By Geoffrey Cann
Russian cyber hackers claimed to have penetrated the operations of a Canadian gas pipeline and caused some disruption. Here’s why I’m skeptical.
Recently, a group of Russian hackers claimed to have penetrated the operations of a Canadian gas pipeline and disrupted its business. Visions of the ransomware attack on Colonial Pipelines from 2021 immediately came to mind, and with it some deeply back of mind worries about energy supply disruption, freezing weather and long cold dark nights.
For those of us living some distance from the equator, mostly northerners, but also a few hardy souls in the south, interruptions in energy supply are rare, short lived, weather related, and almost always about electrical power. My friends in Houston, energy capital of the US, tell me that they frequently experience minor power interruptions, which we never hear about, because, frankly, it’s not news.
This spring has been typical—ice storms sweep through and snap spindly power transmission lines, and tornadoes soldier through the US south and scorch their way through quiet neighborhoods, strewing tragedy in their wake. Interruptions are isolated and impact mostly surface infrastructure.
But when oil or gas infrastructure is involved, it’s newsworthy because it is a rare occurrence, the product is hazardous and hard to contain once it’s loose in the wild, and we generally have little direct experience about dealing with a protracted interruption in supply. In my 60 odd years (and lately they’ve been pretty odd), I have no memories at all about coping with fuel supply disruption. And that includes years living abroad, and lots of international travel.
I totally get why hackers might go after pipelines and other midstream assets:
- Pipelines often appear as the single point of failure in an energy system. That’s why those opposed to oil and gas block pipeline approvals.
- Once built, network infrastructure has lots of nodes or end points, creating a greater attack surface where a vulnerability might lurk.
- Many nodes run quietly without real time direct human supervision.
- Pipelines themselves are old, and much of their original computerization predates the internet, suggesting they lack the sophisticated intrusion detection and defenses typical of the most modern equipment.
- By not connecting these old systems to the internet, or air gapping them, pipeline operators may mistakenly feel they have a superior level of security.
- Much of their computer gear is purchased from a small group of global suppliers. Once a vulnerability in that gear is found somewhere in the world, hackers then seek out that gear everywhere.
The war in Ukraine has also unleashed the hidden cyber desk warriors in both Ukraine and Russia against each other. Russia has long used its cyber skills as an arm of its military. Ukraine has stood up a new cyber army comprised of former tech workers, teachers and hobbyists who target Russian oil and gas facilities.
Eventually the tools and techniques developed in this protracted confrontation will make their way to the dark web marketplaces and be used by hackers around the world for criminal purposes. The energy industry should be worried and should prepare for the coming assaults.
But there are a number of reasons why I’m skeptical about this story.
Skeptical Me
I’m not a naturally suspicious person. Most things I simply accept and move on. But I do know more about pipelines than most (having worked on a couple dozen projects for a handful of pipeline outfits), and this report about a successful disruption has raised my eyebrows.
There were no news reports at the time of the supposed attack (late last year) of a serious disruption at a Canadian gas company. The only news item at the time was the failure of a short segment of an oil pipeline in Kansas. If there was a successful attack, it wasn’t sufficiently disruptive to warrant a news release or a regulatory report. Oil spills for example are reportable incidents.
Since infrastructure is regularly taken off line for maintenance, repair, turn arounds, and expansions, interruptions in operations are actually routine and not news. Pipelines are designed for safe shut downs and start ups, and during the shutdown events, energy flows around the disabled parts of the system to keep it all working.
Then again, North American companies are conditioned to keep cyber attacks confidential. There’s little upside and a lot of downside (stock market impacts, irate shareholders, increased attention from cyber actors, competitive actions) to going public with cyber incidents. Most advisors would counsel to say nothing, reveal nothing, until you absolutely have to, and even then, say as little as possible. Only if operations are truly disrupted and for a length of time beyond the normal ebb and flow would it become news.
Hacking Is Harder That It Appears
Many years ago I worked on a project for one of Canada’s largest oil pipeline operators to figure out a new simplified architecture for its computerized operations systems. The problem they were dealing with was a looming shortage of operators. The systems were so complicated that it took years of apprenticeship just to learn the basics, and young people had no interest in jobs of this kind.
One of those operators who left a gas pipeline just before the pandemic to start up a technology company told me that she would break a sweat just moving the mouse at her workstation. She was required to power through hundreds of separate mouse moves and button clicks to safely power down and then power up one of Canada’s big gas pipeline systems. She had to do this quickly, without error, multiple times a day.
It’s easy to picture a pipeline system like a big straw, but these systems are anything but. Typically they are multiple parallel pipelines of varying capacities, which give flexibility to the system, but also enormous complexity. Along the pipelines are feeder systems flowing in, various storage assets, and junctions with other networks. North America has a couple million miles of pipelines at work, with hundreds of compression stations along their lengths. It takes a lot of energy and mechanical work to push molecules, even light ones like natural gas, down a 2000 mile long pipeline that is 4 feet in diameter. Depending on what’s in the pipeline, systems have a handful to dozens of pumping stations.
A truly successful disruption would require months or years of stealthy and painstaking research into these labyrinth systems just to understand how they are connected. Hackers would need to discover where any weaknesses might be, and how to trigger a cascading failure that would be hard to stop once underway. Testing the hacking is tricky because tests might be detected.
We Are Better Prepared
The Colonial Pipeline incident was a North American wide alarm call to the industry that hackers were focused on the industry. Boards wanted immediate updates on what managers were doing to improve the resilience of other pipelines to the threat of attack. It stands to reason that in the past 2 years pipelines have invested extensively in hardening their systems.
Why Canadian Gas?
I can get the strategic link between Canadian gas pipelines and Russian geopolitical interests. Disrupting Canadian gas inconveniences Canadians of course, but there’s still considerable gas flowing south to the US, where shortages might cause some problems for some consumers or perhaps arms manufacturers.
On the other hand, Canada is at best a bit player in the war in Ukraine, and Canada does not supply Europe with gas as there are no east coast LNG facilities.
From an impact and urgency standpoint, it would surely be in Russia’s interests to target US oil and/or gas pipelines as a priority. The US is one of the world’s biggest energy exporters and is already displacing Russian gas in Europe through its LNG exports. US weaponry is making a huge difference in Ukraine’s battlefield successes.
Is This Fake News?
We now all know that Russia is well practiced at disinformation, gaslighting, and spin. For example, Russia claimed that their invasion of Ukraine was provoked by possible NATO expansion. Finland promptly joins NATO as a reaction to Russia’s invasion, putting NATO directly on Russia’s border, and Russia dismisses Finland’s move as unimportant. The argument to de-Nazify Ukraine is equally laughable as the country is headed by a Jewish comic actor.
It’s entirely in character that Russian hackers would publish such claims without evidence. But why wait 90 days? Surely it would have been more impactful to release word of a successful hack just as the victim was struggling to recover.
Even making such a claim is counter productive and not very strategic, as the effect is to alert every other pipeline company to the heightened risk. Hackers like to live in the shadows too.
Conclusions
Apparently this ‘successful’ hack took place in the middle of a Canadian winter and no one noticed. Homes were warm, lights were on, showers were hot. I’m not dismissing the risk, but I’m also not buying the hackers’ bravado just yet.
Check out my latest book, ‘Carbon, Capital, and the Cloud: A Playbook for Digital Oil and Gas’, available on Amazon and other on-line bookshops.
You might also like my first book, Bits, Bytes, and Barrels: The Digital Transformation of Oil and Gas’, also available on Amazon.
Take Digital Oil and Gas, the one-day on-line digital oil and gas awareness course on Udemy.
Take the one-hour Digital for the Front Line Worker in Oil and Gas, on Udemy.
Biz card: Geoffrey Cann on OVOU
Mobile: +1(587)830-6900
email: [email protected]
website: geoffreycann.com
LinkedIn: www.linkedin.com/in/training-digital-oil-gas
Share This:





CDN NEWS |
US NEWS





























