Security News > 2021 > July > Chinese state hackers breached over a dozen US pipeline operators
Chinese state-sponsored attackers have breached 13 US oil and natural gas pipeline companies between December 2011 to 2013 following a spear-phishing campaign targeting their employees.
The end goal of the attacks was to help China develop cyberattack capabilities that would allow future intrusions to physically damage targeted pipelines or disrupt US pipeline operations.
Chinese-backed threat actors targeted 23 US pipeline operators.
"Overall, the US Government identified and tracked 23 US natural gas pipeline operators targeted from 2011 to 2013 in this spearphishing and intrusion campaign. Of the known targeted entities, 13 were confirmed compromises, 3 were near misses, and 7 had an unknown depth of intrusion," the advisory reads.
This joint advisory follows the DarkSide ransomware attack against the networks of Colonial Pipeline, a company managing the most extensive US pipeline system and supplying roughly half of all the fuel on the US East Coast.
The same month, in May, the Department of Homeland Security announced new pipeline cybersecurity requirements directing critical pipeline owners and operators to report confirmed and potential cybersecurity incidents to CISA. The new security directive makes it easier for the DHS to identify, protect against, and respond to cybersecurity threats directly targeting US critical pipeline sector companies.
News URL
Related news
- US says Chinese hackers breached multiple telecom providers (source)
- US, UK warn of Russian APT29 hackers targeting Zimbra, TeamCity servers (source)
- Chinese Nation-State Hackers APT41 Hit Gambling Sector for Financial Gain (source)
- Chinese Hackers Use CloudScout Toolset to Steal Session Cookies from Cloud Services (source)
- Microsoft: Chinese hackers use Quad7 botnet to steal credentials (source)
- Sophos reveals 5-year battle with Chinese hackers attacking network devices (source)
- Sophos Versus the Chinese Hackers (source)
- FBI Seeks Public Help to Identify Chinese Hackers Behind Global Cyber Intrusions (source)
- US indicts Snowflake hackers who extorted $2.5 million from 3 victims (source)
- Hacker gets 10 years in prison for extorting US healthcare provider (source)