back to article This is the FBI, open up. China's Volt Typhoon is on your network

Nick Lawler, general manager of the Littleton Electric Light and Water Departments (LELWD), was at home one Friday when he got a call from the FBI alerting him that the public power utility's network had been compromised. The digital intruders turned out to be Volt Typhoon. Lawler didn't believe it at first. LELWD provides …

  1. Jou (Mxyzptlk) Silver badge

    Nice article!

    And the time it gets posted is well timed too! Just 11 hours after the other article relevant to that...

    1. Guy de Loimbard Silver badge
      Big Brother

      Re: Nice article!

      Indeed, a good article.

      Also, you couldn't make up some of the catastrophic choices being made in the US at the moment.

      It's almost like opening the doors and leaving the lights on when you go on holiday.

      At a time of heightened cyber activity, you don't slash and burn your capabilities.... surely?

      1. Anonymous Coward
        Anonymous Coward

        Re: Nice article!

        Yes, no need to worry about the FBI spoiling your weekend with alerts about Chinese hackers, they will soon be all DOGEd.

        Can't have our peons bothering our fellow dictators.

        1. Yet Another Anonymous coward Silver badge

          Re: Nice article!

          No, we are only at war with China, we have always been at war with China.

          Russia never hacks us, Russia are our friends, Russia has always been our friends

          1. Paul Hovnanian Silver badge
            Big Brother

            Re: Nice article!

            Oceania had always been at war with Eastasia.

  2. Anonymous Coward
    Anonymous Coward

    I am deeply impressed.

    First by Lawler's initial response - it really did sound like a scam, so good job not providing personal info or clicking a link sent via a text.

    But even more impressed by the FBI's response - actually showing up in person (ok, they sent Homeland Security) instead of shrugging and saying "well, we tried to warn them".

    Then following through, including running a penetration test to make sure all the vulnerabilities were closed.

    Great job all around! (Except for Volt Typhoon, which should probably be renamed to Sewer Drinker or something similarly awful.)

    1. Guy de Loimbard Silver badge
      Thumb Up

      Re: I am deeply impressed.

      I second your view!

      I think it should make a good poster boy/case study for how to deal with this sort of issue, from beginning to end.

    2. Anonymous Coward
      Anonymous Coward

      Re: I am deeply impressed.

      I feel like the FBI's actions were terrible, and the employee's response (f-off, asshole!) was completely justified. I probably would have been just as cold but less insulting, told them what I think about the method (in straight-forward, honest terms), and hung up -- without calling the FBI office.

      What kind of ass asks for *personal* contact information for company business?

      Send a letter, if it simply can't be communicated through that network. Next-day if needed. Have them call you back at the FBI HQ and discuss steps to do next. There are better ways of doing *anything* than cold-calling someone, saying you're the FBI, and asking for their personal information. Fuck that, *especially* if you really are the FBI.

      1. fnusnu

        Re: I am deeply impressed.

        No point sending an email to a work address on a network compromised by hackers thereby alerting them to the FBI's actions.

        You haven't thought this through, have you?

  3. Doctor Syntax Silver badge

    "We don't have any access to large critical infrastructure."

    From their customers PoV they were probably exactly that themselves.

    1. MachDiamond Silver badge

      ""We don't have any access to large critical infrastructure.""

      Sure, an electric company wouldn't have a database of customer's information including those silly enough to sign up for auto-pay. Electric usage has been strongly correlated to wealth on a country level and I imagine that the premise translates, relatively, to the local level as well. A household in an area of higher than average property prices that uses lots of electricity on a regular basis is going to be better off. Name, address, estimated income/wealth, credit card number, tax ID, phone number (as good as a national ID) and the power company's records become very useful.

      I like spy novels and they often go into how the protagonist is able to pull the information they need out of random data that they can get access to. This makes me very careful about the information I give out about myself. I don't think I have anything important to hide, but maybe I win the lottery this week. Maybe the Man is hunting for another spy and there's enough hits about me that I become a suspect and wind up collected and taken downtown to sit under a naked light bulb answering nonsensical (to me) questions for hours. Better to be a Blank.

      1. martinusher Silver badge

        This is routine for everyday web usage. Unfortunately. Because the information that's collected about you is not collected by a shadowy spy agency but is a commodity for sale (or, more likely, hire).

  4. Michael Strorm Silver badge

    Going by the accompanying thumbnail, it looks like it's too late...

    China has already managed to do some very strange things to their infrastructure.

    1. trindflo Silver badge

      Re: Going by the accompanying thumbnail, it looks like it's too late...

      Picture was already gone by the time I read the article. Thanks for sharing it. Reading Stormlight now and I needed that picture!

  5. Claptrap314 Silver badge

    "We don't have any access to large critical infrastructure. We don't own transmission. We're a distribution company. Yes, we're part of the overall grid, but the impact of taking out Littleton is small. You would never think that would be a target of any type of attack," Lawler told The Register.

    You know, unless you had heard about L0ft's testimony to the US Congress in...1998?

    Okay, so it's not the job of the GM to be a cybersecurity expert. But you are designated as critical infrastructure. Somebody in the US government that you support so much thinks you matter. You have to wait for a personal contact that you done f***ed up to believe it?

    Okay, so I can appreciate, very much, this part "It sounded like one of those Microsoft scams," Lawler said. He told the agent: "Go f-yourself, I'm not going to click on a link, you must think I'm an idiot. What is your name again?" Personally, as this was from the FBI, I would have gone with, "You ever hear of Frank Abernathy? I'm doing what he told me in this situation." And hung up. Yeah, you call the FBI up after that, since you are the GM of designated national critical infrastructure. Otherwise??? Yeah, that's a seriously unprofessional contact.

    1. MachDiamond Silver badge

      "You know, unless you had heard about L0ft's testimony to the US Congress in...1998?"

      I would have loved to have a collective like L0ft Heavy Industries in my neck of the woods in that era.

    2. O'Reg Inalsin

      Abagnale? I couldn't find anything about Frank Abernathy.

      1. Claptrap314 Silver badge

        Gah!! I keep getting it wrong. Mea Culpa

  6. Paul Hovnanian Silver badge

    The FBI ...

    ... probably could have thought through their approach a bit more. Like request that the person contacted should forward the information to their IT team or consult with a security expert.

    But then that's not just the FBI. I had my credit card company ask me to call them back at a number I didn't recognize. About some questionable charges. No way I'm calling that. But I did contact them on the customer service number on the back of the card. After getting the charge problem handled, I made a suggestion that they never request customers contact them through unknown numbers. It instills bad habits. And I don't really mind being forwarded by the primary service contact to the proper department.

    1. Claptrap314 Silver badge

      Re: The FBI ...

      I've had the (in)security department of a bank call me up & try to get me to prove who I was. I let them have it. Then I called the number on the back of my card.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like