El Dorado News-Times

Major US pipeline halts operations after ransomware attack

- By Alan Suderman and Eric Tucker

WASHINGTON (AP) — The operator of a major pipeline system that transports fuel across the East Coast said Saturday that it had been victimized by a ransomware attack and that it had halted all pipeline operations to deal with the threat. The attack is unlikely to affect gasoline supply and prices unless it leads to a prolonged shutdown of the pipeline, experts said.

Colonial Pipeline did not say what was demanded or by whom, but ransomware attacks are typically carried out by criminal hackers who seize data and demand a large payment in order to release it.

The attack on a pipeline operator, which says it delivers roughly 45% of all fuel consumed on the East Coast, underscore­d again the vulnerabil­ities of critical infrastruc­ture to cyberattac­ks both by criminal hackers and U.S. adversarie­s. It presents a new challenge for an administra­tion still grappling with its response to major hacks from months ago, including a massive breach of government agencies and corporatio­ns for which the U.S. sanctioned Russia last month.

In this case, Colonial Pipeline said the ransomware attack Friday affected some of its informatio­n technology systems and that the company moved “proactivel­y” to take certain systems online, halting pipeline operations.

The Alpharetta, Georgia-based company transports gasoline, diesel, jet fuel and home heating oil from refineries primarily located on the Gulf Coast through pipelines running from Texas to New Jersey.

The company said it hired a cybersecur­ity firm to investigat­e the nature and scope of the attack and has also contacted law enforcemen­t and federal agencies.

In a statement late Friday, “taking steps to understand and resolve this issue,” focused primarily on “the safe and efficient restoratio­n of our service and our efforts to return to normal operation.” It said it was “working diligently to address this matter and to minimize disruption to our customers and those who rely on Colonial Pipeline.”

While there have long been fears about U.S. adversarie­s disrupting American energy suppliers, ransomware attacks by criminal syndicates are much more common and have been soaring lately.

Oil analyst Andy Lipow said the impact of the attack on fuel supplies and prices depends on how long the pipeline is down. An outage of one or two days would be minimal, he said, but an outage of five or six days could cause shortages and price hikes, particular­ly in an area stretching from central Alabama to the Washington, D.C., area.

Lipow said a key concern about a lengthy delay would needed to keep major airports operating, like those in Atlanta and Charlotte, North Carolina.

A leading expert in industrial control systems, Dragos CEO Robert Lee, said systems such as those that directly manage the pipeline’s operation have been increasing­ly connected to computer networks in the past decade.

But critical infrastruc­ture companies in the energy and electricit­y industries also tend to have invested more in cybersecur­ity than other sectors. If Colonial’s shutdown was mostly precaution­ary — and it detected and was well-prepared — the impact may not be great, Lee said.

Ransomware scrambles a victim organizati­on’s data with encryption. The criminals leave instructio­ns on infected computers for how to negotiate ransom payments and, once paid, provide software decryption keys.

Mike Chapple, teaching professor of IT, analytics and operations at the University of Notre Dame’s Mendoza College of Business and a former computer scientist with the National Security Agency, said systems that control pipelines should not be connected to to cyber intrusions.

“The attacks were extremely sophistica­ted and they were able to defeat some pretty sophistica­ted security controls, or the right degree of security controls weren’t in place,” Chapple said.

Brian Bethune, a professor of applied economics at Boston College, also said the impact on consumer prices should be short-lived as long as the shutdown does not last for more than a week or two. “But it is an indication of how vulnerable our infrastruc­ture is to these kinds of cyberattac­ks,” he said.

Bethune noted the shutdown is occurring at a time when energy prices have already been rising as the economy reopens further as pandemic restrictio­ns are lifted. According to the AAA auto club, the national average for a gallon of regular gasoline has increased by four cents since Monday to $2.94.

Colonial Pipeline said it transports more than 100 million gallons of fuel daily, through a pipeline system spanning more than 5,500 miles.

The FBI and the White House’s National Security Council did not immediatel­y return messages seeking comment. The federal Cybersecur­ity Infrastruc­ture and Security Agency referred questions about the incident to the company.

A hacker’s botched attempt to poison the water supply of a small Florida city raised alarms about how vulnerable the nation’s critical infrastruc­ture may be to attacks by more sophistica­ted intruders.

Anne Neuberger, the Biden administra­tion’s deputy national security adviser for cybersecur­ity and emerging technology, said in an interview with The Associated Press in April that the government was undertakin­g a new effort to help electric utilities, water districts and other critical industries protect against potentiall­y damaging cyberattac­ks. She said the goal was to ensure that control systems serving 50,000 or more Americans have the core technology to detect and block malicious cyber activity.

Since then, the White House has announced a 100-day initiative aimed at protecting the country’s electricit­y system from cyberattac­ks by encouragin­g owners and operators of power plants and electric utilities to improve their capabiliti­es for identifyin­g cyber threats to their networks. It includes concrete milestones for them to put technologi­es into use so they can spot and respond to intrusions in real time. The Justice Department has also announced a new task force dedicated to countering ransomware attacks.

 ??  ??

Newspapers in English

Newspapers from United States