Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
ComputerWorldNetwork WorldCIO CanadaCIO Canada Governments' ReviewJobUniverse Canada
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Unlock the potential of data with the right data warehouse solutionUnlock the potential of data with the right data warehouse solution read more
IBM Multiform Master Data Management: The evolution of MDM applicationsIBM Multiform Master Data Management: The evolution of MDM applications read more
Closing the data privacy gap: Protecting sensitive data in non-production environmentsClosing the data privacy gap: Protecting sensitive data in non-production environments read more
Yuk it Up
Featured White Paper
Are you secure? Assessment is the key to plugging security holes Knowing where potential security threats can manifest themselves within your IT infrastructure makes all the difference when it comes to the ongoing challenge of keeping your critical business information where it should be—safe and secure within your corporate network. An IBM whitepaper, entitled, Are You Secure, considers the need to understand your current security situation and plan accordingly, recognizing your vulnerabilities and addressing these in an efficient, timely manner. Complimentary with registration. Sponsored by IBM Corp.
Cyber threats accelerate, browser vulnerabilities proliferate in H1 2008, says IBM X-Force Report It may not surprise anyone to know that organized and highly sophisticated outlaws are running rampant in cyberspace. But they’re more dangerous than ever. IBM Corp.’s recently published X-Force 2008 Mid-Year Trend Statistics Report says cyber-criminals are utilizing new automation techniques and strategies that let them exploit vulnerabilities faster. This most recent 85-page comprehensive report observes there’s little time between when a vulnerability is exposed to when it is exploited. Many other key findings and trends are contained within this 85-page report. Complimentary with registration. Sponsored by IBM Corp.
The need for application speed is paramount in today's business. There's little tolerance for even the slightest measure of network slowdown or performance impediment. Your applications and business processes must deliver when they're needed. The Info-Tech Research Group report - App Performance Management Rollout: "Big Bang" a Big Mistake - offers recommendations in how you might seek to approach application performance management (APM) and ensure the highest level of business readiness. The report has a value of $150 but is complimentary with your registration. It is sponsored by Citrix Systems Inc.
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
IT World Canada Blogs
Keep up with breaking news on worms, trojans, spam and other threats to your corporate network and hear about the best practices in risk management from some of Canada's leading experts.
Featured Product Review
MailFrontier, Sophos, Symantec, and Trend Micro deploy effective spam combatants. Spam is such a significant problem these days that even the federal government has gotten involved, passing legislation such as the CAN-SPAM Act. Meanwhile, a wide variety of companies has collaborated on an authentication scheme called the Sender ID Framework, aimed at making e-mail fraud even harder to perpetrate. Realistically, though, neither CAN-SPAM nor e-mail-sender authentication is likely to do much to stem the flood of mail. Fortunately, anti-spam products continue to evolve and improve.
Sign-Up for
Security
eNewsletter Delivered Weekly
Click here
Page 1 of 1

Extortionists have hacked power plants: CIA

SAN FRANCISCO — Cyber-extortionists have managed to cut the power to several cities by hacking the power grid over the Internet, a U.S. Central Intelligence Agency analyst said last week.

Speaking at a conference of security professionals last week, CIA analyst Tom Donahue disclosed the recently declassified attacks while offering few specifics on what actually went wrong.

Criminals have launched online attacks that disrupted power equipment in several regions outside of the U.S., he said, without identifying the countries affected. The goal of the attacks was extortion, he said.

"We have information, from multiple regions outside the United States, of cyber intrusions into utilities, followed by extortion demands," he said in a statement posted to the Web on Friday by the conference's organizers, the SANS Institute. "In at least one case, the disruption caused a power outage affecting multiple cities. We do not know who executed these attacks or why, but all involved intrusions through the Internet."

"According to Mr. Donahue, the CIA actively and thoroughly considered the benefits and risks of making this information public, and came down on the side of disclosure," SANS said in the statement.

One conference attendee said the disclosure came as news to many of the government and industry security professionals in attendance. "It appeared that there were a lot of people who didn't know this already," said the attendee, who asked not to be identified because he is not authorized to speak with the press.

He confirmed SANS' report of the talk. "There were apparently a couple of incidents where extortionists cut off power to several cities using some sort of attack on the power grid, and it does not appear to be a physical attack," he said.

Hacking the power grid made front-page headlines in September when CNN aired a video showing an Idaho National Laboratory demonstration of a software attack on the computer system used to control a power generator. In the demonstration, the smoking generator was rendered inoperable.

The U.S. is taking steps to lock down the computers that manage its power systems, however.

On Thursday, the Federal Energy Regulatory Commission (FERC) approved new mandatory standards designed to improve cybersecurity.

CIA representatives could not be reached immediately for comment.

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Related Content
Articles

Book Reviews

Special Advertising Partners
IDC Case Study: Identity And Access Management Buying Criteria.
IDC analyses IAM buying criteria and deployment at Coppin State University. Coppin State replaces "first generation" IAM solution to obtain benefits needed for today's agile enterprise: ease of integration, rapid deployment, simplified compliance, flexibility.
White Papers
Closing the data privacy gap: Protecting sensitive data in non-production environments
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
Unlock the potential of data with the right data warehouse solution
Once you've made the decision to implement a new data warehouse, you want to make sure you choose the one that's right for your organization. This buyer's guide provides checklists for starting points that you can use when evaluating vendors and their products. Complimentary with registration. Sponsored by IBM.
Prepare for a more efficient SAP implementation: Take data issues off the critical path
This white paper outlines how the Preliminary Data Assessment Appliance (PDAA) from IBM can help address the challenges of integrating data from different operational applications across the enterprise to an SAP platform. Complimentary with registration. Sponsored by IBM.