Black Hat

Black Hat Researchers Remotely Hack Into SCADA Systems on Oil Rigs

SCADA systems used on oil rigs and other areas of the oil industry are using outdated networking protocols that can easily be compromised, SCADA experts told attendees at the Black Hat security conference.

<p><span><span><strong>SCADA systems used on oil rigs and other areas of the oil industry are using outdated networking protocols that can easily be compromised, SCADA experts told attendees at the Black Hat security conference.</strong></span></span></p>

SCADA systems used on oil rigs and other areas of the oil industry are using outdated networking protocols that can easily be compromised, SCADA experts told attendees at the Black Hat security conference.

Attackers can cause an oil tank to nearly overflow by sending spoofed commands to the programmable logic controller, Brian Meixell and Ercik Forner, researchers from Cimation, told attendees on Thursday. In a live demonstration, Meixell and Forner sent commands to a simulated model of an oil well and a pump to switch to “high” and spill the oil. The team also sent fake data using several Python scripts, making the system think the pump was empty when it was actually close to overflowing.

“So you can have the operator seeing something entirely different than what’s happening in the process, causing the pipe to burst and the tank to overflow,” Forner told attendees. “The operator would see the tank levels decreasing, when in fact they were increasing.”

The duo also hacked the remote terminal unit’s HMI and cause a game of Solitaire to appear on the screen at the conclusion of the talk.

Unlike previously disclosed issues in SCADA systems, Forner and Meixell didn’t exploit any specific security flaws of vulnerabilities in the systems for their attack. This hack relies entirely on the fact that there is no security built-in to the serial Modbus/TCP networking protocol. Dating back to the 1970s, Modbus operates on port 502, and has “no authentication or security at all desgigned into it,” Forner said.

The SCADA system is sending packets over the network without any kind of authentication and using scripts to send remote commands to the PLC devices. The researchers were able to disable logic designed to detect the status of the pump and make it work opposite to what it was supposed to do.

Forner and Meixell are familiar with the issues in these systems, as they support and install SCADA systems in oil rigs. “We only had a 24-volt pump in the demo, but this could cause a complete environmental catastrophe” if used against a real oil-drilling operation, Forner said.

Advertisement. Scroll to continue reading.

Related Content

ICS/OT

The US government has warned that Iran-linked hackers are manipulating PLCs and SCADA systems to cause disruption.

ICS/OT

Join us as speakers from Cisco outline important steps industrial organizations can take to safeguard operations, achieve compliance, and enable sustainable growth.

ICS/OT

Over 20 advisories have been published by industrial giants this Patch Tuesday.

ICS/OT

Honeywell has patched several critical and high-severity vulnerabilities in its Experion PKS  industrial process control and automation product.

ICS/OT

Industrial solutions providers Siemens, Schneider Electric and Phoenix Contact have released July 2025 Patch Tuesday ICS security advisories.

ICS/OT

Censys researchers follow some clues and find hundreds of control-room dashboards for US water utilities on the public internet.

ICS/OT

More than 100 AutomationDirect MB-Gateway devices may be vulnerable to attacks from the internet due to CVE-2025-36535.

ICS/OT

Agencies say the attacks leverage basic intrusion techniques, but poor cyber hygiene within critical infrastructure organizations could lead to disruptions and damage.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version