How Did the Florida Water Plant Breach Happen?

915 views
•
February 10, 2021
by
RSAC Cybersecurity
YouTube video player
How Did the Florida Water Plant Breach Happen?

TL;DR

Unauthorized access through TeamViewer let an intruder manipulate a chemical setting in the Oldsmar water treatment system, but an operator saw the activity, reversed the change, and prevented harm. The incident shows how ordinary remote administration tools, aging industrial systems, and simple human-machine interfaces can expose critical infrastructure to physical danger and service disruption.

Transcript

Hello, RSA Conference community. I am Cecilia Marigney, program manager of innovation and scholars at the RSA Conference. Today, I have the pleasure to interview CEO and founder of Skyth, Bryson Bort. Bryson is also the co-founder of the ICS Village, one of the seven villages we'll be bringing to RSA Conference in 2021. He and Tom Van Norman have f... Read More

Key Insights

  • The breach was an unauthorized TeamViewer session that gave an intruder remote access to the water plant's control environment. TeamViewer was described as a common tool for troubleshooting and remote computer administration in information technology settings.
  • The operator was able to prevent harm because the intrusion occurred during business hours and was visible on the screen. The operator watched the mouse move, observed a chemical setting being altered, and restored the original value after the intruder disconnected.
  • The attempted manipulation involved changing a chemical additive to a potentially dangerous level. No actual damage occurred because the operator immediately corrected the setting, but the event demonstrated that computer access can create physical consequences in critical infrastructure.
  • Industrial control systems are built for long duty cycles, high availability, and uptime. According to Bort, they are often at least 20 years old and were not designed around routine security patching, which creates challenges that differ from conventional information technology environments.
  • The attack apparently used the system as designed rather than exploiting a specialized industrial-control flaw. The security problem was that an unauthorized person could issue legitimate commands and push an operational process outside its intended tolerance.
  • Ransomware is a major concern for critical infrastructure because it can interrupt essential operations even without directly manipulating a dangerous physical process. Bort warns that a water municipality could be taken offline for a period, resulting in a disruption of service.
  • The attack was more likely the work of an opportunistic amateur than a sophisticated attacker, according to Bort's assessment of the visible tradecraft. Acting during regular business hours without concealing the activity allowed the operator to observe and reverse the changes.
  • A human-machine interface can make industrial processes understandable to someone without deep technical knowledge. A simple visual display may let an intruder change operational values by clicking images and editing numbers, even if that person does not understand the underlying control system.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How did the Oldsmar water treatment plant breach happen?

The intruder apparently gained unauthorized access through TeamViewer, a remote desktop application commonly used for troubleshooting and computer administration. During business hours, the plant operator watched the cursor move across the screen and saw a chemical additive setting changed to a potentially dangerous level. The intruder then logged out, and the operator restored the correct setting before any actual damage occurred.

Q: What did the intruder change at the Florida water plant?

The intruder changed the setting for a chemical additive used in the water treatment process, raising it to what could have been a dangerous level. The transcript does not identify the chemical or provide the setting values. Because an operator directly observed the unauthorized activity and reversed the change after the intruder disconnected, the manipulation did not cause actual damage.

Q: Why did the Florida water plant breach cause no damage?

The breach caused no actual damage because a plant operator was present and could see the remote activity on the screen. The operator watched the unauthorized user move the mouse and modify a chemical setting. After the user logged out, the operator immediately changed the setting back, stopping the attempted manipulation before it could produce harmful physical consequences.

Q: Was outdated software responsible for the water plant attack?

Based on the information available in the interview, the breach was performed through TeamViewer rather than attributed to obsolete industrial software. Bort notes that industrial control systems are often old, difficult to patch, and designed for uptime instead of security. In this case, however, the attacker appears to have used an existing remote-access function to send unauthorized operational commands.

Q: Why are industrial control systems difficult to secure?

Industrial control systems are designed for long duty cycles, high availability, and continuous uptime. Bort says they are often at least 20 years old and were not originally designed for security or routine patching. Their computers also control physical processes, so unauthorized commands can create consequences beyond data loss, including disrupted services and potential risks to life or limb.

Q: Was the water plant intrusion a sophisticated cyberattack?

Bort considers an opportunistic amateur more likely than a sophisticated attacker, although attribution remains speculative. The intruder operated during normal business hours and apparently made no effective attempt to hide the on-screen activity. That behavior allowed the operator to see the cursor movements and chemical-setting change, then reverse the action immediately after the unauthorized session ended.

Q: How could a human-machine interface help an intruder alter a water system?

A human-machine interface presents an industrial process through a comparatively simple visual display. Bort says the intruder most likely reached this interface and could therefore make changes by clicking a picture and editing numbers. This means a person may manipulate operational settings without understanding the underlying industrial equipment, control logic, or complete water treatment process.

Q: Why is ransomware a threat to critical infrastructure?

Ransomware can threaten critical infrastructure by disrupting essential operations, even when attackers do not directly manipulate equipment to cause physical harm. Bort gives the example of a water municipality being taken offline for some period, which would interrupt service. He expects ransomware to continue rising and identifies critical infrastructure as particularly vulnerable to this type of attack.

Summary & Key Takeaways

  • An unauthorized person accessed the Oldsmar water treatment plant through TeamViewer during business hours. The operator watched the mouse move and saw a chemical additive setting changed to a potentially dangerous level. After the intruder logged out, the operator restored the setting, so the event caused no actual damage.

  • Bryson Bort distinguishes industrial control systems from ordinary computers by their long service lives, high-availability requirements, and limited support for security updates. In this incident, however, the apparent issue was not obsolete software. The intruder used a legitimate remote-access capability to send unauthorized commands that pushed a process outside acceptable tolerance.

  • The incident illustrates how cyber risk can extend beyond stolen information into physical harm and disrupted essential services. Bort identifies ransomware as another growing concern for critical infrastructure and argues for accessible education about programmable logic controllers, human-machine interfaces, and operational processes through realistic demonstrations and hands-on security exercises.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚