Related Links

Related Stories

  • US oil companies hacked; report links attack to sources within China
    Reports in the Christian Science Monitor suggest that at least three large US oil companies have been the victims of targeted attacks. The custom-made spyware used in the attack appears to have sent the information to China, at least in one case.
  • Further evidence links Aurora attack to China
    Further evidence has emerged suggesting that the Operation Aurora attack exploiting a zero-day flaw in Internet Explorer came from within the People's Republic of China.
  • Hacked Google threatens to pull plug in China
    Google is threatening to unplug its controversial Chinese search engine, following a massive hacker attack on its infrastructure that it says was designed to access the accounts of human rights activists. And the company was not the attackers’ only target, it claims.
  • Using Information Security to Protect Critical National Infrastructure: Energy Sector is Hackers’ Biggest Target
    The oil and gas industries are natural targets for cyber-criminals due to sensitive data and very deep pockets. With the introduction of newer IT technologies, such as wireless and even social networking, the jobs of the information security teams are not getting any easier. John Sterlicchi reports
  • Look After Your SCADA Heart
    Critical national infrastructures such as the National Grid, water and other utility networks have SCADA technology at their heart, but how are these systems protected against hacker, malware and terrorist attacks? Steve Gold spoke to the major players in this important, but little-understood, side of the security industry

News

Oil and gas companies hit hardest by cyberwarfare

28 January 2010

The oil and gas sector has been the hardest hit by stealthy infiltration, according to a report from the Center for Strategic and International Studies (CSIS). The sector was hit by stealth attacks 17% more than the cross-sector average, with almost three oil companies in four having had hackers fly under their radar.

The report, In the Crossfire: Critical Infrastructure in the Age of Cyber War, was commissioned by McAfee. It also found that oil and gas companies were the most exposed to DDoS attacks, with two-thirds of executives saying that they had been bombarded with traffic designed to bring down their systems. A third reported multiple attacks each month.

Denial of service had a more significant effect on oil companies, too. Companies in this sector said that 24 hours of downtime would cost them $8.4m per day – again, a third as much as the cross-sector average. Two-fifths of the total survey base expect a 24-hour outage in their sector in the next year.

This report comes just days after the publication of a Christian Science Monitor article detailing cyberattacks on three of the United States' largest oil companies: ExxonMobil, Marathon Oil, and ConocoPhillips. All three oil companies were infiltrated using malware, according to the report, which added that highly sensitive bid data was stolen.

In spite of being primary targets for cyberattacks, oil and gas companies made the biggest cuts to their security budgets as a result of the recession, according to the report. Up to three-quarters of respondents from this sector reported reductions, it said. And yet according to the report, whereas most sectors focused on cost as a limiting factor in security, the oil sector bucked that trend.

"In the water/sewage and oil/gas sectors, those obstacles were reversed in significance, with lack of awareness being most frequently cited, ahead of cost," the report noted.

Almost six in ten respondents to the survey believed that foreign states had been involved with cyberattacks affecting critical infrastructure in their countries, reflecting growing concerns over cyberwarfare and espionage between governments.

The report polled 600 IT and security executives from 14 countries in seven sectors for their views on the threat landscape.

 

This article is featured in:
Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.