2021 Iranian fuel cyberattack explained
The Iranian fuel 2021 cyberstrike was an attack on the Iranian fuel system, government-issued cards used for buying subsidized fuel, and digital road billboards. The attack took place on 26 October 2021. The government announced that people had to buy gas without their ration card. According to the Supreme Council of Cyberspace, the attacks were similar to the attack on the Iranian rail road transit system in July.[1] [2] Iranian President Ebrahim Raisi stated, "this cyberattack is neither the first time nor will it be the last."[3]
Network infrastructure is a semi-isolated system not connected to the Internet but instead uses the National Internet (National Information Network).[4]
Gholamreza Jalali, the head of Iranian civil defense, accused the United States and Israel of being behind the attack in an interview with state TV.[5]
Scale and Details
Iran's 4300 gas stations were unable to process payments. Initially, the Ministry of Petroleum blamed a technical error, though it was later revealed to be a cyberattack.[6] Users trying to purchase fuel at affected gas stations received a display reading "cyberattack 64411" which is associated with a hotline to the Ayatollah's office which responds to questions about Islamic law, though a possible connection was not commented on by official Iranian agencies.[7] Cybersecurity industry firms noted the similarity to a 2020 rail attack in which a similar message was displayed, prompting speculation of a possible connection between the two attacks. The previous attack was attributed by security researchers at Check Point to the hacking group INDRA, which claims to be an anti-government partisan resistance group.[8] [9]
Digital billboards in Iranian cities were seen displaying messages such as "Khameini! Where is our fuel?" as news about the attack spread.[10] A group called Predatory Sparrow claimed credit for the attack along with a previous cyberattacks against Iranian rail assets earlier in 2021, although Iranian officials simply attributed it to an unnamed state actor.[11]
See also
Sources
- News: Associated Press. 2021-10-27. A cyberattack paralyzed every gas station in Iran. en. NPR. 2021-10-28. 2021-10-28. https://web.archive.org/web/20211028070027/https://www.npr.org/2021/10/27/1049566231/irans-president-says-cyberattack-was-meant-to-create-disorder-at-gas-pumps. live.
- Web site: 2021-10-26. حمله سایبری به جایگاههای سوخت سراسر ایران؛ پیام "خامنهای بنزین ما کو؟" بر بیلبوردها. 2021-10-28. العربیه فارسی. fa. 2021-10-26. https://web.archive.org/web/20211026125751/https://farsi.alarabiya.net/iran/2021/10/26/%D8%AD%D9%85%D9%84%D9%87-%D8%B3%D8%A7%DB%8C%D8%A8%D8%B1%DB%8C-%D8%A8%D9%87-%D8%AC%D8%A7%DB%8C%DA%AF%D8%A7%D9%87-%D9%87%D8%A7%DB%8C-%D9%87%D9%88%D8%B4%D9%85%D9%86%D8%AF-%D8%B3%D9%88%D8%AE%D8%AA-%D8%AF%D8%B1-%D8%B4%D9%87%D8%B1-%D9%87%D8%A7%DB%8C-%D9%85%D8%AE%D8%AA%D9%84%D9%81-%D8%A7%DB%8C%D8%B1%D8%A7%D9%86. live.
- Web site: Iran president says cyberattack not the first, won't be last - Al-Monitor: The Pulse of the Middle East. 2021-10-28. www.al-monitor.com. en. 2021-10-28. https://web.archive.org/web/20211028070007/https://piwik.al-monitor.com/matomo.php?action_name=Iran%20president%20says%20cyberattack%20not%20the%20first%2C%20won%E2%80%99t%20be%20last%20-%20Al-Monitor%3A%20The%20Pulse%20of%20the%20Middle%20East&idsite=1&rec=1&r=329619&h=7&m=0&s=7&url=https%3A%2F%2Fwww.al-monitor.com%2Foriginals%2F2021%2F10%2Firan-president-says-cyberattack-not-first-wont-be-last&_id=2e5c0717f37d1314&_idn=1&_refts=0&send_image=0&pdf=1&qt=0&realp=0&wma=0&fla=0&java=0&ag=0&cookie=1&res=1600x1000&pv_id=reJawD&pf_net=136&pf_srv=78&pf_tfr=28&pf_dm1=820. live.
- Web site: پور. مصطفـی معـصوم. 2021-10-26. سامانه هوشمند سوخت به اینترنت وصل نیست؛ آیا خرابکاری منشا داخلی دارد؟. 2021-10-28. گجت نیوز. fa-IR. 2021-10-27. https://web.archive.org/web/20211027091812/https://gadgetnews.net/552583/fuel-system-is-not-connected-to-the-internet/. live.
- Web site: Iran says Israel, U.S. likely behind cyberattack on gas stations . https://web.archive.org/web/20220314005421/https://www.reuters.com/business/energy/iran-says-israel-us-likely-behind-cyberattack-gas-stations-2021-10-30/ . 2022-03-14 . 2022-03-14 . live . Reuters . 2021-10-30.
- Web site: Suspected cyberattack temporarily disrupts gas stations across Iran . Catalin Cimpanu . The Record by Recorded Future . https://web.archive.org/web/20220120130837/https://therecord.media/suspected-cyberattack-temporarily-disrupts-gas-stations-across-iran/ . 2022-01-20 . live . 2022-03-12 . 2021-10-26.
- Web site: Iran says cyberattack closes gas stations across country . Associated Press . https://web.archive.org/web/20220203182532/https://apnews.com/article/business-middle-east-iran-dubai-united-arab-emirates-0342c10733bc89379e00d99152fe7a1f . live . 2022-02-03 . 2022-03-14 . Jon Gambrell.
- Web site: Iranian state media blames hack for apparent fuel shortage, the latest incident to draw attention . Cyberscoop . Jeff Stone . 2021-10-26 . https://web.archive.org/web/20211027220719/https://www.cyberscoop.com/iran-gas-hack-fuel-breach/ . live . 2021-10-27 . 2022-03-14.
- Web site: Cyberattack Cripples Iranian Fuel Distribution Network . https://web.archive.org/web/20220214090355/https://threatpost.com/cyberattack-cripples-iranian-fuel-distribution-network/175794/ . live . 2022-03-14 . 2022-02-14 . 2021-10-27 . Elizabeth Montalbano . Threat Post.
- Web site: Iranian gas stations out of service after distribution network hacked . Bleeping Computer . Ionut Ilascu . live . https://web.archive.org/web/20211103184013/https://www.bleepingcomputer.com/news/security/iranian-gas-stations-out-of-service-after-distribution-network-hacked/ . 2021-11-03 . 2022-03-15 . 2021-10-26.
- Web site: Iran blames foreign country for cyberattack on petrol stations . BBC . 2021-10-27 . https://web.archive.org/web/20211103164348/https://www.bbc.com/news/world-middle-east-59062907 . 2021-11-03 . 2022-03-15 . live.