Blog

"Explosive" cyber attacks in Oil and Gas are life threatening

March 15, 2018
Matias Madou, Ph.D.
Black and white photo of industrial metal pipes, stairs, and platforms in a complex factory setting.

The focus of most cybersecurity discussions relate to protecting money, reputation and information. Within financial institutions, it is often a threat to personal or company finances. In the telecommunications industry, it is more about personal identity information or intellectual property theft. At a government level, cyber-espionage is a relatively easy and low-cost way to acquire high-value intelligence.

However, the dangers of cyberattacks on physical infrastructure including SCADA (Supervisory Control and Data Acquisition) and ICS (Industrial Control Systems) are very real, growing and frightening, as a recent New York Times article about an attack on a petrochemical company with a plant in Saudi Arabia explains.

Within the Oil and Gas sector, cybersecurity attacks can cause explosions. For a long time, these plants were not connected to networks, but now, in the interests of simplicity of management, they have all been dangerously connected. The probability of these systems being attacked - and successfully so - is now much higher. These  applications are NOT designed with security in mind, because, it was not the intention to have them connected to the internet.

The NYT article details an attack that was not designed to simply destroy data, or shut down the plant, but also to sabotage the firm's operations and trigger an explosion that would likely harm other humans. Investigators said the only thing that prevented an explosion was "a mistake in the attackers'computer code", one which they believe the hackers have "probably fixed by now". Investigators believe it is "only a matter of time" before they deploy the same technique against another company successfully.

Software developers are becoming key architects who underpin the success and safety of many public and private organizations. There is no greater example than in the Oil and Gas industry. It is more important than ever that they have a better knowledge of the security implications of their work and that they learn how to code securely, whatever language or frameworks they use.

If you want to see how developers can learn about security to help protect critical infrastructure, play the following challenge:

https://portal.securecodewarrior.com/#/simple-flow/web/injection/oscmd/cpp/vanilla

The only thing that prevented an explosion was a mistake in the attackers'computer code, the investigators said.

https://www.nytimes.com/2018/03/15/technology/saudi-arabia-hacks-cyberattacks.html

The cyberassault was not designed to simply destroy data or shut down the plant, investigators believe. It was meant to trigger an explosion. https://t.co/kQqcAhoW01

" The New York Times (@nytimes) March 15, 2018

A Cyberattack in Saudi Arabia Had a Deadly Goal. Experts Fear Another Try. https://t.co/q9UdicR7dv

" Colin Wright (@colinismyname) March 22, 2018

The attack was a dangerous escalation in international hacking, as faceless enemies demonstrated both the drive and the ability to inflict serious physical damage. https://t.co/G8bBCteouZ#CyberSecurity #NetworkMonitoring

" Elitery Indonesia (@eliterydc) March 22, 2018

A recent failed #cyberassault on a Saudi Arabian petrochemical company had a deadly goal. This @NYTimes article explains more: https://t.co/3g8oDuPijm pic.twitter.com/MfSqrXSd9u

" Symantec EMEA (@SymantecEMEA) March 21, 2018

Govern AI-driven development before it ships

Measure AI-assisted risk, enforce secure coding policy at commit, and accelerate secure delivery across your SDLC.

Book a demo
Resource library

Explore more blogs

Access expert content on secure coding, AI governance, and software risk management.

browse all
Blog
Filter Label
This is some text inside of a div block.

Cybersecurity Awareness Month 2026: Understanding AI Security Is Critical to Enterprise Defense

We’ve reached a point where most top AI companies have publicly called for a global slowdown in AI development so safety guardrails can catch up, but the truth is, serious security issues have already come to fruition. This leaves countless security leaders and executive teams in an urgent position, as the monetary and risk costs of AI implementation keep piling up.

Learn More
Blog
Filter Label
This is some text inside of a div block.

Enabler 8: Branding Your Program

A secure coding program needs more than great content to succeed. Enabler 8 shows how branding turns participation into a coveted, status-driven experience.

Learn More
Blog
Filter Label
This is some text inside of a div block.

Every Employee is Now on the Frontline of AI Cybersecurity

The enterprise technology landscape is shifting with a velocity few predicted until it was too late. We have officially crossed the threshold from human-written code and basic copilot assistance, into the era of the Agentic Development Lifecycle (ADLC). While autonomous AI agents promise unprecedented efficiency across multiple functions, they also bring an entirely new class of security and regulatory risks.

Learn More

Secure AI-driven development before it ships

See developer risk, enforce policy, and prevent vulnerabilities across your software development lifecycle.

Book a demo
trust score
No items found.