{"id":2893,"date":"2024-04-01T15:24:18","date_gmt":"2024-04-01T20:24:18","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/sellafield-nuclear-waste-site-prosecuted-cybersecurity-failings"},"modified":"2024-04-01T15:24:18","modified_gmt":"2024-04-01T20:24:18","slug":"sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/04\/01\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings\/","title":{"rendered":"Sprawling Sellafield Nuclear Waste Site Prosecuted for Cybersecurity Failings"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt90ded59253cae632\/659c515b2577610407f52c25\/nuclear_plant_mohammad_aaref_barahouei_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sellafield Ltd, the managing company of the Sellafield nuclear site, will be prosecuted by the UK&#8217;s independent nuclear safety regulator for alleged cybersecurity offenses.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to the safety regulator, the infractions were garnered over a four-year period from 2019 to 2023. However, the regulator noted in its announcement that there is nothing to suggest that public safety has been compromised over these &#8220;information technology security offenses.&#8221; The <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.onr.org.uk\/news\/all-news\/2024\/03\/onr-notifies-sellafield-ltd-of-intention-to-prosecute\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Office for Nuclear Regulation (ONR) provided little comment<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> regarding what the specific issues are, or the legal proceedings, but noted that &#8220;details of the first court hearing will be announced when available.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This is not the first time the company has been under scrutiny. Its cybersecurity issues were also addressed in the Chief Nuclear Inspector&#8217;s annual report on the country&#8217;s nuclear industry, released last September.&nbsp;And in December, the Guardian released a bombshell report that advanced persistent threats (APTs) backed by Russia and China have been <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.theguardian.com\/business\/2023\/dec\/04\/sellafield-nuclear-site-hacked-groups-russia-china\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">breaching the Sellafield&#8217;s IT systems<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as far back as 2015 \u2014 attacks that the paper alleged have been consistently covered up by senior staff at the site, which holds a vast store of radioactive waste and the world&#8217;s largest store of plutonium.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though it&#8217;s not currently known whether any senior managers were involved in these security failings and, if so, whether they&#8217;ll face charges, if convicted, an individual can face a maximum of two years in prison.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A nuclear reactor is located on the Sellafield grounds. Even though it was closed in 2003, it is still <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/therecord.media\/sellafield-site-prosecution-nuclear-facility-cybersecurity?&amp;web_view=true\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Europe&#8217;s largest nuclear site,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and the ONR considers it to be &#8220;one of the most complex and hazardous nuclear sites in the world.&#8221; That&#8217;s likely a big part of the reason why the company&#8217;s cybersecurity failings are of notable concern.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Though cyberattacks on power plants aren&#8217;t necessarily common, they have occurred on rare occasions, such as the 2017 spate of attacks using <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/triton-malware-still-targeting-energy-firms\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Triton malware<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, also known as Trisis and HatMan, that was used to target a Middle East petrochemical facility at the hands of the Russian Central Scientific Research Institute of Chemistry and Mechanics (TsNIIkhM). The threat actor moved through IT and operational technology (OT) networks to gain entry to the safety system and targeted the Schneider Electric Triconex safety instrumented system, which allows initiation of a safe shutdown process in case of emergencies. With the system modified by malware, it could have led to damages to the facility, operational shutdown, and even fatalities.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That said, what kind of damage a cyberattack would cause Sellafield and whether it could have a similar catastrophic fallout is unknown, since the nuclear reactor is no longer operational.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/sellafield-nuclear-waste-site-prosecuted-cybersecurity-failings\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sellafield Ltd, the managing company of the Sellafield nuclear site,<\/p>\n","protected":false},"author":12,"featured_media":2894,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2893","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings-scaled.jpg?fit=2560%2C1703&ssl=1",2560,1703,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings-scaled.jpg?fit=300%2C200&ssl=1",300,200,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings-scaled.jpg?fit=640%2C426&ssl=1",640,426,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings-scaled.jpg?fit=640%2C426&ssl=1",640,426,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings-scaled.jpg?fit=1536%2C1022&ssl=1",1536,1022,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings-scaled.jpg?fit=2048%2C1363&ssl=1",2048,1363,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings-scaled.jpg?fit=1024%2C681&ssl=1",1024,681,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/04\/sprawling-sellafield-nuclear-waste-site-prosecuted-for-cybersecurity-failings-scaled.jpg?fit=2560%2C1703&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2893","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2893"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2893\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2894"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2893"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2893"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2893"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}