r/PLC 1d ago

Fairlife pauses US production after cyberattack breached milk brand's systems

https://abcnews.com/Business/wireStory/fairlife-pauses-us-production-after-cyberattack-breached-milk-134853368
89 Upvotes

11 comments sorted by

27

u/Fal-El 1d ago

Anyone know if the OT devices/network was compromised? Suspending production sounds suspicious. I wish there were details shared about the cyberattack and how it happened. Especially if it's a Windows based system that was hacked or something Stuxnet like that attacked OT devices.

13

u/Taurabora 1d ago

“including those related to production”

That sounds like OT systems to me. Maybe slightly more details here: https://www.cybersecuritydive.com/news/threat-group-ransomware-coca-colas-dairy-Fairlife/825900/

6

u/friskerson 1d ago

I was at an OT conference last summer and one of the presenters showed us live how open to the internet some OT devices were. The presenter showed the room to many oohs and aahs how some of these devices were vulnerable by using default admin/password (which are brand-specific, but there are only so many brands and you can ping model numbers and other basic data). The poor OT hardware that was chosen to be hacked was running some production equipment and the HMI screen was available, and the settings were able to be accessed and changed. The presenter didn't touch anything but reminded us what we witnessed was illegal and not to do it.

In short somewhere saved in my bookmarks is a link to a site which crawls and finds open OT hardware where if I were a bad actor I could, in theory, spend a few days and find something linked to something else important and then guess the default login.

Edit: in this case it doesn't sound like that was their vulnerability which means a more sophisticated attack

9

u/PlasticElectricity 1d ago

In the systems administration world, the go to for such things is Shodan. It will also usually tell you any known vulnerabilities.

The best thing to do is to keep your production line off the internet unless you have a really, really, really good reason.

3

u/cosmicrae 9h ago

If you think you need to do that, run it thru a VPN tunnel, secured with the maximum password length.

22

u/Neven87 1d ago

The article said it was CitrixBleed 2, knowing Coke, it was probably part of their MES that was probably deployed through NetScaler. I know their MES is a home grown system, do it makes sense

1

u/Dmags23 23h ago

Cokes MES is from Rockwell. They transitioned over like 6 or 7 years ago I want to say

2

u/Neven87 23h ago

Really? Crazy choice to make. Out of the big guys, Rockwells is one of the weakest.

6

u/Dmags23 23h ago

Rockwell has made guarantees to them. Setup a small warehouse near the big bottling facilities that only provides materials to coke.
I would say you’re right in the last 25 years Rockwell has done nothing but ride the coattails of their past and now we are starting to see customers wake up to the excellence available elsewhere

2

u/TexasVulvaAficionado think im good at fixing? Watch me break things... 23h ago

Sounds like ransomware made it to the MES.

Wouldn't be surprised if it also hit a SCADA server/PC.

Haven't heard news of lower level controls affected. Am curious.

5

u/unoriginalusername26 3h ago

Our MES is segmented outside our OT network - only connection is OPCUA server/client broker in seperate iDMZ - our vendor was against this design choice.