Cyberattacks against infrastructure
Critical infrastructure, including control systems, energy grids, financial institutions, transportation networks, and water facilities, is a frequent target of cyberattacks. As these systems increasingly rely on interconnected industrial control systems (ICS) and SCADA networks, their vulnerability to remote exploitation has grown. Cyberattacks that result in adverse physical effects are classified as cyber-physical attacks.[1]
Cyberattacks on critical infrastructure have increased significantly in recent decades. High-profile incidents across various sectors, such as the Colonial Pipeline cyberattack in energy, ransomware attacks on hospitals, and cyber espionage targeting nuclear waste management sites, highlight the growing economic disruption, safety hazards, and data security threats posed by vulnerabilities in critical infrastructure.
Control systems
Historically, a report on industrial cybersecurity problems by the British Columbia Institute of Technology and the PA Consulting Group, using data from as far back as 1981, found a tenfold increase in the number of successful cyberattacks on SCADA systems infrastructure between 1981 and 2000.[2]
Industrial control systems (ICS) are responsible for activating and monitoring industrial or mechanical processes. Many devices are integrated with computer platforms to control physical infrastructures, such as valves, gates, and electrical substations. These systems are often designed as remote telemetry devices that link to other physical devices via the internet or communication networks. Because ICS networks were traditionally isolated from corporate IT environments, they frequently lacked built-in security protocols, such as password protection or network segmentation, leaving them vulnerable to exploitation.
In an early 2000s security assessment demonstrated by cybersecurity firm manager Paul Blomgren, engineers highlighted how easily these legacy vulnerabilities could be exploited. By accessing an unsecured wireless network antenna at a remote substation from their vehicle, the team connected to the system without requiring a password. Within 20 minutes, they mapped the facility's operational equipment, bypassed the control network to access the connected business network, and extracted sensitive reports without entering the facility.[3]
Energy
Energy is considered an infrastructure that could be attacked[4] and is broken down into two categories: electricity and natural gas.
Cyberattacks on natural gas installations are similar, as cyberterrorists can shut down the installations or reroute gas flows to another section. In Russia, a gas supplier known as Gazprom lost control of its central switchboard, which routes gas flow, after an inside job and Trojan horse program bypassed security.[5] The 2021 Colonial Pipeline cyberattack caused a sudden shutdown of the pipeline that carried 45% of the gasoline, diesel, and jet fuel consumed on the East Coast of the United States.[6]
Wind farms, both onshore and offshore, are also at risk. In February 2022, a German wind turbine maker, Enercon, lost remote connection to approximately 5,800 turbines following a large-scale disruption of satellite links. In April 2022, another company, Deutsche Windtechnik, also lost control of roughly 2,000 turbines due to a cyberattack. While the wind turbines were not damaged during these incidents, these attacks show how vulnerable these companies' computer systems are.[7]
Finance
Financial infrastructures are increasingly vulnerable to cyberattacks due to their reliance on interconnected computer systems. The financial system's complexity and the constant flow of transactions make it an attractive target for cybercriminals. A significant breach could lead to massive financial losses, erode public trust, and destabilize economies.
The landscape of financial cyber threats has expanded rapidly, with threat actors becoming increasingly sophisticated. According to cybersecurity research, financial sector organizations faced an average of over 1,100 cyberattacks per week globally in the early 2020s, reflecting a significant post-pandemic surge in targeted attacks.[8]
A cyberattack on a financial institution or its transactions may be referred to as a "cyber heist". These attacks often begin with phishing campaigns that exploit social engineering tactics to deceive employees into divulging sensitive information. Once inside the network, attackers can deploy keyloggers to capture login credentials and gain unauthorized access to banking systems.
In February 2013, a global cybercrime network executed a coordinated ATM cash-out heist targeting Oman's Bank of Muscat, stealing US$40 million in under 24 hours.[9] Hackers breached third-party credit card processing systems to eliminate withdrawal limits on prepaid debit cards, enabling coordinated teams in over 20 countries to make thousands of simultaneous cash withdrawals.[9] The operation was part of a broader $45 million scheme that also targeted the United Arab Emirates' National Bank of Ras Al-Khaimah.[9] In March 2025, the hacker group "Code Breakers" breached Iranian Bank Sepah, exposing customer and account records across the institution.[10]
Transportation
Like telecommunications, transportation infrastructure relies on interconnected computer systems for scheduling and operations. Impeding transportation in a city or region has economic consequences. Successful cyber attacks can impact scheduling and accessibility, creating a disruption in the economic chain. In January 2003, during the propagation of the SQL Slammer worm, Continental Airlines was forced to cancel flights and halt check-in systems due to widespread network disruption.[11] In May 2015, Chris Roberts, a former cyber consultant, claimed to the FBI that he had repeatedly managed to hack into the in-flight entertainment system of a Boeing 737 and had at least once ordered a flight to climb. The FBI, after detaining him in April 2015 in Syracuse, had interviewed him about the allegations.[12]
Water
In 2024, multiple US water facilities had their industrial equipment compromised by hackers to display anti-Israel messages. Although it resulted in no major damage, the mass attack revealed security vulnerabilities in the United States' water facilities due to a lack of funding and resources.[13]
Waste management
In 2023, the Radioactive Waste Management (RWM) company, owned by the government of the United Kingdom, experienced an unsuccessful cybersecurity breach through LinkedIn. The attack attempted to identify and access the people who were part of the business.[14]
In 2023, Sellafield, the UK's largest and most hazardous nuclear waste disposal site, was targeted by hackers linked to Russia and China. Sleeper malware was discovered inside the site's networks, and it is unknown how long it had been installed or if it had been fully removed. The full extent of the weak security was exposed when staff found they could access Sellafield's servers from outside the site. Reports in 2012 and 2015 reported that the company and its senior management had been aware of the security vulnerabilities, but failed to report or spend resources to address them. As a result, Sellafield's sensitive documents, such as their foreign attack or disaster emergency defense plans and radioactive waste management, may have been compromised.[15]
It is possible for smaller-scale electronics in e-waste to become targets of cyberattacks as well. The PwC estimates that by 2030, the number of Internet of Things (IoT) devices owned around the world would reach over 25 billion. And of that, 70 million tonnes of e-waste will be generated and disposed of. Although only based on anecdotal evidence, it is estimated that the majority of this e-waste may contain components that retain sensitive information and personal data. Cyber criminals may target e-waste from individuals or organizations to gain access to sensitive data that isn't as securely guarded as that on active devices.[16]
Hospitals and medical facilities
Cyberattacks on hospital infrastructure could directly lead to deaths. The cyberattacks are designed to deny hospital workers access to critical care systems. Amidst the COVID-19 pandemic, there was a major increase in cyberattacks against hospitals. Hackers locked up networks and demanded ransoms to return access to these systems.[17]
Hospitals and medical facilities have seen increases in ransomware attacks in which criminals encode Protected Health Information (PHI) and other personally identifiable information. When the ransom is paid, the money is exchanged for a key to decode the information and to return the stolen data.[18] Access points into hospital infrastructure are often through third-party companies that hospitals may contract jobs through. The HIPAA Omnibus Rule created in 2013 requires all contracted businesses to perform work for hospitals where patient information would be required to be held to the same standards of security.[19]
An increasingly common access point has been through cameras and security systems that are added to the hospitals' networks. As more outside companies and devices become connected through the internet, the risks for cyberattacks increases. The increase in attacks during the COVID-19 pandemic led researchers to conclude that increased remote work heightened potential areas of vulnerability.[20] One tactic that has been effective in preventing cyberattacks in the healthcare industry is the Zero Trust method, where users known and unknown are viewed as a potential threat and requires everyone to verify their identity with the appropriate credentials.[18]
The increased use of Electronic Medical Records (EMR) required a greater need for security to protect patient information and privacy.[19] When a hospital experiences a data breach in the United States, the facility is required to report the breach to the people impacted under the Health Information Technology for Economic and Clinical Health Act, also called the HITECH ACT, as it has the Breach Notification Rule. The rule states that facilities are required to report data breaches if the facility provides patient care under HIPAA guidelines. The Health Insurance Portability and Accountability Act protects patients' right to privacy regarding their Protected Health Information (PHI).[21] Accessing PHI can be very lucrative for cybercriminals as this information can contain home addresses, Social Security numbers, banking information, and other personally identifiable information.[18]
See also
- Critical infrastructure protection
- Cyberwarfare
- Industrial control system
- SCADA Strangelove
References
- ↑ Loukas, George (June 2015). Cyber-Physical Attacks A growing invisible threat. Oxford, UK: Butterworth-Heinemann (Elsevier). p. 65. ISBN 978-0-12-801290-1. http://dl.acm.org/citation.cfm?id=2818550.
- ↑ Byres, Eric; Lowe, Justin (October 2004). "The Myths and Facts behind Cyber Security Risks for Industrial Control Systems". 116. VDE Association for Electrical Electronic and Information Technologies.
- ↑ Brown, Alan S. (December 2002). "SCADA vs. the Hackers". Mechanical Engineering (American Society of Mechanical Engineers) 124 (12): 62–63. https://asmedigitalcollection.asme.org/memagazineselect/article-abstract/124/12/37/379167/SCADA-vs-the-HackersCan-Freebie-Software-and-a-Can.
- ↑ Trakimavicius, Lukas (2023-03-31). "Protect or Perish: Europe's Subsea Lifelines" (in en-US). Center for European Policy Analysis. https://cepa.org/article/protect-or-perish-europes-subsea-lifelines/.
- ↑ Denning, Dorothy E. (23 May 2000). "Cyberterrorism: Testimony before the Special Oversight Panel on Terrorism". United States House Committee on Armed Services. https://irp.fas.org/congress/2000_hr/00-05-23denning.htm.
- ↑ "FBI Statement on Compromise of Colonial Pipeline Networks". Federal Bureau of Investigation. 10 May 2021. https://www.fbi.gov/news/press-releases/fbi-statement-on-compromise-of-colonial-pipeline-networks.
- ↑ Trakimavicius, Lukas (2023-01-23). "Predators Will Circle Baltic Power Farms" (in en-US). Center for European Policy Analysis. https://cepa.org/article/west-must-secure-baltic-sea-renewable-energy-resources/.
- ↑ Check Point Research (10 January 2022). "Cyber Attacks Increased 50% Year over Year". Check Point Software Technologies. https://blog.checkpoint.com/security/check-point-research-cyber-attacks-increased-50-year-over-year/.
- ↑ 9.0 9.1 9.2 Vaughan, Bernard (18 November 2013). "Six arrested in $45 million global cybercrime scheme". Reuters. https://www.reuters.com/article/technology/six-arrested-in-45-million-global-cybercrime-scheme-idUSBRE9AH0YZ/.
- ↑ Davidi, O. (12 June 2025). "Cybercrime or Political Warfare? The "Code Breakers" Hack of Bank Sepah's Systems". Jerusalem Institute for Strategy and Security. https://jiss.org.il/en/davidi-cybercrime-or-political-warfare/.
- ↑ Moore, David; Paxson, Vern; Savage, Stefan; Shannon, Colleen; Staniford, Stuart; Weaver, Nicholas (February 2003). "The Spread of the Sapphire/Slammer Worm". CAIDA. https://www.caida.org/catalog/papers/2003_sapphire/.
- ↑ Perez, Evan (18 May 2015). "FBI: Hacker claimed to have taken over flight's engine controls". CNN. http://www.cnn.com/2015/05/17/us/fbi-hacker-flight-computer-systems/index.html.
- ↑ Lyngaas, Sean (2024-03-19). "Cyberattacks are hitting water systems throughout US, Biden officials warn governors | CNN Politics" (in en). https://www.cnn.com/2024/03/19/politics/cyberattacks-water-systems-us/index.html.
- ↑ Lawson, Alex; Isaac, Anna (2023-12-31). "Cyber-hackers target UK nuclear waste company RWM" (in en-GB). The Guardian. ISSN 0261-3077. https://www.theguardian.com/business/2023/dec/31/cyber-hackers-target-uk-nuclear-waste-company-rwm.
- ↑ Isaac, Anna; Lawson, Alex (2023-12-04). "Sellafield nuclear site hacked by groups linked to Russia and China" (in en-GB). The Guardian. ISSN 0261-3077. https://www.theguardian.com/business/2023/dec/04/sellafield-nuclear-site-hacked-groups-russia-china.
- ↑ PricewaterhouseCoopers (June 2023). After Life: Critical infrastructure and the e-waste data security threat (Report). PwC Australia. https://www.pwc.com.au/cyber/critical-infrastructure-afterlife-report.pdf. Retrieved 2026-08-04.
- ↑ "Cyber Daily: Human-Rights Groups Want Law Enforcement to Do More to Stop Hospital Cyberattacks". The Wall Street Journal. 1 June 2020. https://www.wsj.com.
- ↑ 18.0 18.1 18.2 Vukotich, George (2023). "Healthcare and cybersecurity: Taking a Zero trust approach". Health Services Insights 16. doi:10.1177/11786329231187826. PMID 37485022.
- ↑ 19.0 19.1 Yaraghi, Niam (2018). "The Role of HIPAA Omnibus Rules in Reducing the Frequency of Medical Data Breaches: Insights From an Empirical Study". The Milbank Quarterly 96 (1): 144–166. doi:10.1111/1468-0009.12314. PMID 29504206.
- ↑ Wiggen, Johannes (6 June 2020). The Impact of COVID-19 on Cyber Crime and State-Sponsored Cyber Activities (Report). Konrad-Adenauer-Stiftung. https://www.kas.de/en/analysen-und-argumente/detail/-/content/die-auswirkungen-von-covid-19-auf-cyberkriminalitaet-und-staatliche-cyberaktivitaeten. Retrieved 2026-08-04.
- ↑ Dolezal, Diane (2023). "Effects of internal and external factors on hospital data breaches: Quantitative study". Journal of Medical Internet Research 25. doi:10.2196/51471. ProQuest 2917629718. PMID 38127426. PMC 10767628. https://www.proquest.com/docview/2917629718.
