The Volt Typhoon saga continues. Volt Typhoon is a China-based hacking group accused of targeting critical infrastructure, and federal agencies have been tracking its activity for some time. The concern around its ability to establish base camps in IT networks in order to gain eventual access to OT networks has only grown. Here’s the latest.
What the First Advisory Found
An advisory from CISA, the NSA and the FBI reported that hackers suspected of ties to China’s government had taken action affecting critical infrastructure systems. Cybersecurity representatives in Australia, New Zealand and the United Kingdom joined it, and the systems named included both IT and OT. As reported by The Record, the group took zipped files holding “diagrams and documentation related to OT equipment.” The files covered supervisory control and data acquisition systems, relays and switchgear.
Authorities had already tracked attacks by the group in the United States and in territories including Guam. One was carried out against a water utility. In February the Biden administration released an executive order calling for improved security in the water and wastewater sector. Operators of water and wastewater systems can check which OT drawings and asset records sit on reachable IT networks.
The same order set out cybersecurity requirements for United States ports. As Security Week explained, it focuses specifically on the risk that cranes made in China pose to US ports and their OT networks. It also gives the Coast Guard authority to put forward rules enforcing cybersecurity and reporting standards for waterfront facilities and vessels. Facility operators can confirm whether their site falls within the scope of those rules.
A New Warning is Issued
The CISA, NSA, FBI, and several other agencies in the U.S. have joined cybersecurity agencies from Australia, Canada, the United Kingdom, and New Zealand to alert critical infrastructure leaders of the threat that Volt Typhoon poses, particularly to OT systems. This doubles down on the warning that they issued last month in which they emphasized the Chinese hackers’ successful breach of critical infrastructure in the U.S., which lasted years in some cases. Worried that Volt Typhoon may be interested in taking advantage of vulnerabilities, especially during times of geopolitical tensions, the agencies have urged operators to “empower their cybersecurity teams to make informed resourcing decisions, secure their supply chain, and ensure that performance management outcomes align with their organization’s cyber goals,” according to Sergiu Gatlan at Bleeping Computer.
While a warning for all critical infrastructure, a particular spotlight has been put on water and wastewater systems, which already suffer from resource shortages. The Biden administration is continuing to advise states to be vigilant for cyberattacks against these systems, specifically with the threat of Volt Typhoon rising. In a recent letter, Environmental Protection Agency Administrator Michael Regan and National Security Advisor Jake Sullivan noted that Volt Typhoon has already compromised information technology connected to drinking water facilities.
Cybersecurity Concern Rises
In addition to causing major disruption to essential networks, experts are increasingly concerned that China will be able to steal intellectual property through such cyberattacks. During the Billington State and Local Cybersecurity Summit in Washington, D.C., industry speakers discussed China’s use of AI in espionage efforts. To protect from this risk, the CISA has promoted the benefits of “tabletop exercise,” or the process of simulating such attacks in order to develop proper response strategies and techniques.
Despite the push for such preventative measures, the cybersecurity concerns are obviously at an all-time high. Those concerns reach well beyond people who work in the field. A new study shows that the general public is also as worried about the impacts of cyberattacks. MITRE and The Harris Poll found that, “81% of US residents are worried about how secure critical infrastructure may be.” While 78% of respondents believe the responsibility for addressing this problem lies on the federal government, 49% said the responsibility falls on both public and private organizations. Regardless of where the responsibility should be placed, the fact remains that cybersecurity will continue to be a priority, with OT taking a more prominent position, an area that DYNICS knows well. It is essential that facilities downsize the attack surface of their OT networks by denying by default and limiting traffic only to what is required for the operation of the plant. Be sure to explore our products designed specifically to shield OT systems.
Sources
- “CISA shares critical infrastructure defense tips against Chinese hackers” – Sergiu Gatlan, Bleeping Computer
https://www.bleepingcomputer.com/news/security/cisa-shares-critical-infrastructure-defense-tips-against-chinese-hackers/ - “‘We know they’re on the network,’ CISA official says of nation-state actors infiltrating U.S. critical infrastructure” – Sophia Fox-Sowell, Statescoop
https://statescoop.com/nation-state-actors-us-critical-infrastructure-cisa-2024/ - “US Warns of Cyberattacks Against Water Systems Throughout Nation” – Ari Natter, Bloomberg
https://www.yahoo.com/news/us-warns-cyberattacks-against-water-181349931.html?guccounter=1 - “CISA, FBI warn of China-linked hackers pre-positioning for destructive cyberattacks against US critical infrastructure” – Jonathan Greig, The Record
https://therecord.media/cisa-fbi-warn-of-china-linked-hackers-targeting-critical-us-infrastructure - “Executive Order on Port Cybersecurity Points to IT/OT Threat Posed by Chinese Cranes” – Eduard Kovacs, Security Week
https://www.securityweek.com/executive-order-on-port-cybersecurity-points-to-it-ot-threat-posed-by-chinese-cranes/ - “Public anxiety mounts over critical infrastructure resilience to cyber attacks” – Help Net Security
https://www.helpnetsecurity.com/2024/03/18/critical-infrastructure-cyberattacks-risk/










