The Maroochy sewage attack: how a rejected job applicant flooded parks with waste
In 2000 a man in Queensland, Australia, spilled about 800,000 liters of raw sewage into parks and waterways, and he did it from outside the plant, using a laptop and a radio.[1][2] This case file covers how a former contractor turned a town's sewage controls against it, how a traffic stop ended it, and the control that would have shut him out.
What happened
Maroochy Shire, on the Sunshine Coast north of Brisbane, ran a computerized system to control the pumping stations that move its sewage. The system was installed by an outside contractor. Vitek Boden, then 49, had worked for that contractor on the project.[1]
After he left, he applied for a job with the Maroochy Shire Council itself and was turned down.[1] Soon afterward, the sewage system began to misbehave. Pumps failed to run when they should have, alarms stayed silent, and staff found they could not properly see or control what the stations were doing.[2]
The problems ran from February to April 2000. Over that time there were at least 46 attempts to interfere with the system.[1][2] Raw sewage spilled into local parks, rivers and the grounds of a Hyatt Regency hotel. An environmental official described dead marine life, creek water turned black, and a stench that residents could not escape.[1]
How it worked
The pumping stations talked to the central control computer over a two-way radio network. The system trusted any radio message that looked like it came from the right place. There was no strong check that a command really came from the council's own equipment.[2]
According to later analysis of the case, the attacker used a computer, possibly stolen, loaded with the specialized engineering software used to configure the system's controllers, plus radio equipment to talk to the stations.[2] He posed as a legitimate pumping station, sent false instructions, disabled alarms at 4 stations, and kept alerts from reaching the central computer.[2]
In other words, the knowledge and tools he had picked up on the job still worked after the job ended. Nothing in the system could tell the difference between a real station and a former insider parked nearby.
How it was caught
Council staff and the contractor spent weeks trying to work out whether they faced faulty equipment or a person. The answer came on the road. On April 23, 2000, police pulled over Boden's vehicle and found radio and computer equipment inside.[1] A laptop in the car held software for accessing and controlling the sewage management system.[1]
What it cost
In late 2001 the Maroochydore District Court found Boden guilty of hacking into the shire's computerized waste management system, and he was sentenced to 2 years in prison.[1] The environmental damage was the larger bill: about 800,000 liters of untreated sewage in public spaces and waterways, and weeks of staff time spent chasing faults that had a human cause.[1][2]
The case became one of the most cited examples of an attack on industrial control systems, the computers that run pumps, valves and power equipment, and a standard warning about insiders who leave with knowledge of how things work.[2]
The missing control
The missing control: cutting off former contractors and authenticating every command. Someone who had worked on the system still had the knowledge, software and equipment to talk to it after leaving, and the pumping stations accepted instructions without checking that they came from a trusted source.[1][2]
A proper exit process for the contractor, covering returned equipment, software licenses and any shared credentials, would have made his job harder. Authentication on the radio link, so that stations accepted only commands signed by the council's own system, would have made the false instructions useless. Either would have shortened this attack. Both together would likely have stopped it.
What to do in your business
- Run an exit checklist for contractors too. When a vendor, contractor or temp finishes, collect equipment, disable accounts and change any shared passwords they knew, the same day.
- Change shared codes after people leave. Alarm codes, door codes, Wi-Fi passwords and admin logins that a departing person knew should be changed, not left in place.
- Track who holds your specialized software. Keep a list of who has copies of configuration tools, backup files or admin software for your systems, and ask for them back.
- Treat odd equipment faults as a possible person. If alarms go quiet or systems act up repeatedly after a staff change, ask whether someone could be causing it.
- Ask vendors how commands are verified. For alarms, building controls or anything that runs equipment, ask your provider whether the system checks that commands come from an authorized source.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- The Ubiquiti hack was an inside job: how a senior developer extorted his employer
- How the Coinbase data breach happened: bribed support agents and a $20 million demand
- How one trader brought down Barings Bank: account 88888
- How a Twitter employee sold user data to Saudi Arabia for a watch and cash
- The Tesla insider bribe plot: the $1 million offer an employee reported
- Every insider risk control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.