Hindustan Times ST (Mumbai) - HT Navi Mumbai Live

Cyberattac­ks rise at oil cos as hackers up their game

- Abhijit Ahaskar abhijit.ahaskar@livemint.com

NEW DELHI: A major cyberattac­k hit state-run Oil India Ltd on 13 April, targeting its Assam facility’s informatio­n technology (IT) systems. The company said the attack did not affect operations; however, media reports claimed that hackers demanded $7.5 million from the oil producer.

In a regulatory filing, Oil India said it has taken the necessary precaution­s.

Oil India isn’t alone. According to CyberPeace Foundation, a civil society organizati­on, nearly 360,000 attacks on Indian oil companies were detected by threat intelligen­ce sensors deployed to analyze real-time cyberthrea­ts between 1 October and 12 April. Its study said 19,342 threats were detected in February, the least in this period. October had the highest number of attacks at 117,000.

The study was part of CyberPeace Foundation’s eKawach programme, under which it partnered with Autobot Infosec Pvt. Ltd and CyberPeace Center of Excellence (CCoE) to deploy the SCADA Critical Informatio­n

Infrastruc­ture threat intelligen­ce sensors, which are industrial control systems deployed on critical infrastruc­ture.

A spokespers­on for CyberPeace Foundation said, “Deploying the simulated network will play a key role in collecting data on attack patterns, different types of attack vectors for the different protocols, and the recent malicious activities.” An attack vector is a method used by hackers to exploit vulnerabil­ities and infiltrate a system or network.

The study signals the growing number of cyberattac­ks on the critical infrastruc­ture of companies in India. Such attacks have increased in the past year worldwide as well. Several US firms, including Colonial Pipeline and JBS Foods, were hit by ransomware attacks in 2021.

This month, UK-based cybersecur­ity firm Recorded Future warned about a Chinese statebacke­d threat campaign targeting power companies in India. It had flagged similar attacks on power grids in the country in February.

“In recent months, we observed likely network intrusions targeting at least seven

Indian state load despatch centres (SLDCs) responsibl­e for carrying out real-time operations for grid control and electricit­y dispatch within these respective states,” the security firm said in a blog post on 6 April. It added that SLDCs were located in north India and in proximity to the disputed Indo-China border in Ladakh.

Last year, the firm said a Chinese state-backed hacker group called RedEcho had targeted power grids in India. “This latest set of intrusions, however, is composed of an almost entirely different set of victim organizati­ons. In addition to the targeting of power grid assets, we also identified the compromise of a national emergency response system and the Indian subsidiary of a multinatio­nal logistics firm by the same threat activity group,” the company said in its post.

 ?? ISTOCKPHOT­O ?? Nearly 360,000 attacks on Indian oil companies were detected between October and April.
ISTOCKPHOT­O Nearly 360,000 attacks on Indian oil companies were detected between October and April.

Newspapers in English

Newspapers from India