Energy companies are bracing for potential cyberattacks in the wake of a U.S. airstrike late Thursday that killed a top Iranian general.

Hours after the attack at Baghdad International Airport, the U.S. Department of Homeland Security's top cybersecurity official on Friday reissued a summer bulletin from the agency warning of increased cyberattacks by the Iranian government and its allies.

"CISA is aware of a recent rise in malicious cyber activity directed at United States industries and government agencies by Iranian regime actors and proxies," Chris Krebs, director of the Cybersecurity and Infrastructure Security Agency at the DHS, said in a statement accompanying the July alert.

"Iranian regime actors and proxies are increasingly using destructive 'wiper' attacks, looking to do much more than just steal data and money," it continued. "These efforts are often enabled through common tactics like spear phishing, password spraying, and credential stuffing. What might start as an account compromise, where you think you might just lose data, can quickly become a situation where you've lost your whole network."

Independent cybersecurity experts, speaking with Cheddar, said that so-called ransomware – where hackers lock and threaten to delete crucial files unless the victims cough-up payment – are a "high likelihood" event.

"It's cheap, it's easy, it's proven reliable. And in the States, there are any number of entities at any level – state, local, industry, national conglomerate level – there's just a ton of targets, and you only need to get a couple to demonstrate that you've done something," said Trey Herr, director of the Cyber Statecraft Initiative at the Atlantic Council, a think tank in Washington, DC.

The drone strike that killed Maj. Gen. Qassem Soleimani, an apparent targeted assassination ordered by President Trump, sharply escalated simmering tensions between the Iranian and U.S. governments. The countries' leaders have clashed over Iranian influence, military activity, and covert action in Iraq that has killed American and allied troops; Trump's move to withdraw the U.S. from the 2015 nuclear deal between the two nations; and the Trump administration's decision to reinstate harsh economic sanctions on the Islamic Republic that had been lifted as part of the nuclear accord.

Iran last summer shot down a U.S. surveillance drone flying near the Strait of Hormuz and seized oil tankers in an apparent bid to disrupt international oil markets. American and Saudi officials also blamed Iran for drone attacks on Saudi oil infrastructure and attacks that crippled oil tankers.

Iran, though, has also regularly deployed cyberweapons as part of its arsenal. Between 2011 and 2013, hackers launched attacks on dozens of U.S. financial institutions and, overseas, managed to wipe data from some 30,000 computers used by the state-owned oil and gas conglomerate, Saudi Aramco.

"Iran has shown previously to be opportunistic in its targeting of infrastructure with denial of service attacks against banks as well as trying to get access to industrial control systems in electric and water companies," Robert Lee, founder and CEO of the cybersecurity firm Dragos, said in an email. "While it is important to think where strategic targets would be for them it's just as relevant that they might search for those who are more insecure to be able to have an effect instead of a better effect on a harder target."

Other attacks in just the past year have exposed vulnerabilities in U.S. gas pipeline networks, and even the country's electric grids: The North American Electric Reliability Corporation, a federal regulator, confirmed in October that a remote hacker had disabled systems that had allowed an unnamed utility to communicate with and monitor crucial power sites in Utah, Wyoming, and California.

An industry survey published last fall by Siemens found that more than half the country's power providers say that they're unprepared for a cyberattack.

"There's been ongoing activity in the past couple years from the Iranians – and the Russians – to gain access to these networks," Herr said. "Now, in a period of peak escalation like this, where the Iranians are certainly hopping mad, will they use this access to deploy a capability that will create harm? There is some concern about that, which is why DHS issued that warning, which was unusual in its specificity."

The U.S. and its chief ally in the region, Israel, have deployed cyberattacks against Iran: The Stuxnet virus in 2010, for example, derailed Iranian uranium enrichment, although neither the U.S. nor Israel has confirmed that it was responsible for building and deploying the cyber weapon. More recently, an apparent U.S. cyberattack last June reportedly crippled Iran's ability to target oil tankers in the Strait of Hormuz. Such attacks may have effectively cleared the way for similar responses from Iran.

"There's a monkey-see-monkey-do effect: The Iranians are incredibly fast learners, and they tend to reciprocate to others what is done to them," Herr said.

Industry organizations such as the Edison Electric Institute, which represents investor-owned electric utilities, and the American Petroleum Institute, the main trade group for the oil and gas sector, said that they’re monitoring for potential breaches.

“While there is no specific threat to electricity infrastructure at this time, given Iranian capabilities and the potential for retaliation, the electric power industry is closely coordinating across the industry and with our government partners through the Electricity Subsector Coordinating Council… to ensure vigilance and the ability to respond quickly should the situation evolve,” Scott Aaronson, EEI’s vice president for security and preparedness, said in a statement.

Emily Smith, a spokeswoman for the the American Petroleum Institute, said that the oil and gas industry “continues to work collaboratively with government agencies to mitigate and investigate industrial control system (ICS) threats – especially through the oil and natural gas information sharing and analysis center.”

A retaliatory cyberattack, however, is far from certain, Herr and other experts said. Iran has a range of responses at its disposal, from deploying fast boats in the Strait of Hormuz, to sowing violence to disrupt American influence and operations in Iraq and Syria, to targeting allies such as Saudi Arabia or Israel.

"You should really be thinking about proportionality," said Oren Falkowitz, CEO of Area 1 Security, a cybersecurity firm. "Cyber is a great option prior to prevent wars and to do things asymmetrically. In and of itself, I don't think it's a reasonable response, and I think it would be seen as pretty weak."

Effective cyberattacks also demand years of planning – causing damage is the last step in the process, not the first. And if seeking to, say, disrupt infrastructure like pipelines or a power plant, that requires access to complex software, high levels of investment, and sophistication.

"There are real threats in cyberspace, and countries like Iran and China and Russia, as well as criminal groups, are causing epic amounts of damages. But the challenge is that when something happens in the real world, it's not like cyberattacks can just be formulated out of thin air to respond overnight. Launching a cyberattack is a painstaking, monthslong, if not yearslong, process," said Falkowitz, who previously held senior positions at the National Security Agency and U.S. Cyber Command.

The heightened concern about a potential cyberattack, though, may itself be a wakeup call: "If I'm an executive and I've been spending millions of dollars, and I wake up and I'm really worried, I don't know what I've been spending my money on," Falkowitz said. "For the professionals and businesses worried about protecting their intellectual property and customers' sensitive information and financials, this is something that they deal with every single day – the fact that there's a geopolitical hotspot shouldn't really change anything for them."

Share:
More In Business
‘Chainsaw Man’ anime film topples Springsteen biopic at the box office
A big-screen adaptation of the anime “Chainsaw Man” has topped the North American box office, beating a Springsteen biopic and “Black Phone 2.” The movie earned $17.25 million in the U.S. and Canada this weekend. “Black Phone 2” fell to second place with $13 million. Two new releases, the rom-com “Regretting You” and “Springsteen — Deliver Me From Nowhere,” earned $12.85 million and $9.1 million, respectively. “Chainsaw Man – The Movie: Reze Arc” is based on the manga series about a demon hunter. It's another win for Sony-owned Crunchyroll, which also released a “Demon Slayer” film last month that debuted to a record $70 million.
Flights to LAX halted due to air traffic controller shortage
The Federal Aviation Administration says flights departing for Los Angeles International Airport were halted briefly due to a staffing shortage at a Southern California air traffic facility. The FAA issued a temporary ground stop at one of the world’s busiest airports on Sunday morning soon after U.S. Transportation Secretary Sean Duffy predicted that travelers would see more flights delayed as the nation’s air traffic controllers work without pay during the federal government shutdown. The hold on planes taking off for LAX lasted an hour and 45 minutes and didn't appear to cause continued problems. The FAA said staffing shortages also delayed planes headed to Washington, Chicago and Newark, New Jersey on Sunday.
Boeing defense workers on strike in the Midwest turn down latest offer
Boeing workers at three Midwest plants where military aircraft and weapons are developed have voted to reject the company’s latest contract offer and to continue a strike that started almost three months ago. The strike by about 3,200 machinists at the plants in the Missouri cities of St. Louis and St. Charles, and in Mascoutah, Illinois, is smaller in scale than a walkout last year by 33,000 Boeing workers who assemble commercial jetliners. The president of the International Association of Machinists says Sunday's outcome shows Boeing hasn't adequately addressed wages and retirement benefits. Boeing says Sunday's vote was close with 51% of union members opposing the revised offer.
FBI’s NBA probe puts sports betting businesses in the spotlight
The stunning indictment that led to the arrest of more than 30 people — including Miami Heat guard Terry Rozier and other NBA figures — has drawn new scrutiny of the booming business of sports betting in the U.S. The multibillion-dollar industry has made it easy for sports fans — and even some players — to wager on everything from the outcome of games to that of a single play with just a few taps of a cellphone. But regulating the rapidly-growing industry has proven to be a challenge. Professional sports leagues’ own role in promoting gambling has also raised eyebrows.
Tesla’s profit fell in third quarter even as sales rose
Tesla, the car company run by Elon Musk, reported Wednesday that it sold more vehicles in the past three months after boycotts hit hard earlier this year, but profits still fell sharply. Third-quarter earnings fell to $1.4 billion, from $2.2 billion a year earlier. Excluding charges, per share profit of 50 cents came in below analysts' estimate. Tesla shares fell 3.5% in after-hours trading. Musk said the company's robotaxi service, which is available in Austin, Texas, and San Francisco, will roll out to as many as 10 other metro areas by the end of the year.
Load More