The Cybersecurity Threat To Railways

The European Union Agency for Cybersecurity (ENISA) has recently published its first cyber threat landscape report on the transport sector, covering the period from January 2021 to October 2022. Ransomware attacks have become an increasingly significant cyber threat facing the transport sector in the European Union, according to a new analysis published on March 21st.

The report identifies prime threats and examines cyber security breaches during this period. It also includes an assessment of threat actors, considers their motivation for launching cyber attacks and identifiers major trends by mode.

It warns that while the majority of ransomware attacks to-date have targeted information technology (IT) systems such as databases, ransomware groups “will likely target and disrupt” operational technology (OT) systems “in the foreseeable future,” potentially causing even more significant effects for victims.

Overall, ENISA says that ransomware is the main threat to the rail sector, accounting for 45% of cyber attacks.

  • Data-related threats accounted for 25%, as did denial of service (DoS), distributed denial of service (DDoS) and ransom denial of service (RDoS) attacks.
  • Hacks that exploited known IT vulnerabilities accounted for 15%, while fraud, impersonation and counterfeit, malware and supply chain attacks each accounted for 5%.

The majority of cyber attacks targeted railway IT systems, including those behind passenger operations ticket systems, mobile phone apps and passenger information systems, causing disruption by making these services unavailable. Examples included ransomware attacks targeting Swedish public transport authority Skånetrafiken in August 2021 and the Italian State Railways in March 2022 when customers were unable to purchase tickets due to infected IT systems.

Enisa says the only cases affecting operational technology (OT) systems involved entire networks, or where safety-critical IT systems were unavailable.

Notable data thefts included cases at Norfolk Southern (NS), shortline operator OmniTrax and the New York Metropolitan Transportation Authority (MTA) in the United States, as well as at passenger operators Merseyrail in Britain and Lokaltog in Denmark. Personnel and medical records were stolen, and Enisa says that OmniTrax is the first publicly-known case of a double-extortion ransomware attack against a US freight rail operator.

The report also highlights the extensive disruption to Danish State Railways (DSB) services in October 2022. DSB ICT service provider Supeo was itself the victim of a cyber attack, with the result that DSB drivers could not access a key safety-critical IT system, disrupting DSB operations for several hours.

ENISA noted a ransomware attack on the Belarusian state-run train company in January 2022 “in a bid to disrupt Russian troop movements” when the attackers “deployed modified ransomware to bring down the railway system and encrypted servers, databases and workstations belonging to the Belarusian railway service.” The report says that the increasing proportion of DDoS attacks in the rail sector is due to the increased hacktivist activity which followed the invasion of Ukraine, undertaken by pro-Russian or anti-Nato groups.

Pro-Russian hacker groups have claimed responsibility for attacks in 2022 on Romanian national operator CFR Calatori in April, on Lithuanian Railways and Latvian operator SJSC in June, and against Estonian Railways in August.

Considering the issue of cyber attacks exploiting known vulnerabilities to IT systems, ENISA says that two cases stand out.

  • In December 2021 Toronto public transport agency Metrolinx temporarily took down its website as a precautionary measure, after being informed by the Canadian government that it was vulnerable to cyber attack.
  • A system vulnerability potentially allowing access to customers’ personal data held by Swiss Federal Railways (SBB) was reported by an anonymous hacker in January 2022.

Breaking down the attacks by target, the report says that 21, or 72%, were aimed at infrastructure managers and operators, seven (3%) at transport authorities and other public bodies, and only one (3%) at an IT service provider.

“Transport is a key sector of our economy that we depend on in both our personal and professional lives,” says ENISA Executive Director, Juhan Lepassaar“Understanding the distribution of cyber threats, motivation, trends and patterns, as well as their potential impact, is crucial if we want to improve the cyber security of the critical infrastructure involved.” Lepassaar added.

ENISA:   ENISA:   ENISA:  Rail Journal:   The Record:       Railway-Cybersecurity:     Railpage

You Might Also Read: 

UK Rail Signals Can Be Hacked To Cause Crashes:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

 

« The Inevitable Rise Of Artificial Intelligence
Imminent: Cybersecurity Regulations For US Financial Services »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Cyber Secure Forum

Cyber Secure Forum

The Cyber Secure Forum is a premier cybersecurity event dedicated to bringing together experts, and professionals to explore the latest trends, share knowledge, and discuss strategies.

Australian Signals Directorate (ASD)

Australian Signals Directorate (ASD)

The Australian Signals Directorate is an intelligence agency in the Australian Government Department of Defence.

CompliancePoint

CompliancePoint

We design and implement strategies, processes & procedures to mitigate risk, reach compliance goals, protect data assets, and meet industry standards.

Romanian Association for Information Security Assurance (RAISA)

Romanian Association for Information Security Assurance (RAISA)

RAISA promotes and supports information security activities and creates a community for the exchange of knowledge between specialists, academic and corporate environment in Romania.

Merlin Cyber

Merlin Cyber

Merlin is a premier cybersecurity platform that leverages security technologies, trusted relationships, and capital to develop and deliver groundbreaking security solutions.

CyRise

CyRise

CyRise is a venture accelerator focused squarely on early stage cyber security startups.

Uppsala Security

Uppsala Security

Uppsala Security built the first crowdsourced Threat Intelligence platform known as the Sentinel Protocol, which is powered by blockchain technology.

Verafin

Verafin

Verafin is one of the North American leaders in fraud detection and AML software.

CultureAI

CultureAI

CultureAI deliver intelligent cyber security awareness education and tools that build resilient security cultures where employees help defend.

Hack The Box

Hack The Box

Hack The Box is an online platform allowing you to test your penetration testing skills and exchange ideas and methodologies with thousands of people in the security field.

Secure Digital Solutions (SDS)

Secure Digital Solutions (SDS)

Secure Digital Solutions is a leading consulting firm in the business of information security providing cyber security program strategy, enterprise risk and compliance, and data privacy.

Prodera Group

Prodera Group

Prodera Group is a specialist technology consulting partner trusted to help navigate the complex and dynamic lifecycle of change and transformation.

Protected Media

Protected Media

Protected Media’s advanced cybersecurity ad fraud solution guards you against current and emerging threats across Connected TV, Display and Video advertising.

The Security Bulldog

The Security Bulldog

The Security Bulldog distills and assimilates open source cyber intelligence to enable security teams to understand threats more quickly, make better decisions, and accelerate detection and response.

Kerberus Cyber Security

Kerberus Cyber Security

Kerberus Cyber Security (formerly MintDefense) is a leading innovator in Web3 user security, dedicated to safeguarding digital assets and transactions through its flagship product, Sentinel3.

Cyberverse Foundation

Cyberverse Foundation

Cyberverse Foundation is an organization dedicated to building a robust cybersecurity ecosystem in India.