Security flaws put wind farms and factory robots at risk of ransomware
A single day of downtime could cost $700,000 researcher claims at Black Hat
Wind farms and factories that use robots are at risk from ransomware attacks, according to new research into the vulnerabilities found within many industrial control systems.
Security researcher Jason Staggs discovered that controllers are not encrypting all of their messages, reports the Financial Times, and often use default passwords or fail to separate networks. Researchers have warned that these major security flaws could force organisations to choose between damaging operational downtime or paying hackers a ransom in order to resume business.
Staggs told an audience at Black Hat conference in Las Vegas: "What if we wanted to ransomware a wind farm? I'm not talking encrypting data, I'm talking about paralysing wind farm operations in such a way they are no longer able to produce electricity."
Staggs estimated that shutting down a wind farm for a single day would cost the energy provider up to $700,000, and the attacker could cause further damage if the victim does not comply.
David Emm, principal researcher at Kaspersky Labs, commented "It's clear that the world isn't ready for cyber-attacks against critical infrastructure this includes governments, law enforcement agencies, those who run such facilities and those who design and build them.
"Attackers, on the other hand, are clearly ready and able to launch attacks on these facilities. We've seen attacks on power grids, oil refineries, steel plants, financial infrastructure, seaports and hospitals."
The devastating impact of these kinds of ransomware attacks has been illustrated by a number of recent cases, including the widespread Wannacry outbreak that hit the NHS last month.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
In that case, the under-funding of the NHS was partly blamed for the breach, with experts calling for more "trained, registered and accountable" security professionals to be recruited in future. Without them, the attack was dubbed inevitable.
"It's not sufficient to simply protect endpoints and networks, not least because no two facilities are the same," Emm continued. "Security must be tailored to the specific needs of each organisations and be seen as an ongoing process."
Main image credit: Bigstock
Caroline has been writing about technology for more than a decade, switching between consumer smart home news and reviews and in-depth B2B industry coverage. In addition to her work for IT Pro and Cloud Pro, she has contributed to a number of titles including Expert Reviews, TechRadar, The Week and many more. She is currently the smart home editor across Future Publishing's homes titles.
You can get in touch with Caroline via email at caroline.preece@futurenet.com.
-
Cyber experts issue alert after two ransomware groups team up on ‘unprecedented’ threat campaignNews The tie-up includes a new model of industrialized ransomware deployment that significantly lowers the barrier to entry for cyber crime
-
Agentic AI 'breaks the traditional SaaS seat licensing model'News Incumbent software vendors will need to work harder than ever to compete with agile, AI-focused disruptors
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals
-
Ransomware negotiator sentenced for role in major cyber crime groupNews Deniss Zolotarjovs was a key player in a group associated with Conti
-
Threat actors ditch ‘spray and pray’ attacks in shift to targeted exploitationNews A dip in ransomware volumes points to a more targeted approach focused on vulnerability exploitation
-
Security leaders overconfident about ransomware recoveryNews Few manage to recover all their data, and many experience business disruption
-
German authorities want your help finding the hackers behind GandCrab and REvilNews Daniil Maksimovich Shchukin and Anatoly Sergeevitsch Kravchuk are believed to have made millions from ransomware as a service schemes