An Exxon station in Washington. Petrol stations on the US East Coast ran dry last week after the Colonial Pipeline cyber attack. Reuters
An Exxon station in Washington. Petrol stations on the US East Coast ran dry last week after the Colonial Pipeline cyber attack. Reuters
An Exxon station in Washington. Petrol stations on the US East Coast ran dry last week after the Colonial Pipeline cyber attack. Reuters
An Exxon station in Washington. Petrol stations on the US East Coast ran dry last week after the Colonial Pipeline cyber attack. Reuters

These are the lessons of the US Colonial oil pipeline cyber attack


Robin Mills
  • English
  • Arabic

The US energy business should have learnt to be wary of the power of the DarkSide. After numerous warnings, it suffered its most disruptive cyber attack two Fridays ago when the Colonial oil pipeline was shut down after a ransomware attack, suspected to be from this gang. Cyber security needs to be improved but that alone is not enough: the energy industry needs broader resilience to such threats.

The pipeline brings refined oil products – petrol, diesel, heating oil and jet fuel – from the Texas refining complex to meet 45 per cent of consumption on the US East Coast, ultimately supplying New Jersey, New York and other states.

Hackers exfiltrated 100 gigabytes of data and then demanded payment to unencrypt the company's files. Colonial's operational systems were not affected but it shut down pipeline flows – either to prevent further dissemination or, as it now appears, because it could not bill customers. A $5 million ransom was paid to the hackers, according to Bloomberg.

Federal and state governments temporarily waived fuel quality standards and restrictions on hours and weights for road tankers. Traders booked tankers to bring refined products from Europe.

Some refiners were granted exemptions from the Jones Act, an outdated and pernicious law that requires all trade between American ports to be carried out by vessels built and flagged in the US and manned by Americans.

Nevertheless, petrol stations began to run dry: by Thursday evening, according to consumer service Gas Buddy, between half and two thirds of Georgia, Virginia, South and North Carolina were out of fuel. This was exacerbated by limited deliveries from distribution centres as tanker trucks themselves could not secure diesel, as well panic buying.

Indeed, shortages in southern Florida seem mostly to be due to hoarding as the state is primarily supplied by barges, not Colonial's network.

The company resumed pipeline flows on Thursday but it will probably take one to two weeks before service returns to normal in all areas. For the first time in six years, petrol prices rose above $3 a gallon during the interruption but, overall, the effects on demand will be slightly negative.

This is the most disruptive cyber attack in the US to date but far from the first for the energy industry. Electricity and gas pipeline companies have suffered intrusions in recent years that were either aimed at extortion or probing vulnerabilities. The US Department of Energy was one of the victims of the Solarwinds cyber espionage discovered in December.

The famous Stuxnet virus, strongly suspected to be the work of the US and Israel, damaged Iranian centrifuges in 2009 and 2010, setting back its uranium enrichment programme. The National Iranian Oil Company experienced a cyber attack in April 2012. That August, the Shamoon virus, possibly linked to Iran, wiped 30,000 computers at Saudi Aramco.

Several Saudi petrochemical companies have suffered cyber attacks since then while the Ukraine energy grid was also compromised, resulting in power cuts.

These, along with hacks on or by North Korea, are all known geopolitical flash points while growing hostility between the US and China is another. Cyber attacks have great attractions. They are deniable, difficult to identify – making it hard to apprehend perpetrators – while the damage can be gradated short of war. A group such as DarkSide could be a criminal enterprise but it could also be similar to Elizabethan privateers who were licensed by the state to attack its enemies. State agencies could use the cover of extortion attempts to conduct espionage or plant sabotage bugs.

Perhaps the surprise is not how devastating cyber attacks have been but how little damage they have done so far. There has not been serious and prolonged disruption or major physical damage or loss of life. DarkSide’s ransom from Colonial sounds like something Dr Evil would do – disconcerting his henchman by asking for only $1m.

But any of the conflicts mentioned, or others, could turn into more overt confrontations or a hacking group might go too far. Energy infrastructure – essential, exposed, expensive and explosive – is an obvious target.

Surveys suggest that energy cyber security is weak and characterised by inadequate passwords, outdated versions of Microsoft Exchange, employees who are easily duped into clicking on suspicious links, operational systems that are not properly "air-gapped" from the internet and a lack of "war games" to simulate cyber crises.

However, security improvements will not be enough – not against increasingly skilful, well resourced and motivated criminals and state-backed hackers. Digitisation and automation, remote working and operations, drones, the Internet of Things and the electrification of an economy powered by fossil fuels promise greater efficiency, cost savings and environmental gains. But they also expand vulnerabilities.

The Colonial incident exposed several major weaknesses in US energy security. Strategic petroleum stocks are nearly all along the Gulf of Mexico coast and not near other big consumption centres. The East Coast relies on a single system for about half of its petroleum demand. There are no mandatory pipeline cyber security regulations. Logistics faces the circular paradox of needing fuel to deliver fuel. The dead hand of the Jones Act constrains alternatives and there is no way to stop panic buying.

Many other countries would turn out to have similar or deeper flaws when seriously tested. February’s Texas ice storm, although not a cyber attack, highlighted the need to have electricity to deliver gas to generate electricity, and for both to make heat to keep people alive and water flowing.

Greater resilience involves a mix of improved cyber security, tougher infrastructure, duplication and back-ups, diversity of energy sources and delivery methods, more effective regulation and government powers of intervention, better accounting for human behaviour and stronger recovery plans.

Cyber attacks on energy systems will probably become more frequent, more ingenious and more disruptive. Several warnings have passed, fortunately without too much damage, but now it is time to act.

Robin Mills is chief executive of Qamar Energy and author of The Myth of the Oil Crisis

The%20specs
%3Cp%3E%3Cstrong%3EEngine%3A%20%3C%2Fstrong%3E3.5-litre%20twin-turbo%20V6%20%0D%3Cbr%3E%3Cstrong%3EPower%3A%20%3C%2Fstrong%3E456hp%20at%205%2C000rpm%0D%3Cbr%3E%3Cstrong%3ETorque%3A%20%3C%2Fstrong%3E691Nm%20at%203%2C500rpm%0D%3Cbr%3E%3Cstrong%3ETransmission%3A%20%3C%2Fstrong%3E10-speed%20auto%20%0D%3Cbr%3E%3Cstrong%3EFuel%20consumption%3A%20%3C%2Fstrong%3E14.6L%2F100km%0D%3Cbr%3E%3Cstrong%3EPrice%3A%20%3C%2Fstrong%3Efrom%20Dh349%2C545%0D%3Cbr%3E%3Cstrong%3EOn%20sale%3A%20%3C%2Fstrong%3Enow%3C%2Fp%3E%0A
Living in...

This article is part of a guide on where to live in the UAE. Our reporters will profile some of the country’s most desirable districts, provide an estimate of rental prices and introduce you to some of the residents who call each area home.

Winners

Best Men's Player of the Year: Kylian Mbappe (PSG)

Maradona Award for Best Goal Scorer of the Year: Robert Lewandowski (Bayern Munich)

TikTok Fans’ Player of the Year: Robert Lewandowski

Top Goal Scorer of All Time: Cristiano Ronaldo (Manchester United)

Best Women's Player of the Year: Alexia Putellas (Barcelona)

Best Men's Club of the Year: Chelsea

Best Women's Club of the Year: Barcelona

Best Defender of the Year: Leonardo Bonucci (Juventus/Italy)

Best Goalkeeper of the Year: Gianluigi Donnarumma (PSG/Italy)

Best Coach of the Year: Roberto Mancini (Italy)

Best National Team of the Year: Italy 

Best Agent of the Year: Federico Pastorello

Best Sporting Director of the Year: Txiki Begiristain (Manchester City)

Player Career Award: Ronaldinho

Sly%20Cooper%20and%20the%20Thievius%20Raccoonus
%3Cp%3E%3Cstrong%3EDeveloper%3A%3C%2Fstrong%3E%20Sucker%20Punch%20Productions%3Cbr%3E%3Cstrong%3EPublisher%3A%3C%2Fstrong%3E%20Sony%20Computer%20Entertainment%3Cbr%3E%3Cstrong%3EConsole%3A%3C%2Fstrong%3E%20PlayStation%202%20to%205%3Cbr%3E%3Cstrong%3ERating%3A%3C%2Fstrong%3E%205%2F5%3C%2Fp%3E%0A
EA Sports FC 26

Publisher: EA Sports

Consoles: PC, PlayStation 4/5, Xbox Series X/S

Rating: 3/5

Four tips to secure IoT networks

Mohammed Abukhater, vice president at FireEye in the Middle East, said:

- Keep device software up-to-date. Most come with basic operating system, so users should ensure that they always have the latest version

- Besides a strong password, use two-step authentication. There should be a second log-in step like adding a code sent to your mobile number

- Usually smart devices come with many unnecessary features. Users should lock those features that are not required or used frequently

- Always create a different guest network for visitors

In-demand jobs and monthly salaries
  • Technology expert in robotics and automation: Dh20,000 to Dh40,000 
  • Energy engineer: Dh25,000 to Dh30,000 
  • Production engineer: Dh30,000 to Dh40,000 
  • Data-driven supply chain management professional: Dh30,000 to Dh50,000 
  • HR leader: Dh40,000 to Dh60,000 
  • Engineering leader: Dh30,000 to Dh55,000 
  • Project manager: Dh55,000 to Dh65,000 
  • Senior reservoir engineer: Dh40,000 to Dh55,000 
  • Senior drilling engineer: Dh38,000 to Dh46,000 
  • Senior process engineer: Dh28,000 to Dh38,000 
  • Senior maintenance engineer: Dh22,000 to Dh34,000 
  • Field engineer: Dh6,500 to Dh7,500
  • Field supervisor: Dh9,000 to Dh12,000
  • Field operator: Dh5,000 to Dh7,000
SPECS
%3Cp%3E%3Cstrong%3EEngine%3A%20%3C%2Fstrong%3E2.4-litre%204-cylinder%20turbo%20hybrid%0D%3Cbr%3E%3Cstrong%3EPower%3A%3C%2Fstrong%3E%20366hp%0D%3Cbr%3E%3Cstrong%3ETorque%3A%20%3C%2Fstrong%3E550Nm%0D%3Cbr%3E%3Cstrong%3ETransmission%3A%20%3C%2Fstrong%3ESix-speed%20auto%0D%3Cbr%3E%3Cstrong%3EPrice%3A%3C%2Fstrong%3E%20From%20Dh360%2C000%0D%3Cbr%3E%3Cstrong%3EAvailable%3A%20%3C%2Fstrong%3ENow%0D%3C%2Fp%3E%0A
Suggested picnic spots

Abu Dhabi
Umm Al Emarat Park
Yas Gateway Park
Delma Park
Al Bateen beach
Saadiyaat beach
The Corniche
Zayed Sports City
 
Dubai
Kite Beach
Zabeel Park
Al Nahda Pond Park
Mushrif Park
Safa Park
Al Mamzar Beach Park
Al Qudrah Lakes 

UAE currency: the story behind the money in your pockets
Biggest%20applause
%3Cp%3EAsked%20to%20rate%20Boris%20Johnson's%20leadership%20out%20of%2010%2C%20Mr%20Sunak%20awarded%20a%20full%2010%20for%20delivering%20Brexit%20%E2%80%94%20remarks%20that%20earned%20him%20his%20biggest%20round%20of%20applause%20of%20the%20night.%20%22My%20views%20are%20clear%2C%20when%20he%20was%20great%20he%20was%20great%20and%20it%20got%20to%20a%20point%20where%20we%20need%20to%20move%20forward.%20In%20delivering%20a%20solution%20to%20Brexit%20and%20winning%20an%20election%20that's%20a%2010%2F10%20-%20you've%20got%20to%20give%20the%20guy%20credit%20for%20that%2C%20no-one%20else%20could%20probably%20have%20done%20that.%22%3C%2Fp%3E%0A
The%20specs
%3Cp%3E%3Cstrong%3EPowertrain%3A%20%3C%2Fstrong%3ESingle%20electric%20motor%0D%3Cbr%3E%3Cstrong%3EPower%3A%20%3C%2Fstrong%3E201hp%0D%3Cbr%3E%3Cstrong%3ETorque%3A%20%3C%2Fstrong%3E310Nm%0D%3Cbr%3E%3Cstrong%3ETransmission%3A%20%3C%2Fstrong%3ESingle-speed%20auto%0D%3Cbr%3E%3Cstrong%3EBattery%3A%20%3C%2Fstrong%3E53kWh%20lithium-ion%20battery%20pack%20(GS%20base%20model)%3B%2070kWh%20battery%20pack%20(GF)%0D%3Cbr%3E%3Cstrong%3ETouring%20range%3A%20%3C%2Fstrong%3E350km%20(GS)%3B%20480km%20(GF)%0D%3Cbr%3E%3Cstrong%3EPrice%3A%20%3C%2Fstrong%3EFrom%20Dh129%2C900%20(GS)%3B%20Dh149%2C000%20(GF)%0D%3Cbr%3E%3Cstrong%3EOn%20sale%3A%3C%2Fstrong%3E%20Now%3C%2Fp%3E%0A
UAE%20athletes%20heading%20to%20Paris%202024
%3Cp%3E%3Cstrong%3EEquestrian%3C%2Fstrong%3E%3Cbr%3EAbdullah%20Humaid%20Al%20Muhairi%2C%20Abdullah%20Al%20Marri%2C%20Omar%20Al%20Marzooqi%2C%20Salem%20Al%20Suwaidi%2C%20and%20Ali%20Al%20Karbi%20(four%20to%20be%20selected).%3Cbr%3E%3Cstrong%3EJudo%3C%2Fstrong%3E%3Cbr%3EMen%3A%20Narmandakh%20Bayanmunkh%20(66kg)%2C%20Nugzari%20Tatalashvili%20(81kg)%2C%20Aram%20Grigorian%20(90kg)%2C%20Dzhafar%20Kostoev%20(100kg)%2C%20Magomedomar%20Magomedomarov%20(%2B100kg)%3B%20women's%20Khorloodoi%20Bishrelt%20(52kg).%3Cbr%3E%3Cbr%3E%3Cstrong%3ECycling%3C%2Fstrong%3E%3Cbr%3ESafia%20Al%20Sayegh%20(women's%20road%20race).%3Cbr%3E%3Cbr%3E%3Cstrong%3ESwimming%3C%2Fstrong%3E%3Cbr%3EMen%3A%20Yousef%20Rashid%20Al%20Matroushi%20(100m%20freestyle)%3B%20women%3A%20Maha%20Abdullah%20Al%20Shehi%20(200m%20freestyle).%3Cbr%3E%3Cbr%3E%3Cstrong%3EAthletics%3C%2Fstrong%3E%3Cbr%3EMaryam%20Mohammed%20Al%20Farsi%20(women's%20100%20metres).%3C%2Fp%3E%0A
%20Ramez%20Gab%20Min%20El%20Akher
%3Cp%3E%3Cstrong%3ECreator%3A%3C%2Fstrong%3E%20Ramez%20Galal%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStarring%3A%3C%2Fstrong%3E%20Ramez%20Galal%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStreaming%20on%3A%20%3C%2Fstrong%3EMBC%20Shahid%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERating%3A%20%3C%2Fstrong%3E2.5%2F5%3C%2Fp%3E%0A
The specs: 2018 Mercedes-AMG C63 S Cabriolet

Price, base: Dh429,090

Engine 4.0-litre twin-turbo V8

Transmission Seven-speed automatic

Power 510hp @ 5,500rpm

Torque 700Nm @ 1,750rpm

Fuel economy, combined 9.2L / 100km

COMPANY%20PROFILE
%3Cp%3E%3Cstrong%3ECompany%20name%3A%3C%2Fstrong%3E%20Alaan%3Cbr%3E%3Cstrong%3EStarted%3A%3C%2Fstrong%3E%202021%3Cbr%3E%3Cstrong%3EBased%3A%3C%2Fstrong%3E%20Dubai%3Cbr%3E%3Cstrong%3EFounders%3A%3C%2Fstrong%3E%20Parthi%20Duraisamy%20and%20Karun%20Kurien%3Cbr%3E%3Cstrong%3ESector%3A%3C%2Fstrong%3E%20FinTech%3Cbr%3E%3Cstrong%3EInvestment%20stage%3A%3C%2Fstrong%3E%20%247%20million%20raised%20in%20total%20%E2%80%94%20%242.5%20million%20in%20a%20seed%20round%20and%20%244.5%20million%20in%20a%20pre-series%20A%20round%3Cbr%3E%3Cbr%3E%3C%2Fp%3E%0A