IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Cyber attackers strike flood monitoring system in Goa, India

Ransomware attack has prevented the ability to back up data, with attackers demanding Bitcoin in return for decryption

Cyber attackers have targeted a flood monitoring system with ransomware in Goa, India, demanding Bitcoin in return for decrypting the data.

The Water Resource Department (WRD) runs a flood monitoring system at 15 locations on Goa’s major rivers, designed to monitor water levels as part of its disaster management planning.

However, WRD executive engineer Sunil Karmarkar said the system was struck by a ransomware attack on June 21, taking place between 12am and 2am.

As a result, integrity of the system’s data was altered, preventing the ability to back up the previous data. According to Karmarkar, the server runs on a 24-7 internet line and an absence of antivirus protection and use of outdated firewalls helped facilitate the ransomware attack.

“The server has been under cyberattack of ransomware,” Karmarkar said in a report to authorities. “Under the attack, all the files are encrypted with eking extension and cannot be accessed.

“In a popup and stored file, the attackers are demanding Bitcoin cryptocurrency for the decryption of the data.”

In the aftermath, the flood monitoring system’s data could not be accessed or downloaded from the server, including data related to battery voltages of different stations.

Additionally, data packets regarding 12 of the flood system’s stations could not be transferred to the WIMS server, text messages and emails were unable to be obtained, and old data could not be backed up, Karmarkar added.

Police said they have asked representatives of Hyderabad-based software developer ASTRA Microwave Products being asked to help track down the culprits and better protect the flood monitoring system.

“This work has been awarded to ASTRA Microwave Products Ltd, Hyderabad,” Karmarkar revealed. “The company has been directed to block further damage and upgrade the system and recover the data at their own risk and cost.”

The attack is the latest example of cyber criminals that will attack any organisation and system with ransomware, regardless of its effect on people and society. While some groups such as Lockbit will veer away from targeting organizations such as hospitals and utilities, others – such as the notorious Conti ransomware attackers – are indiscriminate and will not take morals into consideration.

In the wake of the attack, prominent cybersecurity expert Kevin Beaumont took to social media to condemn the cyber criminals for targeting a critical safety system. He said on Twitter: “Whichever ransomware group did this should provide a free decryption key.”

Featured Resources

The state of Salesforce: Future of business

Three articles that look forward into the changing state of Salesforce and the future of business

Free Download

The mighty struggle to migrate SAP to the cloud may be over

A simplified and unified approach to delivering Enterprise Transformation in the cloud

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

The Total Economic Impact™ Of IBM FlashSystem

Cost savings and business benefits enabled by FlashSystem

Free Download

Recommended

Darktrace partners with HackerOne to bring AI to attack resistance
cyber security

Darktrace partners with HackerOne to bring AI to attack resistance

11 Aug 2022
Waterstones suffers stock nightmare after botched IT upgrade
digital transformation

Waterstones suffers stock nightmare after botched IT upgrade

10 Aug 2022
Barclays strikes deal with Microsoft to migrate staff to Teams
collaboration

Barclays strikes deal with Microsoft to migrate staff to Teams

10 Aug 2022
Logicalis snaps up UK-based IT consultancy Q Associates
mergers and acquisitions

Logicalis snaps up UK-based IT consultancy Q Associates

9 Aug 2022

Most Popular

Cyber attack on software supplier causes "major outage" across the NHS
cyber attacks

Cyber attack on software supplier causes "major outage" across the NHS

8 Aug 2022
Why convenience is the biggest threat to your security
Sponsored

Why convenience is the biggest threat to your security

8 Aug 2022
Electrical explosion reported at Google's Iowa data centre
data centres

Electrical explosion reported at Google's Iowa data centre

9 Aug 2022