The Cybersecurity and Infrastructure Security Agency, FBI and Department of Energy yesterday urged the energy sector and other critical infrastructure organizations to take certain actions to reduce cyber risks from state-sponsored Russian actors targeting the global energy sector. The FBI also alerted global critical infrastructure industrial control systems that a research institution controlled by the Russian government continues to target the global energy sector utilizing malware known as TRITON.

John Riggi, AHA鈥檚 national advisor for cybersecurity and risk, said, 鈥淏oth of the alerts relate the threats emanating from the same Russian research institute supporting the Russian military. As noted in the alert, TRITON was first used in 2017 to target a foreign petrochemical facility. This attack represented a notable shift in industrial control system targeting as the first attack designed to allow physical damage, environmental impact, and loss of life in the event of a plant鈥檚 running in an unsafe condition. Hospitals鈥 and health systems鈥 cybersecurity teams are encouraged to share these alerts with their facilities鈥 teams and all third parties providing operational technology services.鈥

For more information on these or other cyber and risk issues, contact Riggi at jriggi@aha.org.

Related News Articles

Headline
The Cybersecurity and Infrastructure Security Agency April 17 released guidance to reduce risks associated with a reported breach of Oracle cloud services.鈥
Headline
The National Counterintelligence and Security Center, the FBI, and the Defense Counterintelligence and Security Center yesterday released guidance on鈥
AHA Cyber Intel
While the rate of cyberattacks on hospitals has risen dramatically, the severity of the impacts has also grown exponentially. Let鈥檚 look at the state of cyber鈥
Headline
The House Energy and Commerce Oversight and Investigations Subcommittee April 1 discussed cybersecurity threats in legacy medical devices during a hearing. The鈥
Headline
The Trump Administration March 28 announced that it renewed for one year the public emergency for ongoing malicious cyber-enabled activities against the U.S.鈥
Headline
The FBI March 26 advised that, after extensive investigation and intelligence review, they have not identified any specific credible threat targeted against鈥