Site navigation

Smart Cities At Risk From Cybercriminals Says IBM Security Researcher

Theo Priestley

,

Smart Cities funding Scotland

From detecting and attempting to mitigate traffic congestion to disaster detection and response to remote control of industry and public utilities Smart Cities are suddenly in the spotlight as a potential target for cybercrime.

Once the realm of fiction and movies such as Die Hard 4.0, smart cities are now the growing target for sophisticated cybercriminals as the infrastructure contain numerous vulnerabilities that could allow hackers to cause panic among citizens by manipulating city services and utilities.

According to research conducted by IBM division X-Force Red, around 17 vulnerabilities have been discovered in various smart city systems across the UK, US and Europe, eight of which have been deemed as “critical”.

New Technologies, Old School Threats

The IBM research team said in a recent blog post that they were prepared to dig deep to expose vulnerabilities, however initial testing yielded some of the most common and basic security issues, such as default passwords, authentication bypass and SQL injections, highlighting that smart cities are already exposed to old-school threats that should not be part of any smart environment.

“We found a European country using vulnerable devices for radiation detection and a major US city using them for traffic monitoring.” said Daniel Crowley, research director at IBM.

“After we found the vulnerabilities and developed exploits to test their viability in an attack scenario, our team found dozens (and, in some cases, hundreds) of each vendor’s devices exposed to remote access on the internet. All we did was use common search engines like Shodan or Censys, which are accessible to anyone using a computer.”

Panic Attacks On A City-Wide Scale

According to Crowley, a cybercriminal could unleash a city-wide panic attack using any of these vulnerable systems and exploits. Attacks could take the form of;

  • Flood warnings – Attackers could manipulate water level sensor responses to report flooding in an area where there is none — creating panic, evacuations and destabilisation.
  • Radiation alarms – Similar to the flood scenario, attackers could trigger a radiation leak warning in the area surrounding a nuclear power plant without any actual imminent danger.
  • General chaos – Pick your favourite crime action movie from the last few years, and there’s a good chance that some hacker magically controls traffic signals and reroutes vehicles. If one could control a few square blocks worth of remote traffic sensors, they could create a similar gridlock effect as seen in the movies.

The blog post highlights a number of smart city hardware and software vendors, along with a long list of vulnerabilities exposed during the research.

“Security around these sensors and controls must be a lot more stringent to prevent scenarios like the few we described.” Crowley added.

Theo Priestley

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data