SCADA Security Hacking Story: New York Dam

In 2013, an incident occurred in New York involving the intrusion of Iranian hackers into a small dam known as Bowman Dam. While the nature of the attack was not particularly sophisticated, it served as a test for the hackers to gauge the extent of their access to the dam’s systems.

Bowman Dam, a vital utility for managing storm surges, had its Supervisory Control and Data Acquisition (SCADA) system connected to the internet through a cellular modem. It’s important to note that the attack occurred during a maintenance period when the SCADA system’s control features were not operational, limiting the potential damage. Nevertheless, the attackers could infiltrate the system and only could monitor its status.

The primary cause of concern surrounding this incident lies in the vulnerability of the dam’s internet connection and the lack of robust security controls in place. It is widely believed that the dam was targeted not specifically due to its importance or value as a target but because of its exposed internet connection. The hackers exploited this weakness to gain unauthorised access and exhibited high technical expertise by directly manipulating the SCADA equipment.

This case is a stark reminder of the inherent risks of directly exposing SCADA systems to the internet. When these systems are not adequately protected, they become attractive targets for potential hackers. The Bowman Dam intrusion underscores the urgent need for implementing stringent security measures to safeguard critical infrastructure from cyber threats.

