Cyberattack on Pool in Israel a Wake-Up Call For Pool Pros

The recent cyberattack on a hotel pool controller in Israel highlights the potential risks and vulnerabilities that the pool industry faces in terms of hackers affecting Operational Technology (OT) security. As the use of technology in pool systems continues to increase, it is important for pool companies and professionals to understand the potential dangers and take steps to protect themselves and their clients.

Hackers Shine Spotlight on Lack of Security

The hacktivist group GhostSec claimed it breached the hotel’s pool water system and could control the pH and chlorine levels in the pools. The attackers did not disclose the details of the OT breach, but researchers at Otorio, a cybersecurity company specializing in OT security, investigated the incident and found two Aegis II controllers that were exposed.

The Aegis II controller is a device used to monitor and control the chemical concentration in water in locations such as swimming pools, spas, and water parks. The controllers can communicate with other systems, such as pumps, heaters, and sensors, to maintain water quality.

AEGIS II Controller

In this case, the AEGIS II here was responsible for continuously measuring and controlling the conductivity and biocide concentration to keep pipework and heat exchangers clean.

The AEGIS II Controller’s applications included:

  • Control of bleeding in evaporation cooling systems
  • Control of corrosion inhibitors, de-foamers and dispersants
  • Measuring and control of inhibitor concentration
  • Measuring and control of pH and ORP voltage
  • Metering of biocides

According to Otorio’s report, the hackers could have potentially affected the pH levels of the hotel’s pools, but there is no evidence that any harm was done to the guests or the facility. However, the incident raises concerns about the growing threat of OT cyberattacks and their impact on critical infrastructure and public safety.

Targeting Pool Automation Devices With Weak Security

One of the key concerns in the pool industry is the use of programmable logic controllers (PLCs) and other ICS devices that are used to monitor and control the various aspects of pool systems, such as chemical levels, temperature, pumps, and lighting. These devices can be vulnerable to cyberattacks if they are not properly secured, especially if they are connected to the Internet or other networks.

OT cyberattacks are not new, but they are becoming more frequent, sophisticated, and disruptive. Unlike hackers that focus on stealing data or disrupting services, OT attacks can have physical consequences, such as equipment damage, production loss, environmental damage, or human harm.

Finding Out Exactly How It Happened

In the case of this particular pool controller breach, the attackers were able to access the Aegis II controllers with default passwords, which is a common weakness that can be easily exploited. Once the attackers gained access to the controllers, they could potentially manipulate the chemical levels in the pools, which could cause harm to the swimmers or damage to the equipment.

At the discovery of this breach, OTORIO promptly informed Israel’s Cyber Emergency Response Team (CERT) of the incident and worked closely with the authorities to resolve the issue as quickly as possible. As of now, the affected controller is no longer accessible to the public.

This incident highlights the importance for pool professionals to take a proactive approach to OT security by implementing best practices and security controls, such as:

  • Changing default passwords and using strong and unique passwords for each device and user
  • Updating firmware and software patches regularly to fix known vulnerabilities
  • Segmenting the network and restricting access to critical devices and systems
  • Encrypting data in transit and at rest to prevent unauthorized access
  • Monitoring the system for suspicious activities and anomalies that could indicate a cyberattack
  • Having a comprehensive incident response plan in place to minimize the impact of a cyberattack and restore normal operations as quickly as possible.

Installers who are performing upgrades or new installations of equipment should also stay informed about the latest trends and threats in OT security and seek guidance from cybersecurity experts or specialized vendors if needed. By taking a proactive and collaborative approach to OT security, pool professionals can help mitigate the risk of hackers gaining access to equipment and ensure the safety and satisfaction of their clients.

Rate this post

The post Cyberattack on Pool in Israel a Wake-Up Call For Pool Pros appeared first on PoolMagazine.com – Get The Latest Pool News.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep Reading

Related Article

Confer Plastics Plans 30,000-Square-Foot Warehouse Expansion

Confer Plastics, one of the most established manufacturers serving the pool and spa industry, is moving forward with a 30,000-square-foot warehouse expansion at its Wheatfield, N.Y., facility. The project, now […]
The post Confer Plastics Plans 30,000-Square-Foot Warehouse Expansion appeared first on PoolMagazine.com – Get The Latest Pool News.

Meet the 702 Pros Family—Balancing Home and Business

  • Grow your brand with digital by 702 Pros
  • Listen to samples of the latest podcasts Tappods
  • Connect & manage B2B businesses with HoneyHat
  • Manage customers & projects with Pulsenest
  • Create online promotions in minutes with OnSago
  • Invest for equity in pre-market startups with Sparkmeta
  • Show what Matters to You with Mattersly
  • Find things to do in your city ThingsTDN
  • Hire contractors to build your dream pool with Pool Launch
  • Create & manage your brand links with Linkpeas
  • Locate & schedule local service providers with Provingo
  • Book workers for gigs in seconds with Workergram
  • Show your skills & build your portfolio with Scoutshift
© 2022 Splash Weekly is a pool news and idea platform. Further information is available upon request. All information covered within this website is proprietary and not meant for duplication in any way. Further information is available upon request. Splash Weekly is a 702 Pros Company. Visit our website sitemap for more information about content structing. The information on this website is general, and shouldn't be used to base any decisions on your life or work. Splash Weekly™ makes no representations or warranties as to accuracy, appropriateness, completeness, methods of working, results of operations or anything else. You use the site entirely at your own risk. Some links might lead you to content that is not accurate for the purpose(s) of which we linked. We cannot be responsible for any content you find in those pages. Web Design by Go Pool Pros.