Hackers Tried to Poison a Florida Water Supply

  • By Dawna M. Roberts
  • Published: Feb 24, 2021
  • Last Updated: Mar 18, 2022

 It's bad enough that hackers are running rampant these days committing fraud, stealing millions, and exposing data, but now they are also trying to poison people.

What Happened?

On Monday, CBS News reported that hackers had breached the town water treatment plant in Pinellas County, (Oldsmar) Florida. As the treatment plan operator watched, someone remotely took control of the mouse and increased the amount of lye (sodium hydroxide) from 100 parts per million to 11,100 parts per million (dangerously high level).

Pinellas County Sheriff Bob Gualtieri was quoted as saying;

"This is obviously a significant and potentially dangerous increase, sodium hydroxide, also known as lye, is the main ingredient in liquid drain cleaners."

According to the Centers for Disease Control (CDC), when lye is ingested in these quantities, it would have caused vomiting, chest and abdominal pain.

Thankfully, the water treatment plant operator was able to resume control and put the levels back to a safe amount. The treatment plan regularly adds lye to the water to reduce its acidity.

Data Breach Today reported that "'That remote access was brief, and the operator didn't think much of it because his supervisor and others will remotely access his computer screen to monitor the system at various times,' Gualtieri says."

Later that day, around 1:30 p.m., the threat actor returned and boosted the system's level of lye from 100 parts per million to 11,100 parts per million. The hacker was only in the system for 3-5 minutes tops but enough time to potentially cause some serious damage. If it had not been caught immediately, the incident could have resulted in disaster.

How it Happened

So far, city officials have discovered hackers used TeamViewer (remote access software) to breach the county water treatment plant's computers.

According to Data Breach Today, "'Importantly, the public was never in danger,' says Pinellas County Sheriff Bob Gualtieri during a  Monday press conference. Oldsmar, Florida, which is about 17 miles northwest of Tampa, has a population of about 15,000 people."

What is TeamViewer

TeamViewer is a tool used by IT professionals and tech support operatives. It allows someone remote access and, depending on configuration settings, complete control of a remote server or computer. In the right hands, it is a fantastic tool to use to help someone in need of support. However, when abused by hackers, it hands over the keys and opens up a myriad of safety issues.

It is unclear how the water treatment plant used TeamViewer or in what capacity. No one has yet commented on how they had it configured and what security settings were used.

Most government agencies have spent the last few years security their systems to keep intruders out. Therefore, it is alarming that someone could so easily breach a water treatment plant and potentially poison thousands of people.

Depending on the level of security when accessing the water treatment plant's system, experts theorize that to do so, a threat actor would need an authorized account or use something like a brute-force attack. Many of these modern systems require two-factor or multi-factor authentication. How was that bypassed?

According to threat researchers, TeamViewer has been adequately fortified within the last five years to eliminate the possibility of computer takeovers. It is important to learn what went wrong here so that a patch can be delivered, or systems altered to repair the vulnerability.

How Did Oldsmar Respond?

According to Pinellas County Sheriff Bob Gualtieri, the entire incident was contained quickly, and county officials are working with both the U.S. Secret Service and the FBI to investigate the matter further and find the culprit(s) responsible.

About the Author
IDStrong Logo

Related Articles

Instagram Vulnerability Allowed Hackers Access to Control Your Phone

Security experts Check Point Research discovered a critical vulnerability while examining Instagra ... Read More

Alien Malware Infects More than 226 Mobile Apps and Steals Bank Data

As reported on September 24, 2020, by ZDNet and ThreatPost, a new strain of malware named “A ... Read More

Universal Health Systems Hit by Ransomware Attack

Universal Health Systems (UHS), a Fortune 500 company owning more than 400 hospitals across the co ... Read More

Exchange Server Bug Exposes a Big Risk to Hackers

Months after Microsoft released a patch to fix a serious flaw in MS Exchange Server, more than 61% ... Read More

Clients’ Bank Data Exposed in Blackbaud Ransomware Attack

Blackbaud software was victim to a ransomware attack last May, and new information suggests that c ... Read More

Latest Articles

What is Single Sign-On: The Benefits and Importance of Implementing SSO

What is Single Sign-On: The Benefits and Importance of Implementing SSO

Every day, more people get online - most do it for leisure, but organizations are increasingly moving into the digital environment.

Personal vs Sensitive Personal Information (SPI): What’s the Difference

Personal vs Sensitive Personal Information (SPI): What’s the Difference

What is there to know about a person? Certainly, their name, but how about their affiliations, philosophical beliefs, or sexual orientation?

What Is An On-Path Attack and How Does It Work? 

What Is An On-Path Attack and How Does It Work? 

Suppose someone left their home, got in their car, and drove to the grocery store. Much like data packets that travel over Internet highways, the car will use various pathways to reach its destination; however, once the car gets to the store, a question remains: what happened between the generating point and the destination?

Featured Articles

How to Buy a House with Bad Credit

How to Buy a House with Bad Credit

Buying your own home is the American Dream, but it might seem out of reach to those with bad credit. However, the good news is, if your credit is less than perfect, you do still have options and in most cases, can still buy a home.

How Secure Is Your Password? Tips to Improve Your Password Security

How Secure Is Your Password? Tips to Improve Your Password Security

Any good IT article on computers and network security will address the importance of strong, secure passwords. However, the challenge of good passwords is that most people have a hard time remembering them, so they use simple or obvious ones that pose a security risk.

Top 10 Senior Scams and How to Prevent Them

Top 10 Senior Scams and How to Prevent Them

Senior scams are becoming a major epidemic for two reasons. First, seniors often have a lot of money in the bank from a life of working hard and saving.

Free Identity Exposure Scan
Instantly and Securely Check if Your Personal Information is Exposed on the Dark Web or Sold by Data Brokers
Please enter first name
Please enter last name
Please select a state
Close
Free Identity Threat Scan
Instantly Check if Your Personal Information is Exposed
All fields below are required
Please enter first name
Please enter last name
Please enter a city
Please select a state
Please enter an age
Please enter an email address
Close