Security flaws put wind farms and factory robots at risk of ransomware
A single day of downtime could cost $700,000 researcher claims at Black Hat


Wind farms and factories that use robots are at risk from ransomware attacks, according to new research into the vulnerabilities found within many industrial control systems.
Security researcher Jason Staggs discovered that controllers are not encrypting all of their messages, reports the Financial Times, and often use default passwords or fail to separate networks. Researchers have warned that these major security flaws could force organisations to choose between damaging operational downtime or paying hackers a ransom in order to resume business.
Staggs told an audience at Black Hat conference in Las Vegas: "What if we wanted to ransomware a wind farm? I'm not talking encrypting data, I'm talking about paralysing wind farm operations in such a way they are no longer able to produce electricity."
Staggs estimated that shutting down a wind farm for a single day would cost the energy provider up to $700,000, and the attacker could cause further damage if the victim does not comply.
David Emm, principal researcher at Kaspersky Labs, commented "It's clear that the world isn't ready for cyber-attacks against critical infrastructure this includes governments, law enforcement agencies, those who run such facilities and those who design and build them.
"Attackers, on the other hand, are clearly ready and able to launch attacks on these facilities. We've seen attacks on power grids, oil refineries, steel plants, financial infrastructure, seaports and hospitals."
The devastating impact of these kinds of ransomware attacks has been illustrated by a number of recent cases, including the widespread Wannacry outbreak that hit the NHS last month.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
In that case, the under-funding of the NHS was partly blamed for the breach, with experts calling for more "trained, registered and accountable" security professionals to be recruited in future. Without them, the attack was dubbed inevitable.
"It's not sufficient to simply protect endpoints and networks, not least because no two facilities are the same," Emm continued. "Security must be tailored to the specific needs of each organisations and be seen as an ongoing process."
Main image credit: Bigstock
Caroline has been writing about technology for more than a decade, switching between consumer smart home news and reviews and in-depth B2B industry coverage. In addition to her work for IT Pro and Cloud Pro, she has contributed to a number of titles including Expert Reviews, TechRadar, The Week and many more. She is currently the smart home editor across Future Publishing's homes titles.
You can get in touch with Caroline via email at caroline.preece@futurenet.com.
-
Jaguar Land Rover says IT disruption set to continue
News The automotive manufacturer is still not fully operational after the recent cyber attack
-
Microsoft CEO Satya Nadella says UK ties are 'stronger than ever' as tech giant pledges $30bn investment
News Microsoft CEO Satya Nadella says it's commitment to the UK is "stronger than ever" after the tech giant pledged $30bn to expand AI infrastructure and build a new supercomputer.
-
Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million reward
News The US Department of Justice is offering a reward of up to $10 million for information leading to the arrest of Volodymyr Viktorovych Tymoshchuk, an alleged ransomware criminal.
-
Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack
News The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector
-
Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities
News The attack on IT systems supplier Miljödata has impacted public sector services across the country
-
A notorious hacker group is ramping up cloud-based ransomware attacks
News The Storm-0501 threat group is refining its tactics, according to Microsoft, shifting away from traditional endpoint-based attacks and toward cloud-based ransomware.
-
Security researchers have just identified what could be the first ‘AI-powered’ ransomware strain – and it uses OpenAI’s gpt-oss-20b model
News Using OpenAI's gpt-oss:20b model, ‘PromptLock’ generates malicious Lua scripts via the Ollama API.
-
Data I/O shuts down systems in wake of ransomware attack
News Regulatory filings by Data I/O suggest the costs of dealing with the attack could be significant
-
Average ransom payment doubles in a single quarter
News Targeted social engineering and data exfiltration have become the biggest tactics as three major ransomware groups dominate
-
BlackSuit ransomware gang taken down in latest law enforcement sting – but members have already formed a new group
News The notorious gang has seen its servers taken down and bitcoin seized, but may have morphed into a new group called Chaos