Hackers Kinda Like to Eat

Curtis Hanson (U.S. Managing Partner · Invictus Incident Response), Whitney Bowman-Zatzkin, Andrew Rose

BSides Las Vegas 2025 · Day 1

Overview

This I Am The Cavalry track session pairs Curtis Hansen (in person), representing Invictus Incident Response and describing himself as a new BioISAC member, with Andrew Rose (remote on AV), presented as involved with BioISAC and future threat modeling across states. The stated mission is to connect cyber risk to food, water, agriculture, and broader life-sciences infrastructure—the “bioeconomy” spanning pharma, biomanufacturing, genetics, and agriculture—under a pragmatic banner: no one is coming to save us, so defenders and communities need actionable resilience strategies.

Watch on YouTube

Visual summary for Hackers Kinda Like to Eat by Curtis Hanson, Whitney Bowman-Zatzkin, Andrew Rose
Visual summary for Hackers Kinda Like to Eat by Curtis Hanson, Whitney Bowman-Zatzkin, Andrew Rose

Key moments

  1. 2:00 BioISAC / bioeconomy framing: agriculture as part of broader life-sciences risk; Andrew Rose introduces his path via agricultural finance vulnerabilities.
  2. 6:00 Curtis Hansen on climate-linked agricultural risk; EDDI-style atmospheric dryness imagery as drought/fire weather context.
  3. 8:00 Center pivot irrigation: remote phone/tablet operation, chemical application, and nitrate/blue-baby public-health linkage through water systems.
  4. 10:00 UK South Staffordshire water case: Cl0p-associated ransomware narrative, multi-month extortion timeline, IT vs OT impact claims vs actor screenshots.
  5. 18:00 US water OT incidents (~Oct 2023): Cyber Av3ngers, Unitronics PLC defacements, internet-facing devices and default-password hygiene lessons.
  6. 26:00 IR pragmatism: expanding attack surface post-COVID; inventories, shadow IT, MFA tradeoffs in clinical settings, ISAC intel sharing.
  7. 30:00 Resilience planning: tabletops, out-of-band comms, backups, analog/manual overrides; Stuxnet cited as electronic-trust cautionary tale.
  8. 36:00 Andrew Rose on personal continuity: food/water stockpiling basics, community reliance over ‘lone prepper’ framing; nighttime heat risk discussion.

Hackers Kinda Like to Eat

Speakers: Curtis Hansen, Invictus Incident Response; Andrew Rose, BioISAC (remote)

Conference: BSides Las Vegas

YouTube: https://www.youtube.com/watch?v=V3wMcvbXd6c

Overview

This I Am The Cavalry track session pairs Curtis Hansen (in person), representing Invictus Incident Response and describing himself as a new BioISAC member, with Andrew Rose (remote on AV), presented as involved with BioISAC and future threat modeling across states. The stated mission is to connect cyber risk to food, water, agriculture, and broader life-sciences infrastructure—the “bioeconomy” spanning pharma, biomanufacturing, genetics, and agriculture—under a pragmatic banner: no one is coming to save us, so defenders and communities need actionable resilience strategies.

The talk alternates between two voices: Rose supplies macro vulnerability stories and cross-sector tabletop framing; Hansen bridges incident-response reality to agricultural systems and OT complexity. Together they walk through center-pivot irrigation as remotely operable critical equipment, nitrate water-quality impacts with a public health tie-in, a detailed case study of a UK water ransomware incident attributed in narrative to Cl0p, and a separate US-focused story about Iran-linked Cyber Av3ngers compromising Unitronics PLCs on internet-facing interfaces with default/weak credentials. The back half shifts into organizational guidance (ISAC membership, inventories, IR plans, tabletop exercises) and personal resilience practices (food storage, water capture, community mapping), explicitly blending cyber hygiene with acknowledgment that hygiene can collide with operational realities in healthcare and industrial environments.

Background

▶ Watch: BioISAC / bioeconomy framing: agriculture as part of broader life-sciences ri... (2:00)

Rose describes stumbling into agricultural finance risk roughly ten years ago after finding significant vulnerabilities at a large bank financing agriculture, leading him to ask whether the agricultural supply chain was similarly exposed. His answer then and now: broadly yes, compounded by low awareness bridging cyber and agricultural communities—farmers treating cyber events like weather, and cyber practitioners underestimating farm-scale automation.

Hansen positions himself as an agricultural futurist by experience, not formal credentialing: capital-markets work financing novel protein and seaweed operations forced long 7–20 year risk horizons. That lens connects climate, crop viability, and operational reliability. He also focuses on flash drought and fire weather, showing EDDI-style atmospheric dryness imagery (satellite program referenced as “Eddie / EDDI” in speech) as a way to think about moisture stress and wildfire precursors.

The irrigation discussion centers center pivots: pumped groundwater delivered through moving booms, sometimes also distributing fertilizers and pesticides. The security hook is remote operation from phones and tablets—convenience creating attack surface. Rose ties pivot malfunction and fertilization patterns to nitrate accumulation, referencing Iowa (especially Des Moines area) as a region with acute nitrate concerns, and describes blue baby syndrome (medically methemoglobinemia) as a pediatric emergency pattern hospitals must prepare for when nitrates spike in drinking water.

Key Findings

▶ Watch: Center pivot irrigation: remote phone/tablet operation, chemical application,... (8:00)

Water is the hinge between cyber, food, and hospitals. The speakers argue that ransomware or manipulation of water systems is not an abstract IT problem—it propagates into irrigation, clinical care, and societal stability. Hansen uses South Staffordshire Water (spoken as “South Staff / Staffordshire”) as a UK case: a Cl0p-associated ransomware storyline servicing populations described at ~1.3 million people and ~35,000 commercial customers, framed as metro-scale impact comparable to Dallas–Fort Worth or San Diego (analogies as stated in talk).

Extortion timelines are long. The incident narrative spans July intrusion, August extortion activity, and a September second wave—used to emphasize that “recovery” is not a weekend exercise and that business and civic consequences persist for months.

Threat actor claims vs verified operational impact diverge. The victim-facing story emphasized IT breach, customer data exposure, and asserted no harmful change to water delivery or chemical treatment. Cl0p-style actors nonetheless posted screenshots claiming Scada/OT access; the speakers treat this as unverified but strategically plausible pressure tactic, warning defenders to separate ransom theater from confirmed process manipulation.

Victimology patterns matter for expectation setting. Rose cites Water ISAC victimology analysis around Cl0p suggesting a large share (~45%) of victims were industrial/infrastructure-oriented—used to argue financial motivation aligns with targets likely to pay under public pressure.

US water OT defacements show low sophistication can still reach PLCs. A separate thread covers October 2023 incidents affecting at least ~10 US water facilities (with Pennsylvania municipality ~15,000 residents called out as confirmed hacked on record). The group named is Cyber Av3ngers, described as Iran-linked, IRGC-associated in the speaker’s assessment, sabotage-focused, mixing information operations with real access. Impact observed: defacement of Unitronics PLC HMI rather than destructive process shutdown—still a proof that internet-facing OT with default/no passwords is exploitable.

Attack surface expansion is the default trend. Post-COVID digitalization increased cloud, on-prem, IoT, and field connectivity (pivots, combines). The speakers argue this expands opportunity for adversaries and workload for defenders—without automatically increasing maturity.

Culture and economics block security adoption. In Q&A, they discuss translating security into dollar loss narratives for agricultural operators and the harsh reality that many societies respond only after crises—contrasting Estonia’s nationwide cyber education push after 2007 with slower cultural movement elsewhere. North Dakota is offered as a US example of state-level cyber education investment.

Technical Deep Dive

▶ Watch: US water OT incidents (~Oct 2023): Cyber Av3ngers, Unitronics PLC defacements... (18:00)

The deepest technical content is in the OT case studies rather than exploit walkthroughs.

For Cl0p, the speaker emphasizes a file-transfer supply-chain attack pattern (MOVEit, Accellion, Cleo mentioned as examples of “pop one vendor, hit many customers”), then applies that mental model to why critical infrastructure entities appear in leak sites. Technical defenders should read that as third-party concentration risk plus exfiltration-first extortion—sometimes sparing encryption, which changes IR priorities (availability may remain while confidentiality is lost).

For Cyber Av3ngers, the described access path is almost insultingly simple: internet-exposed PLCs, default credentials like “admin / 123” (as stated), implying absence of segmentation and basic remote-access governance. The recommended mitigations echoed in-session are textbook network segmentation, eliminating unnecessary internet exposure for OT devices, and credential hardening—simple to say, expensive to operationalize where vendors require remote support or installers leave defaults.

The uncomfortable truth is that “textbook” OT security often dies at the project management layer. A pivot or PLC is installed by an integrator under time pressure. Remote access is enabled because someone will be on call at 2 a.m. during harvest. The vendor cloud portal is convenient. The firewall change request sits in a queue. The asset never enters the CMDB because it was purchased through a nonstandard channel. Two years later, an incident responder asks, “What’s the subnet for the field controllers?” and the organization discovers the real architecture is whatever the integrator left running. The speakers do not use that exact story, but their emphasis on inventory and stale diagrams maps directly to this recurring pattern.

Another technical undercurrent is third-party risk concentration in agriculture and water. Modern farming is not a standalone farm; it is a mesh of OEM telemetry, dealer support portals, supplier logistics, commodity markets, and seasonal labor systems. An attacker does not need to hack “the farm” in a movie sense if they can disrupt financing, inputs, logistics, or telemetry dependencies. Rose’s opening bank anecdote is doing conceptual work here: cyber risk in agriculture is not only about tractors; it is about the capital and data networks that make large-scale agriculture possible.

The nitrate thread is also a useful cyber-physical mental model even when no malicious actor is involved. Over-fertilization and under-hydration (as described) can worsen nitrate runoff and soil-surface accumulation. Cyber manipulation could, in principle, bias control loops toward unsafe states—pumps running incorrectly, schedules altered, chemical injection rates changed—turning process-control integrity into a public-health variable. The speakers are careful in the UK case to separate confirmed outcomes from actor claims, which is the correct engineering instinct: in incident response, you do not let an extortionist’s screenshot become your process safety truth without validation.

On the ML side of network detection (not the focus of this talk), the session instead highlights IR realities: unknown inventories, stale diagrams, shadow IT, and missing logs—failure modes that turn incidents into archaeology.

Hansen also discusses grey-zone warfare framing: adversaries treat cyber, IO, espionage, and sabotage as one playbook. The personal mitigation discussed is analog redundancy—paper maps when GPS might be targeted in escalated conflict—used as a metaphor for resilience planning, not as a specific intelligence forecast.

The Q&A segment widens the aperture further: a participant ties the discussion to hybrid conflict scenarios around Taiwan timelines mentioned elsewhere at the conference, port infrastructure risk, cold chain, and a MITRE-referenced unclassified exercise echoing Salt Typhoon-style complexity. Curtis and a second speaker (Paris, as named in the transcript) debate lead times for domestic food continuity, with Curtis suggesting 11 days of abundance may be optimistic versus 3–7 in an on-demand supply-chain framing—explicitly uncertain, but directionally aimed at encouraging local redundancy. This portion is speculative scenario talk, not a validated FEMA estimate; treat it as planning provocation, not a forecast.

Demo / Proof of Concept

▶ Watch: IR pragmatism: expanding attack surface post-COVID; inventories, shadow IT, M... (26:00)

No live cyber demo is performed. Rose references a BioISAC annual event demonstration (February) where a new combine was manipulated “from the stage,” described as concerning because it had not yet experienced the headline hacks affecting major brands—used as evidence that agricultural machinery attack surface is active and under-researched.

Defensive Implications

▶ Watch: Andrew Rose on personal continuity: food/water stockpiling basics, community ... (36:00)

For infrastructure owners: treat OT remote access as a policy decision, not a convenience feature. Default creds and internet exposure are recurring root causes in the stories told. Build asset inventory and network diagrams as living artifacts; IR teams repeatedly find incidents harder because these basics are false.

For IR programs: plan out-of-band communications, holiday coverage, and assumptions that collaboration tools may be down. Run tabletop exercises to build muscle memory; the speakers argue incidents are when and again, not if.

For information sharing: join sector ISACs (BioISAC explicitly pitched) to exchange IOCs and TTPs and to translate actor branding (Cl0p, Cyber Av3ngers) into management-ready context.

For resilience beyond bytes: the speakers advocate manual overrides and analog checks, citing Stuxnet as an example where purely electronic trust in instrumentation enabled physical consequences without human-visible sanity checks—used as a parable, not a reanalysis of Stuxnet mechanics.

For security economics: translate controls into business outcomes the operator understands—downtime hours, lost yield, missed planting windows, regulatory fines, and hospital surge costs—rather than abstract CVE counts. Curtis argues incident-driven ROI stories land better than generic hygiene sermons.

For education systems: the Estonia and North Dakota anecdotes are offered as models where societal cyber capacity is treated as infrastructure, not a hobby elective—relevant to long-term pipeline problems in rural utilities and agricultural technology support.

Key Takeaways

  • Bioeconomy risk spans agriculture, water, pharma, and genetics; food security is a cyber-adjacent problem because agriculture is automated, connected, and water-dependent.
  • Center pivots illustrate how remote control for productivity becomes remote attack surface for irrigation and chemical application.
  • Nitrates link agricultural practice, water quality, and pediatric hospital surge risk—cyber-physical effects can appear as public-health symptoms.
  • South Staffordshire case study highlights long extortion timelines and the need to parse actor claims about OT access carefully.
  • Cyber Av3ngers cases highlight lethal simplicity: internet-facing PLCs and default passwords still happen in US water environments.
  • Digital transformation increases exposure faster than cultural maturity; Estonia and North Dakota are offered as counterexamples of societal investment.
  • Personal preparedness is discussed bluntly (food storage, water capture, community ties) as complements—not replacements—for organizational security work.

About the Speaker(s)

Curtis Hansen represents Invictus Incident Response and states he became a BioISAC member in 2025. He presents incident-response experience and frames agricultural futures through climate and finance risk.

Andrew Rose speaks remotely for BioISAC, describing work on future threat modeling, multi-state tabletop exercises, and past national agriculture-community awareness efforts after discovering serious issues at a large agricultural finance institution. He references collaboration with a colleague named Josh for talk scope (water/agriculture/hospitals intersection). Whitney, a BioISAC co-founder, is noted as unable to attend.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A Calvary-style cross-sector briefing: strong OT case snapshots and IR realism, padded with personal preparedness monologue that’s memorable but not always tightly evidenced.

Heather Calloway (CISO) — STRONG ACCEPT

High-value for leaders owning critical infrastructure: it connects ransomware economics, OT exposure, third-party file-transfer risk, and hospital surge dynamics—then forces the boring basics (inventory, segmentation, tabletops) back onto the agenda.

→ Top-rated talks at BSides Las Vegas 2025

All talks from BSides Las Vegas 2025