two of the officers of “conduct unbecoming an officer” for entering the apartment without a warrant, but the third officer was cleared of wrongdoing, the suit says. Read more »

Heidi Klum shares rare photo of all 4 of her and Seal's kids

Heidi Klum posted a rare picture with husband Tom Kaulitz and her four kids: Leni, 19, Henry, 18, Johan, 17, and Lou, 14, having some quality family time. Read more »

European stocks head for flat open as markets struggle to find momentum

This is CNBC’s live blog covering European markets. European markets are heading for a flat open Tuesday, continuing lackluster sentiment seen at the start of the week in the region ... Read more »

Linda C. Black Horoscopes: November 28

Nancy Black Today’s Birthday (11/28/23). This year energizes your work and health. Faithful domestic routines provide central support. Shift directions to balance your work and health, before adapting around team ... Read more »

Michigan Democrats poised to test ambitious environmental goals in the industrial Midwest

FILE – One of more than 4,000 solar panels constructed by DTE Energy lines a 9.37-acre swath of land in Ann Arbor Township, Mich., Sept. 15, 2015. Michigan will join ... Read more »

Gaza Is Falling Into ‘Absolute Chaos,’ Aid Groups Say

A shaky cease-fire between Israel and Hamas has allowed a surge of aid to reach Palestinians in Gaza, but humanitarian groups and civilians in the enclave say the convoys aren’t ... Read more »

Bereaved Israeli and Palestinian families to march together in anti-hate vigil

Demonstrators march against the rise of antisemitism in the UK on Sunday – SUSANNAH IRELAND/REUTERS Bereaved Israeli and Palestinian families will march together as part of an anti-hate vigil on ... Read more »
Top List in the World