Assessment of Ransomware Event at U.S. Pipeline Operator
ID: 7d24a0a8-67b8-5480-9a28-0c9a63319fae
STIX ID: report--7d24a0a8-67b8-5480-9a28-0c9a63319fae
Feed Name: Dragos Blog
Dragos links a CISA alert to a December 2019 U.S. Coast Guard report describing a Ryuk ransomware incident at an unnamed U.S. pipeline operator's natural gas compression facility: attackers used a phishing link to breach the IT network, pivoted to Windows-based ICS devices (HMIs and historians) due to insufficient IT/OT segregation, encrypted systems and caused loss of view leading to a controlled shutdown and approximately two days of operational downtime; the report concludes the incident reflects commodity ransomware behavior rather than ICS-specific targeting and provides recommendations (phishing awareness, email flagging, stronger IT/OT segmentation, patching, backups, monitoring, and recovery testing).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
