August 16, 2022
The hackers who generously decided not to ransomware a UK water treatment company are missing a trick. But, before we look at that, it is worth mentioning that the threat actor appears to count coup on the wrong victim, and the reporting follows along. Thames Water isn’t the victim of this breach, so that’s lol.
On to the hack, these guys are making a mistake, attacking a water treatment plant and threatening it. Even to say, “see, we could’ve done worse but didn’t”, is going to get people very riled up. This is critical national infrastructure. This is a big deal. GCHQ will be hunting them down, and the public would be happy to see them strung up. Do not fuck with people’s water supply.
How to turn that around and make it a tool they could use to their advantage? Easy. UK water companies are terrible, horrible, polluters dumping sewage and plastic into the water. They are fucking with people’s water supply.
These hackers should’ve pulled all the emails they could find and made them available to researchers (academics and journalists). Put them up as an online search tool and as an afterthought also available to download. Something to give the researchers plausible deniability so they can look at the data “in the public interest.”
“It was publicly available, and normally we would never look through private files, but given the public interest and the public nature of the available documents, we felt that it was worth… blah blah. Anyway.
“Here is the terrible thing that water companies are doing!!!
The water companies are fucking with peoples water supply; only no one is talking about it. Change that. Expose the duplicity and corruption in handling the UK’s water, and people will forget the origin of the data. Hell, they’d probably get a medal.
Since they’re not making money, their best option is exposing sewage dumping polluters. The worst option — the one they chose — is to say, “we could have totally killed you guys, but we didn’t. You’re welcome.”
Have fun getting wrecked by Cyber von Cheltenham!
-
Great WoTR piece: Ending the Ideology of the Offensive
https://warontherocks.com/2022/08/ending-the-ideology-of-the-offense-part-i/-
-
-
~Attacking Titan M with Only One Byte~
https://blog.quarkslab.com/attacking-titan-m-with-only-one-byte.html-
-
Some states hold onto those blood samples for years, even decades, and police may now be using them in criminal investigations. My latest for @WIRED:-
-
-
-
-
-
-
-
-
-
An anti tracking device that scans for SSIDs and MACs (presumably from phones) and alerts if the same ones keep showing up.
https://www.wired.com/story/this-anti-tracking-tool-checks-if-youre-being-followed/ https://github.com/azmatt/chasing_your_tail-
-
This thread is really cool
Least-related animal: Sponges. You and sponges are both animals. That's basically all you've got in common.-