Sys admin admits trying to axe California power grid
A sys admin last week pleaded guilty to attempting to disrupt the power grid in California by shutting down a data centre that managed the state's electrical supply. — Lonnie Charles Denison, 33, of South Natomas in California confessed …
Context & Ripple Effects
The plea by sys admin Lonnie Charles Denison lands weeks after another California insider case: in late November 2007 a suspect was charged with hacking the state's canal system, making this the second alleged insider attack on California physical infrastructure in under a month. It also closes out a quarter in which federal prosecutors extracted guilty pleas from network operators, including a botmaster who admitted controlling some 250,000 zombie PCs.
What distinguishes the Denison case is the target class: not consumer networks or botnets but a data centre managing the state's electrical supply. A single administrator with legitimate credentials allegedly came closer to grid disruption than the era's high-volume external attackers managed.
First-order effects
- Denison faces sentencing for the attempted disruption, and the operator of the targeted data centre must now account for how one admin's credentials could reach shutdown-level control of grid-management systems.
Second-order effects
- California utilities and the operators of similar control-room data centres face immediate pressure to tighten privileged-access controls and separation of duties, since the alleged attack vector was trusted-employee access rather than an external breach.
Third-order effects
- If insiders with legitimate credentials are treated as the primary threat to grid operations, critical-infrastructure operators move toward auditing and least-privilege models for control systems — a shift that would put supervisory-control environments under the same access-governance discipline as corporate IT.
The trend: Critical-infrastructure security is pivoting from defending the perimeter against outside hackers to policing the trusted administrators already inside control systems.