Russia covertly mapping key energy infrastructure for sabotage, Dutch report warns

AIVD HollandTHE RUSSIAN INTELLIGENCE SERVICES are “covertly mapping” the energy infrastructure of the North Sea, in preparation for acts of disruption and sabotage, according to a new report form the Dutch government. The 32-page report was published this week, ahead of the one-year anniversary of the 2022 Russian invasion of Ukraine. It was authored collaboratively by the two main intelligence agencies of the Netherlands, the General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD).

The report notes that Russian spy ships, drones, satellites and human agents are engaged in an unprecedented effort to chart the energy and other “vital marine infrastructure” of the North Sea. The purpose of this effort is to understand how the energy and other key infrastructure works in the North Sea. The term North Sea refers to the maritime region that lies between France, Belgium, the Netherlands, Germany, Denmark, Norway and the United Kingdom. It hosts key energy infrastructure, including oil, natural gas, wind and wave power installations, which supply energy to much of northern Europe.

According to the report, Russian intelligence and espionage activities in the North Sea “indicate preparatory acts of disruption and sabotage. These appear to be aimed at energy systems, but also other vital infrastructure, such as undersea power and communication cables, and even drinking water facilities. Consequently, physical threats toward any and all of these facilities should be viewed as conceivable, the report warns.

On Saturday, the Dutch government said it would expel an undisclosed number (believed to be at least ten) of Russian diplomats. It also accused Moscow of engaging in constant efforts to staff its diplomat facilities in the Netherlands with undercover intelligence officers. On the same day, the Dutch government said it would shut down its consulate in Russia’s second-largest city, St. Petersburg, and ordered Russia to shut down its trade mission in the port city of Amsterdam.

Author: Joseph Fitsanakis | Date: 21 February 2023 | Permalink

US government report details first-ever drone attack on energy grid

Electrical substation

A REPORT ISSUED BY the United States government last month provides details of what is thought to be the first known attack on the country’s energy infrastructure by an unmanned aircraft system. The report appears in a Joint Intelligence Bulletin (JIB) dated October 28, 2021. The JIB is a collaborative intelligence product of the Department of Homeland Security, the Federal Bureau of Investigation and the National Counterterrorism Center.

The report documents an apparent drone attack that took place on July 16, 2020. The target of the attack was an electrical substation in the state of Pennsylvania. The document does not provide details about the geographic location of the attack, nor does it identify the substation that was targeted. It does, however, give details about the type of commercial drone that was used, which it identifies as a Chinese-built DJI Mavic 2. The DJI Mavic 2 is a compact quadcopter drone, which is popular among aerial photography enthusiasts in the United States. It costs between $1,300 and $4,450, depending on its design and amount of features.

The specific device used in the attack in Pennsylvania had been modified by its operator, most likely in order to cause a short circuit and damage the distribution lines or transformers it came in contact with. The device had a thick copper wire hanging from its body, which was attached with nylon cords. Additionally, the perpetrator of the attack had taken steps to anonymize the device, be removing its quality control markings and other identifying information from it. The camera and internal memory card, which are standard technical features of DJI Mavic 2 drones, had also been removed, according to the report. As a result, the operator of the device has not been identified.

The report concludes that illicit [drone] activity is expected “to increase over energy sector and other critical infrastructure facilities as use of these systems in the United States continues to expand”.

Author: Joseph Fitsanakis | Date: 05 November 2021 | Permalink

Croatia to extradite whistleblower who alleged Dutch oil firm spent millions in bribes

Monaco

A WHISTLEBLOWER WHO CLAIMS that a major Dutch oil firm paid millions in bribes to officials in return for lucrative contracts, is to be extradited to Monaco, following his arrest in Croatia last summer. Jonathan Taylor, of Southampton, United Kingdom, was a lawyer working for SBM Offshore, a Netherlands-based group of companies that provide services to the global offshore oil and gas industry. In 2012, he leaked documents allegedly showing that SBM Offshore “paid €185 million [$217 million] in bribes in several countries between 2005 and 2011”, in return for being awarded service contracts.

But SBM Offshore accused him of extortion and claimed that he stole proprietary documents and then tried to blackmail his employer, asking for $3 million in exchange for staying silent about the alleged bribes. Following this accusation, authorities in Monaco, which hosts an SBM Offshore regional facility, issued an Interpol “red notice” for Taylor’s detention. A red notice is essentially a request to law enforcement worldwide to locate and provisionally detain a person of interest, pending a possible extradition.

In July of this year, Taylor was arrested in Dubrovnik, Croatia, where he was holidaying with his family, by local police acting on the Interpol’s red notice. Immediately following his arrest, the government of Monaco sought to have him extradited there “for questioning”, even though he had not been charged with a crime. According to Monegasque police, Taylor was wanted “for questioning to determine whether or he should be charged” with a crime.

Taylor and his lawyers deny the claims against him, which they describe as acts of retaliation for him having blown the whistle on SBM Offshore. Now, however, authorities in Monaco have summoned Taylor to appear before a magistrate, after the Supreme Court of Croatia upheld an extradition ruling that was issued by a lower court earlier this year. This means that Croatian authorities should soon be extraditing Taylor to Monaco, as per the principality’s request. However, Taylor currently remains in Croatia and he and his supporters have urged the Croatian authorities to not comply with Monaco’s extradition request.

Author: Joseph Fitsanakis | Date: 21 September 2021 | Permalink

Israel behind mysterious attacks on Iranian oil tankers, report claims

Iran oil tanker

THE ISRAELI INTELLIGENCE SERVICES are behind a series of mysterious attacks that have damaged Iranian oil tankers in the past 24 months, according to a new report that cites sources in the international shipping industry. The report, which appeared last week in The Wall Street Journal, cites a number of “shipping professionals” and “regional officials”, but does not name them.

The paper claims that the Israeli government decided to target the Iranian oil tankers after it concluded that Tehran uses the proceeds from oil sales to fund groups like Hezbollah in Lebanon and the Houthi rebels in Yemen. Most of the damaged ships were attempting to deliver oil to Syria in violation of a host of international sanctions against Iran, which are led by the United States. Washington appears to be quietly supporting the Israeli attacks on Iranian ships, according to The Wall Street Journal.

The article cites an anonymous shipping industry professionals as claiming that at least three Iranian oil tankers sustained serious damage following Israeli attacks in 2019, while at least six more Iranian ships were struck by Israel in 2020. All nine ships were transporting oil. There is no information about alleged attacks on Iranian oil tankers in 2021, with the exception of one Iranian vessel that was targeted by a group of divers who allegedly planted a limpet mine on its keel in February of this year.

None of the Iranian ships that were allegedly attacked by Israel sunk as a result, said The Wall Street Journal. However, all sustained significant damage and were forced to return to Iranian ports. As a result, Iran’s ability to deliver oil to Syria has been severely disrupted in the past two years, said the paper.

Author: Joseph Fitsanakis | Date: 15 March 2021 | Permalink

Emirates authorities confirm four ships targeted by ‘sabotage operations’

Fujairah UAE EmiratesAuthorities in the United Arab Emirates said on Sunday that four commercial ships were targeted by “sabotage operations”, but did not point to possible culprits. The announcement came hours after false reports circulated in Iranian and Lebanese media stating that explosions had been witnessed at the port of Fujairah, a major Emirati commercial shipping facility that borders the Sultanate of Oman and is visible from the coast of Iran. The alleged explosions were first reported by Al-Mayadeen, a Shiite-Lebanese satellite television station, and were then picked up by a host of Iranian news outlets.

The reports caused alarm in international energy market circles, as observers feared that the explosions may have resulted from deliberate attacks by Iranian forces. Located less than 100 miles from the Strait of Hormuz, through which over 30 percent of the world’s sea-transported oil is trafficked, the Port of Fujairah is the world’s second largest shipping fueling hub. Even a partial destruction of the port would cause major disruptions in the international energy transportation system. Several hours later, however, the Associated Press dismissed the reports as false, saying it had spoken to “Emirati officials and local witnesses” and had found the earlier reports of explosions at Fujairah to be “unsubstantiated”.

Later on Sunday, state-owned Emirates News Agency published a statement by the Ministry of Foreign Affairs, which said that four ships had indeed “suffered acts of sabotage” while sailing off the Emirati coast. The Foreign Ministry’s statement said that the ships were “civilian trading vessels of various nationalities” and that they had been “subjected to […] acts of sabotage”. It added that “subjecting commercial vessels to sabotage operations and threatening the lives of their crew is considered a dangerous development”. However, Emirati officials refused to elaborate on the nature of the sabotage that the ships allegedly suffered, or discuss the possible culprit or culprits of the alleged attacks. On Friday, the United States Maritime Administration (MARAD) warned that Iranian military forces could target “US commercial ships, including oil tankers”. There was also an “increased possibility” of “Iran or its regional proxies taking action against US and partner interests”, said MARAD.

Author: Joseph Fitsanakis | Date: 13 May 2019 | Permalink

US to shut down its embassy in Venezuela as national blackout enters 6th day

US embassy in Caracas VenezuelaThe United States said on Tuesday that it will evacuate its last few diplomats from its embassy in Caracas, as the electricity blackout in Venezuela enters its sixth day, making it the longest energy crisis in the nation’s history. Energy shortages are not new in Venezuela. The oil-rich Latin American country of 31 million people suffered two disastrous nationwide blackouts in 2009 and a third one in 2016. But the current blackout is quickly approaching the one-week mark and is believed to have caused a minimum of 20 deaths, mostly in hospitals around the country. The majority of the population currently lacks access to fuel and banking services, while there are disruptions in critical food and water supply lines. Several instances of mass looting have been reported across the nation since Monday.

The precise cause of the blackout remains unknown, though a number of experts point to a massive outage of the Simón Bolívar Hydroelectric Plant, located in northeastern Venezuela’s Necuima Canyon, as the root of the problem. Known also as the Guri dam, the facility generates more than four fifths of Venezuela’s electricity output, and may be responsible for the nationwide blackout. The continuing crisis has exacerbated the already adversarial relationship between Washington and Caracas, as the Venezuelan government blames the US and the local opposition leader Juan Guaidó for the blackout. The government said on Monday that it would investigate Guaidó in connection with rumors of sabotage of the Guri dam facility. The announcement prompted the White House to warn that “a lot of countries would react very quickly” if Guaidó was incarcerated. On Tuesday, Washington said that the remaining 20 members of staff of its embassy in the Venezuelan capital would be evacuated by Friday. Soon afterwards, the Venezuelan government said that it had ordered the American diplomats to leave the country, so that their presence there would not be used as a pretext by Washington to launch a military invasion of the country.

Meanwhile, the blackout continued as of Tuesday night, with experts warning that the aging infrastructure of Venezuela’s energy network, coupled with the lack of specialists on the ground, made it difficult to overcome the crisis. The US-based Wired magazine explained on Tuesday that restoring the integrity of the energy grid following a large-scale blackout —a process known as a “black start”— will depend on being able to identify the root of the problem. But the absence of spare equipment and up-to-date monitoring software and hardware means that the Venezuelan state operator lacks the ability to visualize the grid and “understand the state of the system in real time”. At the same time, supporters of the Venezuelan government accuse Washington of sabotaging its oil-export sector by refusing to buy Venezuelan oil and threatening to impose sanctions on foreign states that purchase oil from Venezuela. That, they say, has deprived the country of its main source of hard currency and is makes it exceedingly difficult for Caracas to sustain the nation’s energy and food-supply networks.

Author: Joseph Fitsanakis | Date: 13 March 2019 | Permalink

German intelligence chief says Russia tried to hack energy grid

BfV GermanyThe head of Germany’s domestic security agency has publicly blamed the Russian government for a large-scale cyberattack that has targeted German energy providers. The comments follow a June 13 announcement on the subject by Germany’s Federal Office for Information Security (BSI), which is charged with securing the German government’s electronic communications. According to the BSI, a widespread and systematic attack against Germany’s energy networks has been taking place for at least a year now. The attack, which the BSI codenamed BERSERK BEAR, consists of various efforts by hackers to compromise computer networks used by German companies that provide electricity and natural gas to consumers around the country.

The attacks have been mostly unsuccessful, said BSI, having managed to breach just a few office computer networks. Energy grids have remained largely unaffected by BERSERK BEAR, said BSI. But the agency has refused to disclose information about the extent of the alleged cyberattacks and the companies that were targeted. It claims, however, that the situation is now “under control”. On Wednesday, Hans-Georg Maassen, director of Germany’s Federal Office for the Protection of the Constitution (BfV) said in an interview that the Russian government was most likely behind the attacks. There were “numerous clues pointing to Russia”, said Maassen, including the method with which the attack was carried out. The “modus operandi” of the attackers “is a major indicator that points to Russian control of the offensive campaign”, said Maassen.

Earlier this month, the United States imposed for the first time economic sanctions on Russian companies that allegedly helped the Kremlin tap undersea communications cables used by Western countries. One of the companies was identified by the US Department of the Treasury as Digital Security, which Washington said has helped Russian intelligence agencies develop their offensive cyber capabilities. Two of Digital Security’s subsidiaries, Embedi and ERPScan, were also placed on the US Treasury Department’s sanctions list. But the Kremlin fervently denies these accusations. On Wednesday, a spokesman for the office of the Russian presidency said that Moscow had “no idea what [Maassen] was talking about”. A Russian Foreign Ministry spokesman told reporters in the Russian capital that Germany and other countries “should provide facts” to justify their accusations against Moscow.

Author: Joseph Fitsanakis | Date: 21 June 2018 | Permalink

Russians ‘uncovered plan to kill Greek prime minister’

Kostas Karamanlis

K. Karamanlis

By JOSEPH FITSANAKIS | intelNews.org |
A Russian counter-surveillance team operating in Athens in 2008 confronted a foreign team from “a country allied to Greece”, which planned to kill Kostas Karamanlis, then Greece’s Prime Minister. The revelation, published in the current issue of Greek weekly newsmagazine Epikera, is allegedly based on a Russian briefing contained in a classified document authored by the Greek National Intelligence Service (EYP). According to the document, the assassination plot was code-named Pythia and was hatched by the intelligence agency of “a country allied to Greece”. It was aimed at preventing Athens from signing on to a series of energy pipeline deals with Moscow. The 19-member Russian counter-surveillance team mentioned in the EYP document had allegedly been set up a few months earlier by the FSB, Russia’s primary foreign intelligence agency. The team was deployed after the Russians realized that that Prime Minster Karamanlis’ telephone calls with Russian leader Vladimir Putin were being intercepted by foreign spies, at least two of which were allegedly British citizens. According to the Epikera article, between April 20 and 25, while shadowing the Greek Prime Minister in the Nea Makri area, just north of Athens, a four-member Russian counter-surveillance team faced off two spy operatives of “a country allied to Greece”. Read more of this post

Senate bill proposes closer links between US spies, private sector

Olympia Snowe

Olympia Snowe

By IAN ALLEN| intelNews.org |
A bipartisan bill, unveiled yesterday in the US Senate, proposes closer links between US intelligence agencies and private sector companies active in areas of “critical infrastructure”. Drafted and proposed by Republican senator Olympia Snowe and Democrat Jay Rockefeller, the legislation builds on concerns by government officials that US energy and telecommunications systems may not be able to sustain a concentrated cyber-attack by a foreign government agency or organized cybercriminal group. The major practical problem in terms of the government protecting these systems is that most have been deregulated since the Reagan era, and are now almost entirely under the control of private corporations. According to the bill, the US government would have to define the term “critical infrastructure”, and then designate the companies in control of such infrastructure networks as “critical partners” in protecting strategic national interests. Read more of this post

Analysis: Google-NSA partnership part of broader trend

Google

Google

By IAN ALLEN | intelNews.org |
We reported last week the apparent alliance between the Google Corporation and the US National Security Agency, which is the main US government organization tasked with communications interception, as well as communications security. The partnership, which began soon after Google’s decision to close down its venture business in China, where its operations came repeatedly under cyber-attack, has caused considerable controversy among civil liberties advocates. But an op-ed in the US-based Federal News Radio website describes it as the beginning of a new trend, which is likely to intensify. Read more of this post

News you may have missed #0005

  • Republican Senator’s extra-marital affair endangered national security. John Ensign is a member of the Senate Homeland Security and Governmental Affairs Committee, including its Permanent Subcommittee on Investigations, giving him and his staff access to extremely sensitive national defense information. His extra-marital affair made him vulnerable to blackmail by hostile spy services or other interests eager to pry secrets from his position on sensitive national security committees, veteran counterintelligence officials say.
  • Thank goodness reformists didn’t win in Iran election, says Mossad. Israel spy chief Meir Dagan, told the Knesset Foreign Affairs and Defence Committee on June 17 that if reformist candidate Mir Hossein Mousavi had won the elections “Israel would have a more serious problem because it would need to explain to the world the danger of the Iranian threat”.
  • CIA still fighting full release of detainee report. According to two intelligence officials, the CIA is pushing the Obama administration to suppress passages describing in graphic detail how the agency handled its detainees, arguing that the material could damage ongoing counterterrorism operations by laying bare sensitive intelligence procedures and methods.
  • US electricity industry to scan grid for spies. The planned scan is part of a pilot initiative to see whether Chinese spies have infiltrated computer networks running the US power grid. IntelNews has been keeping an eye on revelations that foreign spies have penetrated the electronic infrastructure of America’s electrical supply grid.
  • US Supreme Court declines review of Cuban Five case. It and its supporters argue Cuban spies received a fair trial in heart of Miami Cuban-American community, but Cuban government says it will continue to campaign for their release.

Intelligence sources say US electric grid hacked by foreign spies

By IAN ALLEN | intelNews.org |
In yesterday’s edition, The Wall Street Journal quoted senior US intelligence sources, including former Homeland Security Department officials, who said that foreign spies have penetrated the electronic infrastructure of America’s electrical supply grid. The officials said the hackers, who have reportedly been traced to Russia and China, among other countries, do not currently appear intent on disrupting the system. Instead, they seem to be “on a mission to navigate [and map] the US electrical system and its controls”, allegedly so that they can sabotage it “during a crisis or war”. Interestingly, the discovery was reportedly made not by utility company technicians, but by US intelligence agents engaged in monitoring cyber-intrusions into the nation’s electronic infrastructure. Read more of this post