Israel

Country

Hackers take control of a water treatment system at a hotel in Israel

September 10, 2022

NEED TO REVIEW AND SEARCH FOR ONE MORE SOURCE

GhostSec’s claimed breach of 55 Berghof PLCs in Israel. This weekend, on September 10, 2022, the hacktivist group published another announcement alleging that it successfully breached another controller in Israel.The affected controller is an Aegis II controller manufactured by ProMinent.

According to images that the GhostSec published, the group appeared to have taken control of a water system’s pH and chlorine levels. In the published message, the hacktivists said they “understand the damages that can be done …” and that the “Ph pumps” are an exception for their anti-Israeli cyber campaigns.

read more

Attack Disables Irrigation Systems and Disrupts Water Treatment Processes

April 9, 2023

Water controllers for irrigating fields in the Jordan Valley were damaged, as were control systems for the Galil Sewage Corporation. Several water monitors – which monitor irrigation systems and wastewater treatment systems – were left dysfunctional on Sunday after a cyber attack targeted the monitoring systems. Specifically, water controllers for irrigating fields in the Jordan Valley were damaged, as were control systems for the Galil Sewage Corporation.

The management for both major systems was pushing all of Sunday morning to work through the issue and bring the systems back into full operation. Farmers in the region were warned several days prior about suspicions over a planned cyber attack. Some of them, as a result of the warning, disconnected the remote control option for their irrigation systems and switched them to manual operation, instead, to prevent any harm from the attack. Indeed, those who left their systems on remote control were the ones impacted by the attack.

The attack is thought to be part of an annual “hacktivist” campaign that takes place every April, and this year’s attempt at least managed to cause a nuisance for some farms in the Jordan Valley. The cyber attack is part of an annual campaign called “OpIsrael,” which strikes in April with DDoS attacks and breach attempts on targets in the country.

Each year of the cyber attack campaign seems to bring new targets of opportunity. This year the threat actors put a special focus on irrigation systems. The Galil Sewage Corporation was one of the targeted wastewater processors that was breached, and the company reports that the cyber attack blocked several controllers for about a day and disrupted some treatment processes.

read more

Israel Water Monitoring Systems in Cyber Attack

April 9, 2023

Several water monitors – which oversee irrigation systems and wastewater treatment systems – were not operational this past Sunday after a cyber attack targeted the systems.
Specifically, water controllers for irrigating fields in Israel’s Jordan Valley suffered damage along with control systems for the Galil Sewage Corporation.
Workers for the two systems worked throughout the day to get the systems back up and running. The source of the cyberattack, however, is unknown, according to a report in the Jerusalem Post.

read more

Hackers Accessed HMIs at Israeli Water Facility

December 1, 2020

An Iranian threat-actor published a video of a breach in an Israeli reclaimed water reservoir HMI system. According to industrial cybersecurity firm OTORIO, the hackers accessed a human-machine interface (HMI) system that was directly connected to the internet without any authentication or other type of protection. The target was apparently a reclaimed water reservoir. “This gave the attackers easy access to the system and the ability to modify any value in the system, allowing them, for example, to tamper with the water pressure, change the temperature and more. All the adversaries needed was a connection to the world-wide-web, and a web browser,” OTORIO said in a blog post.

read more

PLCs Targeted in Water and Wastewater Facilities Attacks in Israel

April 24, 2020

The Israeli government revealed that wastewater treatment plants, pumping stations and sewage facilities across the country were targeted in a coordinated attack on April 24 and 25. Sources told SecurityWeek that the attackers targeted programmable logic controllers (PLCs) used to control valves. The changes made to the PLC logic were valid, which indicates that the attackers knew exactly what they were doing. The attack may have been discovered after the compromised PLCs caused suspicious valve changes, but it’s unclear if the attackers were trying to cause damage by tampering with valves or if they made an error that led to their discovery.

read more

Hillel Yaffe Hospital Ransomware Attack Paralyzed Majority of Hospital’s Computer Systems.

October 13, 2021

According to reports, among the affected systems are the hospital’s electric doors, as well as the patient registry system – which severely hampered the medical center’s ability to receive and discharge patients. Some non-urgent procedures were canceled, but most of the hospital’s work continued using alternative IT systems and pen and paper. Cybersecurity experts said the hospital did not deploy the best possible security options, making it vulnerable to attack.

The hospital was back to being fully operational over a month after a ransomware attack. To reduce the vulnerability of follow-up attacks, medical centers across Israel shut down some IT systems.

read more

Iranian Hackers Attempt to Disrupt Israel Power System

January 1, 2003

WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.

read more

Computer Glitch Prevents Return of Gas Service

January 1, 2011

WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.

read more

Agriculture water pumps attacked

June 1, 2020

Water pumps were attacked in Mateh Yehuda province in Israel. These were specific, small drainage installations in the agriculture sector that were immediately and independently repaired by the locals, causing no harm or any real-world effects,” the Water Authority said in a statement.

read more