Romanian water authority hit by ransomware attack over weekend
嗯,用户让我用中文总结一篇文章,控制在100字以内,而且不需要用“文章内容总结”之类的开头。我得先仔细看看这篇文章讲的是什么。 文章主要讲的是罗马尼亚的水务管理机构Romanian Waters遭受了勒索软件攻击。攻击影响了大约1000个计算机系统和10个地区办公室。虽然服务器和一些系统被影响,但控制水务基础设施的操作技术没有受到波及。调查人员发现攻击者使用了Windows的BitLocker功能来加密文件,并留下了赎金说明。 此外,罗马尼亚的网络安全机构提到,虽然该国的关键IT基础设施保护系统在攻击前没有保护水务机构,但现在正在努力将其纳入保护系统中。目前还没有确定攻击的来源,也没有任何组织或国家声称对此负责。 用户的需求是总结内容,所以我要抓住关键点:谁被攻击了,影响范围,哪些系统受影响,哪些没受影响,攻击手段,以及后续措施和调查情况。 现在我要把这些信息浓缩到100字以内。确保涵盖主要事件、影响范围、技术细节和后续行动。同时避免使用复杂的术语,让总结简洁明了。 可能的结构是:罗马尼亚水务机构遭遇勒索软件攻击,影响千余系统和多个办公室;服务器等受影响但关键基础设施未受损;攻击者使用BitLocker加密并索要赎金;调查中尚未归因于特定组织或国家。 这样应该可以控制在100字左右,并且符合用户的要求。 </think> 罗马尼亚水务管理机构遭勒索软件攻击,约1000个计算机系统及10个地区办公室受影响。服务器、数据库等受损,但关键水务基础设施运行正常。调查发现攻击者利用Windows BitLocker加密文件并索要赎金。目前尚未确定攻击来源及责任归属。 2025-12-22 15:30:18 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

Water plant hacker

Romanian Waters (Administrația Națională Apele Române), the country's water management authority, was hit by a ransomware attack over the weekend.

Officials with the National Cyber Security Directorate (DNSC) said Sunday that the incident impacted approximately 1,000 computer systems at the national water authority and 10 of its 11 regional offices.

While the breach affected servers running geographic information systems, databases, email, and web services, as well as Windows workstations and domain name servers, operations and operational technology (OT) systems controlling water infrastructure are unaffected.

Wiz

Investigators from multiple Romanian security agencies, including the Romanian Intelligence Service's National Cyberint Center, who are now investigating the incident and working to contain its impact, have found that the attackers used the built-in Windows BitLocker security feature to lock files on compromised systems, then left a ransom note demanding that they be contacted within 7 days.

"The National Administration of Romanian Waters specifies that the operation of hydrotechnical assets is carried out only through dispatch centers using voice communications. Hydrotechnical constructions are safe and are operated locally by service personnel and coordinated by dispatch centers," the DNSC said in a Sunday advisory.

The Romanian cybersecurity agency stated that while the country's national cybersecurity system for critical IT infrastructure did not protect the water management authority's infrastructure before the attack, authorities are now working to integrate it into protective systems operated by the National Cyberint Center.

Investigation ongoing, no attribution

In an update on Sunday, officials said the attack vector has not yet been identified and that the national water authority's operations remain unaffected by the incident.

"Dispatching and operation of hydrotechnical structures are carried out within normal parameters, using telephone and radio communications. Hydrotechnical structures are safe and are operated locally by service personnel, coordinated by dispatchers. Forecasting and flood protection activities have not been affected," the DNSC added in a Monday update.

While no ransomware operation or state-backed threat group has claimed responsibility to date, and the Romanian Waters agency has yet to attribute the attack, the incident follows Danish intelligence officials' blaming Russia for orchestrating a destructive water-utility cyberattack in 2024.

In early December, together with the FBI, NSA, European Cybercrime Centre (EC3), and various other cybersecurity and law enforcement agencies worldwide, CISA warned that pro-Russia hacktivist groups, including Z-Pentest, Sector16, NoName, and CARR (Cyber Army of Russia Reborn), are targeting critical infrastructure organizations worldwide.

This is the latest major ransomware attack that has hit Romania in recent years. Electrica Group (a major Romanian electricity supplier and distributor) was also breached by the Lynx ransomware gang one year ago, while over 100 hospitals across Romania were forced to take their systems offline after a February 2024 Backmydata ransomware attack disrupted their healthcare management systems.

tines

Break down IAM silos like Bitpanda, KnowBe4, and PathAI

Broken IAM isn't just an IT problem - the impact ripples across your whole business.

This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.


文章来源: https://www.bleepingcomputer.com/news/security/romanian-water-authority-hit-by-ransomware-attack-over-weekend/
如有侵权请联系:admin#unsafe.sh