Feeds

EU halts carbon trading after 'concerted' hack attacks

€30m up in smoke

Next gen security for virtualised datacentres

The European Commission has temporarily halted trading of carbon emissions credits following revelations that some two-million allowances worth about €30m were stolen from insecure accounts in recent days.

At least three of the “cyber attacks” have occurred since the beginning of the year, and other registries are known to be vulnerable, EC officials said in a FAQ posted on Friday. The Associated Press said national systems in five countries – including Austria, the Czech Republic, Estonia, Greece, and Poland – “each fell victim to 'concerted' online thievery over five days this week.”

Trading is scheduled to resume on Wednesday, but only if vulnerable countries secure their registries. Among the measures required, Bloomberg News reported, is the adoption of multi-factor authentication for account access rather than the simple use of a user name and password as is the case at many sites now.

The EC sets a limit on the total amount of carbon that can be spewed into the environment, and then allows polluters to buy and sell emission credits. Factories that emit less can sell allowances to those that emit more. The cap and trade system is the source of intense criticism from both environmentalists and pro-business groups, so it's not clear who is behind the attacks. While each ton of credit is worth about €2m apiece, each certificate comes with its own serial number, so it's not clear if a thief would be able to profit by reselling the stolen credits.

The EC didn't say how the registries were breached. Phishing emails that attempt to swindle registry-account passwords date back to at least July and resulted in the theft of 250,000 carbon permits worth over €3m. EU climate exchange ECX.eu has also come under defacement attacks by what's believed to be green-hat hackers opposed to the system.

The Czech registry compromised this week was planning to upgrade its security on Wednesday, but had to postpone the move after discovering the missing credits. About one million permits belonging to multiple companies were stolen from that exchange, Bloomberg said. Some 475,000 of them belonged to Blackstone Global Ventures and were transferred to accounts in Poland, Estonia, and Lichtenstein.

In November, an exchange in Romania was also compromised, the EC said. ®

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
prev story

Whitepapers

Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up distributed data
Eliminating the redundant use of bandwidth and storage capacity and application consolidation in the modern data center.
The essential guide to IT transformation
ServiceNow discusses three IT transformations that can help CIOs automate IT services to transform IT and the enterprise
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.