{"id":30566,"date":"2025-05-23T17:32:09","date_gmt":"2025-05-24T00:32:09","guid":{"rendered":"https:\/\/essential.construction\/news\/from-cuckoos-egg-to-todays-cyber-threat-landscape\/"},"modified":"2025-05-23T17:32:09","modified_gmt":"2025-05-24T00:32:09","slug":"from-cuckoos-egg-to-todays-cyber-threat-landscape","status":"publish","type":"post","link":"https:\/\/essential.construction\/news\/from-cuckoos-egg-to-todays-cyber-threat-landscape\/","title":{"rendered":"From &#8216;Cuckoo\u2019s Egg&#8217; to Today&#8217;s Cyber Threat Landscape"},"content":{"rendered":"<p> [ad_1]<br \/>\n<\/p>\n<div id=\"\">\n<p id=\"ember653\">In 1990, I read an exciting book titled <em><a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/The_Cuckoo%27s_Egg_(book)\" target=\"_blank\">The Cuckoo\u2019s Egg<\/a>: Tracking a Spy Through the Maze of Computer Espionag<\/em>e. The author, astronomer <a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Clifford_Stoll\" target=\"_blank\">Clifford Stoll<\/a>, managed computers at\u00a0Lawrence Berkeley National Laboratory (LBNL)\u00a0in California. He was tasked with resolving an accounting error of 75 cents in the computer usage accounts.<\/p>\n<p id=\"ember654\">The tedious process eventually led him to disclose a German hacker who had gained access to U.S. military secrets through LBNL\u2019s computers. He had been selling information to the KGB for years.<\/p>\n<h3 class=\"wp-block-heading\" id=\"ember655\">Today\u2019s threat landscape in construction<\/h3>\n<p id=\"ember656\">The LBNL incident was one of the first\u2014if not <em>the<\/em> first\u2014documented cases of a computer break-in. Fast-forward to today and\u00a0cyber-attacks are an everyday phenomenon that occurs more often in construction.<\/p>\n<p id=\"ember657\"><a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/www.construction.com\/resource\/data-resilience-in-design-and-construction-how-digital-discipline-builds-stronger-firms-smartmarket-brief\/\" target=\"_blank\">A 2023 survey<\/a> by Dodge Construction Network, in collaboration with content security and management company Egnyte, found that 59% of AEC firms had faced a cybersecurity threat within two years.<\/p>\n<p id=\"ember658\">General contractors were the most affected, with 70% experiencing a threat and 30% dealing with a ransomware attack during that period.<\/p>\n<h3 class=\"wp-block-heading\" id=\"ember659\">Recent cyber incidents<\/h3>\n<p id=\"ember660\">Some examples of construction-related cybersecurity incidents include:<\/p>\n<ul class=\"wp-block-list\">\n<li><a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/www.kyberturvallisuuskeskus.fi\/sites\/default\/files\/media\/publication\/TRAFICOM_Tietoturvan-vuosi-2022_EN_WEB.pdf\" target=\"_blank\">Two ransomware attacks<\/a> in 2022 on Finland-based companies, Vahanen Group, an engineering firm, and Uponor Corporation, a manufacturer<\/li>\n<li><a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/www.constructiondive.com\/news\/skender-ransomware-attack-chicago-maine\/712844\/\" target=\"_blank\">A ransomware attack<\/a> on Skender Construction, a Chicago-based general contractor, in 2024<\/li>\n<li><a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/www.cfodive.com\/news\/scammers-siphon-25m-engineering-firm-arup-deepfake-cfo-ai\/716501\/\" target=\"_blank\">AI deep fake scam<\/a> on ARUP\u00a0allegedly led a staff member to transfer $25 million to Hong Kong bank accounts in 2024<\/li>\n<li><a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/cybernews.com\/cyber-war\/north-korea-hackers-attack-south\/\" target=\"_blank\">Spying malware<\/a> distributed through the website of a professional association of the South Korean construction sector<\/li>\n<\/ul>\n<h3 class=\"wp-block-heading\" id=\"ember662\">Why construction is an attractive target<\/h3>\n<p id=\"ember663\">I can think of several reasons construction can be an attractive and lucrative target for malicious actors:<\/p>\n<ul class=\"wp-block-list\">\n<li>Construction projects involve dozens or hundreds of companies that vary in tech maturity and security awareness. The weakest link can open the channel to valuable information.<\/li>\n<li>Email is still the predominant digital communication method and the primary source of phishing and other attacks. If anybody introduced our email tech, it would be deemed impossibly insecure.<\/li>\n<li>Construction project teams create and share information that has market value to some malicious actors. Designs of critical infrastructure, plans for a new production plant, or information about locations of sensitive equipment can be accessed through AEC firms\u2019 computers.<\/li>\n<\/ul>\n<p id=\"ember665\">One security expert told me that for some organizations, even seemingly harmless information can become valuable over time when connected with other data.<\/p>\n<h3 class=\"wp-block-heading\" id=\"ember666\">Prevent, protect, and prepare<\/h3>\n<p id=\"ember667\">Studies have shown that the construction sector is behind other industries in cybersecurity. However, in the Dodge survey, 72% of architects, engineers, and contractors claimed to have a moderate or higher degree of preparation for an attack that would cause them to lose access to documents.<\/p>\n<p id=\"ember668\">The problem is that in a heavily networked industry, a cyberattack on one company on a project can impact several others, including the client. As general contractors are mainly responsible to the client, they should do due diligence on their partners\u2019 cybersecurity. I don\u2019t know how commonly CGs <a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/www.constructiondive.com\/news\/how-to-add-cybersecurity-provisions-in-construction-contracts\/722583\/\" target=\"_blank\">include related provisions in the contracts<\/a>.<\/p>\n<p id=\"ember669\">Anyway, we need to ramp up cybersecurity in this sector. <strong>Craig Yeack<\/strong> from Bulk Construction Materials Initiative <a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/www.forconstructionpros.com\/construction-technology\/article\/22914524\/bulk-construction-materials-initiative-bcmi-cybersecurity-in-construction-prevent-protect-and-prepare\" target=\"_blank\">suggests<\/a> that construction businesses consider cybersecurity a funnel of <em>three Ps<\/em>: prevention, protection, and preparation. Prevention is the largest piece at the top.<\/p>\n<p id=\"ember670\"><strong>PS.<\/strong> While I wrote this piece, I remembered a trip to Washington, D.C., in the early 1990s. I mentioned Cuckoo\u2019s Egg while visiting an architect who lived there. To my great surprise, he knew the author personally. <a rel=\"noreferrer noopener nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Six_degrees_of_separation\" target=\"_blank\">Not six<\/a>, but one degree of separation this time!<\/p>\n<\/div>\n<p>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/aec-business.com\/from-cuckoos-egg-to-todays-cyber-threat-landscape\/\" rel=\"nofollow noopener\" target=\"_blank\">This article was originally posted at Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[ad_1] In 1990, I read an exciting book titled The Cuckoo\u2019s Egg: Tracking a Spy Through the Maze of Computer &#8230; <a title=\"From &#8216;Cuckoo\u2019s Egg&#8217; to Today&#8217;s Cyber Threat Landscape\" class=\"read-more\" href=\"https:\/\/essential.construction\/news\/from-cuckoos-egg-to-todays-cyber-threat-landscape\/\" aria-label=\"Read more about From &#8216;Cuckoo\u2019s Egg&#8217; to Today&#8217;s Cyber Threat Landscape\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1062,1066],"tags":[1162],"class_list":["post-30566","post","type-post","status-publish","format-standard","hentry","category-aec-business","category-all-posts","tag-smart-construction","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-33"],"_links":{"self":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts\/30566","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/comments?post=30566"}],"version-history":[{"count":0,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts\/30566\/revisions"}],"wp:attachment":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/media?parent=30566"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/categories?post=30566"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/tags?post=30566"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}