Darknet Diaries

68: Triton

34 snips
Jun 23, 2020
Julian Gutmanis, an industrial incident responder, along with Marina Krotofil from FireEye and Robert M. Lee, CEO of Dragos, dive into the Triton malware attack on a Saudi chemical plant. They discuss how this sophisticated malware jeopardizes safety systems, highlighting the dire consequences of cyber threats in industrial settings. The trio uncovers the complexities of cybersecurity and safety protocols, emphasizing the risks posed by insider threats. Moreover, they address the urgent need for robust security measures and international regulations to mitigate potential disasters.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

The Initial Incident

  • Six Triconex safety systems malfunctioned at a Saudi Arabian chemical plant, causing a shutdown.
  • The initial investigation revealed unauthorized configuration changes and a remote desktop session on an engineering workstation.
INSIGHT

Realizing the Security Incident

  • The plant initially thought the shutdown was due to mechanical problems, not a security incident.
  • Julian Gutmanis, an OT incident responder, recognized the seriousness of the situation upon learning about the unauthorized logins and safety system failures.
ANECDOTE

Arrival at the Plant

  • Julian and Nasser, OT incident responders, flew to the plant to investigate the incident.
  • Ironically, another shutdown occurred while they were at the security checkpoint, delaying their entry.
Get the Snipd Podcast app to discover more snips from this episode
Get the app