A claim that a Canadian natural gas company was targeted in a cyberattack could be anything from a Russian disinformation campaign to a real and present threat to critical infrastructure, experts say.
According to a trove of leaked Pentagon documents, Russian-based cyber actors compromised an internet protocol address, a unique network address for a computer, on Feb. 25. The hackers claimed to have caused “sufficient damage” to cause the company to lose profit, and that their intention was to cause loss of income for Canadians, but not loss of life.
The group said to have launched the cyberattacks identified as Zarya. The documents say the group shared screenshots with officers in the Russian Federal Security Service, the successor to the KGB, which claimed they acquired the ability “to increase valve pressure, disable alarms, and initiate an emergency shutdown of an unspecified gas distribution station.”
Officers in the Russian Federal Security Service anticipated a successful attack would “cause an explosion at the gas distribution station” and were monitoring Canadian news reports for any indications of an explosion. The documents say if the group were successful, it would mark the first observation of a pro-Russia hacking group successfully launching a disruptive attack against Western industrial control systems.
Cybersecurity experts have long warned of how oil and gas infrastructure such as pipelines or refineries are enticing targets for cyberespionage because shutting them down could disrupt critical systems or Canada’s energy supply.
But a successful cyberattack of that magnitude would have likely attracted more attention, said Stephanie Carvin, a national security expert at the Norman Paterson School of International Affairs at Carleton University.
“This is not evidence of an attack, this is evidence of a conversation … There could have been and it was just covered (up). It’s possible but we just don’t know. These guys could be bragging to their bosses just looking for a paycheque. And it could be misinformation,” Carvin said.
:format(webp)/https://www.thestar.com/content/dam/thestar/news/canada/2023/04/11/claim-a-canadian-energy-company-was-target-of-russian-cyberattack-highlights-our-vulnerability-but-could-just-be-fake/stephanie_carvin.jpg)
Having said that, Russia is no stranger in targeting critical infrastructure in other countries, Carvin added, so the possibility of it occurring should not be entirely dismissed.
“What it is to me is it’s indicative of Russian willingness (to target infrastructure in other countries),” Carvin said.
Brett Callow, a threat analyst with anti-malware company Emsisoft, which helps companies retrieve their data when they’ve been hacked, described Zarya as a “hacktivist” group. They differ from other Russian cybergangs in that their primary motive is to advance Russia’s political interests rather than make money.
“There are multiple hacktivist ‘collectives’ claiming hacks, often falsely. In some cases, it’ll simply be an attention-seeking individual making a false claim (for laughs) while, in other cases, it may be intentional disinformation intended to keep the other side busy,” Callow said.
But still, “the potential is there” for a massive cyberattack on critical infrastructure that could cause ripple effects in multiple sectors, he added.
“Our systems, including our critical infrastructure systems, have been vulnerable for years. They have been under attack for years. And it’s probably only a matter of time before one of these attacks morphs into something very serious,” Callow said.
Zarya is associated with another pro-Russia hacktivist group called Killnet, Callow said. He expressed strong skepticism about their ability to cause real damage to oil and gas companies. Their primary methods are DOS (denial of service) and DDoS (distributed denial of service) attacks, which can take down websites and online services temporarily.
“Both groups are more noise than action … They can be disruptive and a pain in the butt, but it is low level stuff,” Callow said. “Certainly not likely to cause an explosion.”
There have been examples of cybercriminals targeting large oil and gas companies. Callow highlighted an example from the U.S. where a gang of cybercriminals breached data systems belonging to Colonial Pipeline, which controls nearly half the gasoline, jet fuel and diesel flowing through the East Coast, the New York Times reported.
The company’s data systems were connected to pipeline operations and they decided to turn off a major pipeline. The Times reported that government officials said the country could only operate for another three to five days before buses and other mass transit vehicles would have to scale back their operations because of the dearth of diesel fuel.
Cyberattacks are an even greater threat at a time when nearly every electronic device is connected to the internet, said Carol Fung, a cybersecurity expert at Concordia University.
“Canada has a lot of interest in making smart cities, electrifying the system, electrifying industry, and we are expecting more and more critical infrastructures and more government operations and all the important facilities to either be electrified or connected (to other smart devices),” Fung said.
“The power grid is kind of getting more and more intelligent, which means a lot more flexibility and control and potentially … that makes it easier to be attacked by sophisticated attackers all over the world,” she added.
One example of an emerging technology that has become a popular target for cyberattacks are electronic charging stations, Fung said.
The stations are popping up all over the U.S. due to incentives for consumers to switch to electronic vehicles, which means manufacturers are rushing to build them and get them to market.
“However the security features of those products or devices actually is left as an afterthought … imagine if some of them are not secure enough, they can be hacked. So there are consequences,” Fung said.
It’s an example of the security issues that are exposed in the face of rapidly changing technology, which could also apply to systems and devices used in the oil and gas industry.
“A lot of machines are vulnerable already,” Fung said. “You just don’t know.”
The Communications Security Establishment, a federal department responsible for information technology and communications security, said in a statement that it doesn’t comment on specific cybersecurity incidents or on leaked intelligence because of their sensitive nature.
But they noted they have expressed concerns about cyberattacks causing disruption to critical infrastructure.
“We remain deeply concerned about this threat and urge critical infrastructure owners and operators to get in touch with us to work together to protect their systems,” it said.
SHARE:
JOIN THE CONVERSATION
Anyone can read Conversations, but to contribute, you should be a registered Torstar account holder. If you do not yet have a Torstar account, you can create one now (it is free)
Sign In
Register
does not endorse these opinions.



