Shutdown for 48 Hours – US Gas Pipeline Part of a Targeted Ransomware Attack

A ransomware attack on a US natural gas facility meant a pipeline had to be shut down for two days, the US Department of Homeland Security (DHS) has noted.

Little is to be known about the name of the facility or when the attack happened.

Mostly this issue was severe in part because the organization was not prepared for such an attack, however, it began with a malicious link sent to staff at the facility eventually caused the shutdown “of the entire pipeline asset”.

The incident was detailed in a recent security alert., which revealed it to be a “spear-phishing” attack, in which individuals are sent fraudulent but believable scam messages.

That let the attacker into the company’s entire network.

Often, networks are segmented into these types of sectors. The “operational network” which runs computers in the factory is typically separated from the office IT – but not in this case, meaning the ransomware infection was allowed to spread throughout.

Ransomware typically encrypts files on a victim’s computer and demands payment before offering to unlock them again – although there is no guarantee that the cyber-criminals who develop such software will unlock the software or return the data.