Former Water Treatment Plant Employee Charged With Remote Attack 

In a press release, the U.S. Department of Justice said that a former employee of Discovery Bay Water Treatment Facility in California was indicted by a federal grand jury for intentionally attempting to cause a malfunction to the facility’s safety and protection systems. 

Employed as an “instrumentation and control tech” between July 2016 and December 2020 for a private Massachusetts company under contract with the facility, the indictment alleges that Rambler Gallo had installed remote control software on his employer’s systems as well as his personal computer. After resigning from his job in January 2021, he used his personal computer to send remote commands to the water treatment’s computers to uninstall critical software tools responsible for monitoring water pressure, filtration, and chemical levels on the water. Although the reason is unknown, it is assumed his intent was to cause harm.  

According to the indictment, filed June 27, 2023, and unsealed earlier today, prior to the attack on the Discovery Bay Water Treatment facility, Gallo, 53, of Tracy, Calif., was a full-time employee of a private Massachusetts-based company identified in the indictment as Company A. Company A contracted with Discovery Bay to operate the town’s wastewater treatment facility; the facility provides treatment for the water and wastewater systems for the town’s 15,000 residents. During his employment with Company A, from July of 2016 until December of 2020, Gallo was the company’s “Instrumentation and Control Tech,” with responsibility for maintaining the instrumentation and the computer systems used to control the electromechanical processes of the facility in Discovery Bay.

The indictment alleges that while Gallo was employed with Company A, he installed software on his own personal computer and on Company A’s private internal network that allowed him to gain remote access to Discovery Bay’s Water Treatment facility computer network. Then, in January of 2021, after Gallo had resigned from Company A, he allegedly accessed the facility’s computer system remotely and transmitted a command to uninstall software that was the main hub of the facility’s computer network and that protected the entire water treatment system, including water pressure, filtration, and chemical levels.

The indictment charges Gallo with one count of transmitting a program, information, code, and command to cause damage to a protected computer, in violation of 18 U.S.C. §§ 1030(a)(5)(A) and (c)(4)(B)(i).If convicted, Gallo faces a maximum statutory penalty of 10 years in prison and a fine of $250,000.

Roy Akerman, Co-Founder & CEO, Rezonate had this comment:

      “Insider threats are an uprising risk to organizations of all sizes across all verticals. An over privileged workforce raises the question of who is “watching the watchers.” The case of the Discovery Bay Water Treatment Facility in California appears to be a faulty deprovisioning process, but any administrative access that lacks the proper permissions processes around it is a huge vulnerability – regardless of who the user is. Never trust, always verify.” 

Insider threats are more dangerous than external ones because they’re already in. Organizations need to make sure that the threats posed by insiders are not only minimized as much as possible, but addressed quickly if they turn out to be a real threat.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading