• If you are having trouble changng your password please click here for help.

Colonial Pipeline System Restart

Ex313

Air Force Icon Supporter
Wooba Gooba With The Green Teeth
14   0
Joined
Aug 21, 2012
Messages
1,847
Reaction score
2,776
Location
Dacula
https://cpcyberresponse.com/

Update: Wednesday, May 12, 5:11 p.m.

Colonial Pipeline initiated the restart of pipeline operations today at approximately 5 p.m. ET.

Following this restart, it will take several days for the product delivery supply chain to return to normal. Some markets served by Colonial Pipeline may experience, or continue to experience, intermittent service interruptions during the start-up period. Colonial will move as much gasoline, diesel, and jet fuel as is safely possible and will continue to do so until markets return to normal.

As we initiate our return to service, our primary focus remains safety. As part of this startup process, Colonial will conduct a comprehensive series of pipeline safety assessments in compliance with all Federal pipeline safety requirements.

This is the first step in the restart process and would not have been possible without the around-the-clock support of Colonial Pipeline’s dedicated employees who have worked tirelessly to help us achieve this milestone. We would also like to thank the White House for their leadership and collaboration, as well as the Department of Energy, Department of Transportation, FBI, PHMSA, FERC and other federal, state and local agencies for their ongoing support.

We will continue to provide updates as restart efforts progress.
 
iu

Glad they figured it out.
 
So, did they air gap it? Or is it still connected to the internet?
I think that is yet to be determined.
I follow some security industry pros on Twitter and one of them said the company was using a previous version of Microsoft Exchange. Not the current version.

My speculation: If an MS Exchange mail server was used to gain entry, the hackers could have compromised the laptops of some employees who work on the SCADA control network. If the field techs have sim cards installed in the laptops, and they were working on the SCADA equipment, they would infect the SCADA equipment, compromise the air gap and connect via the sim card connection to the hackers control servers. At that point, the hackers could move from SCADA to SCADA once they get set up.
I'm just "Tom Clancy-ing" it here. I don't really know what happened.
 
Back
Top Bottom