Security researchers uncovered Stuxnet, a highly sophisticated computer worm designed to attack Siemens industrial control systems. By September, analysts reported that around 60% of known infections were in Iran, and speculation grew that its nuclear programme was the target.
What happened
- The worm was first identified in June 2010 by Belarusian firm VirusBlokAda and became public in mid-July 2010.
- It spread via USB drives and Windows vulnerabilities, including previously unknown (zero-day) flaws.
- Infections were also found in countries including Indonesia, India, and the United States.
- In September 2010, Iranian officials confirmed Stuxnet had infected personal computers of staff at the Bushehr nuclear plant.
Why it mattered
Stuxnet is widely regarded as the first known cyber weapon built to cause physical damage, and experts said its complexity pointed to state backing. It changed how governments and industry think about the security of critical infrastructure.
Lessons for organisations
Operational technology needs its own security controls: network segmentation, strict control of removable media, and monitoring of engineering workstations. Standards such as IEC 62443 complement ISO/IEC 27001 for industrial environments, and asset inventories should include industrial devices.
Source: Al Jazeera
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.