BSI IT Security Report 2014 – attacks on industrial objectives
BSI (Federal Office for Information Security) published “IT Security Report 2014” (in German), a document with 40 pages of information and reports on cyber security. Probably the most interesting parts of the reports are those in Chapter 3.3 – Security Incidents in the industry. 3.3.1 reports about an APT (Advanced Persistent Threat) attack on a steel factory in Germany. The attack was, as usual, conducted via spear-phishing and social engineering targeting the office employees of the steel factory. Check out this link to see the 28 steel factories in Germany (I can’t guarantee that the number is correct). After the office network was penetrated and malware was running on the computers inside the company network, the attackers went a step further and infected successively computers in the factories. What happened next is a matter which can be truly understood by security experts in ICS/ACS. If you don’t know what it means, read further. Industrial Control Systems (ICS) are those systems that control entire systems in factories, consisting in computers, and devices that belong to the production – in this case, furnaces and their control systems. BSI mentions that the malware attack on the CS of the furnace produced “massive damages to the…