CIA Claims Cyber Attackers Blacked Out Cities
Dotnaught writes to tell us InformationWeek is reporting that the CIA admitted today that recent power outages in multiple cities outside the United States are the result of cyberattacks. "We have information, from multiple regions outside the United States, of cyber intrusions into utilities, followed by extortion demands. We suspect, but cannot confirm, that some of these attackers had the benefit of inside knowledge. We have information that cyberattacks have been used to disrupt power equipment in several regions outside the United States. In at least one case, the disruption caused a power outage affecting multiple cities. We do not know who executed these attacks or why, but all involved intrusions through the Internet."
That's why they invented out-of-band management tools long, long ago.
Given the nature of how the internet works, having a dial-up line to a management console (who then requires authentication) is much better for OOB management than using the Internet.
Jeroen Ruigrok/Asmodai
Presuming that InformationWeek had their typical lame coverage here, a quick search found a much better article about this at Forbes (they even know to ask Bruce Schneier about it!) where they link to a nice background article about these SCADA systems.
From some articles it seems that the affected cities are from Central and South America, including some in Mexico.