
As dependence on the Internet increases from corporate activities to daily life, the risk of cyberattacks is becoming more serious. To prepare for cyberattacks, we should look at past damage cases and understand attack methods. This time, we will introduce 5 selected cases from overseas examples of cyberattacks that have caused public concern.
MIT Students' Building Lighting Hack " Wall Tetris "
In April 2012, students at the Massachusetts Institute of Technology (MIT) hacked the lighting system of a campus building and turned the building's window lights into a giant Tetris game " hack " (a traditional MIT guerrilla-style prank). Although there was no actual damage as it was an experiment by students, this hacking exposed the vulnerability of the lighting system and the possibility of remote control attacks by others.
The targeted building was the Green Building (Building 54) on campus, which met conditions such as being tall, clearly visible from a distance near the river, and having windows suitable for a dot matrix display. The students first infiltrated the building and connected attack tools to the lighting system. They treated the 9×17 grid of 153 windows on the building's side as the computer game Tetris and freely manipulated the lighting system. The event was recorded in photos and videos, which can still be viewed online today.

Supply Chain Attack Targeting Major U.S. Retail Chain
In December 2013, the POS system of Target, a major U.S. retailer, was infected with malware, resulting in the leak of approximately 40 million credit card • debit card records and personal information of approximately 70 million customers. Target is a large-scale retail store handling everything from food to daily necessities and electronics, with annual sales of approximately 7 trillion yen at the time. Card information of shoppers from approximately three weeks was leaked, making it the largest-scale damage in terms of customer information leakage in the retail industry.
The method of this incident is called a supply chain attack (*), which was carried out using the HVAC management system provider introduced in the office as a stepping stone. The attackers first sent a phishing email to this provider and infiltrated it. Using the account information obtained there, they infiltrated the network of the main target retail company, installed malware on POS terminals, and stole large amounts of data.
* A supply chain attack is a cyberattack that exploits business connections between organizations as a stepping stone to illegally infiltrate the target organization. Rather than directly attacking the target company, it is a method of first attacking related companies or business partners that tend to have weaker security measures, and using that as a foothold to attack the target organization.
Ransomware WannaCry That Wreaked Havoc Worldwide
In May 2017, an incident occurred in which approximately 230,000 computers in over 150 countries worldwide were infected with WannaCry, ransomware that holds data hostage and demands ransom, causing significant damage. WannaCry was encryption-type ransomware that encrypted and locked data so users could not access it, demanding ransom payment in the virtual currency Bitcoin.
The ransom demand was initially equivalent to $300, but increased to the equivalent of $600, and furthermore, a message was displayed stating that " if the ransom was not paid after 3 days, the encrypted files would be completely deleted and could not be restored ". However, it is considered doubtful whether data could be recovered even if the ransom was paid.
WannaCry spread infection by exploiting a known vulnerability in Windows. Microsoft had already released a security patch for this vulnerability, but it is pointed out that older computers that had not applied this update became infected and the damage spread.
The damage overseas was enormous, particularly in the UK, where medical facilities responsible for the public healthcare system were infected, causing major disruption with normal operations halted. The stoppage of management systems for medical records, prescriptions, and appointments caused life-threatening damage such as cancellation of surgeries and ambulance admissions, and approximately 19,000 medical appointments were cancelled.

" One of History's Most Complex and Sophisticated Cyberattacks " SolarWinds Incident
In December 2020, a cyberattack through products of U.S.-based SolarWinds was discovered. It was an advanced persistent threat (APT) attack using sophisticated methods to steal large-scale confidential information, affecting 18,000 organizations including U.S. government agencies. Intelligence agencies of both the U.S. and UK identified the source of the attack as Russia's Foreign Intelligence Service (SVR).
In this incident, SolarWinds' IT management • network management system Orion Platform was targeted. Malware SUNBURST was embedded in Orion's update program and spread to customer systems through downloads. It has been found that SUNBURST created a backdoor (back entrance for intrusion) for unauthorized access in infected networks and carefully stole information using this as a foothold.
Because SUNBURST was embedded in an update program with a legitimate digital signature First Name, could operate disguised as normal Orion network monitoring activities, and SUNBURST disabled many of the endpoint security tools, this malware continued its attacks undetected for a long time. Despite affecting government agencies and major corporations worldwide, it could not be detected for over a year, and because it was a highly sophisticated and widespread attack that was very cleverly orchestrated, it is considered " one of history's most complex and sophisticated cyberattacks ".
Russian Cyberattacks Targeting Ukraine's Critical Infrastructure
In February 2022, Russia's invasion of Ukraine began. It is known that cyberattacks had been increasing from about a month before, but in fact, large-scale power outages caused by malware had already occurred in December 2015 and December 2016.
In December 2015, a power outage occurred in western Ukraine, affecting 225,000 households. It was the first large-scale power outage caused by a cyberattack, and attracted worldwide attention as Ukraine's Security Service announced Russian government involvement. The malware Blackenergy used in the attack hijacked power company operators' PCs for monitoring and obtained IDs and passwords to log into the power grid control system. After illegally logging into the control system, it caused the power outage through remote operation.
In December 2016, a substation in the suburbs of the capital Kyiv was attacked, causing a power outage lasting over an hour. It was caused by malware Industroyer and CRASHOVERRIDE, which this time directly controlled substation switches and circuit breakers without going through the power grid control system.
In Ukraine, cyberattacks targeting critical infrastructure occurred one after another, targeting railway system servers, the national pension fund, banks, communications, and more. Phishing scams targeting government agencies also occurred.
Summary
As can be seen from Ukraine's current situation, cyberattacks have now become a serious matter related to warfare between nations. The existence of nations and organizations that interfere with activities or steal valuable information to gain advantage over hostile countries or companies is well known. Financial crime for monetary purposes is also centered on organized professional groups, and we should be aware that cyberattacks are becoming more vicious.
* Please also read these articles.
- Toward Secure IoT, " IoT Security Guidelines " You Should Know First
- Security Measures Are Essential for IoT! Explaining Possible Risks and Countermeasures
[Part 1] Understanding Threats Lurking in IoT [Part 2] Understanding Countermeasures Against Security Threats - Understanding the Overview of " Product Security Measures Guide for SMEs Developing IoT Devices "