Threat Monitor Annual Report 2023

Man indicted after acting as malicious insider against water treatment facility

July saw the indictment Rambler Gallo, a former employee of a Massachusetts based company operating at the Discovery Bay Water Treatment Facility in California, after his alleged attack on the facility in January 2021. Gallo, the former Instrumentation and Control Tech at the facility, is alleged to have installed software on his own private computer as well on the private internal network of his employer, and, upon resignation from the company in January 2021, exploiting his remote access to uninstall software which was the main hub of the network and which was responsible for protecting the entire water treatment system including filtration, chemical levels, and water pressure. He faces up to 10 years behind bars and up to $240k for the charge of transmitting a program, information, code, and command to cause damage to a protected computer, in violation of 18 U.S.C. §§ 1030(a)(5)(A) and (c)(4)(B)(i). This Discovery Bay facility attack, as well as the similar attack on the water system of Oldsmar in early 2021, likely contributed to the March 2023 decision of the Biden administration to make the conducting of cyber security audits on public water systems mandatory.

19

Made with FlippingBook - PDF hosting