site banner

The latest in industrial sabotage: geofenced passenger trains that fail when repaired in competitors' yards

badcyber.com

Some were also rigged to fail after a certain date or beyond a certain mileage.

20
Jump in the discussion.

No email address required.

special "command movement to slip in the back door"

Me to my patients when it's time to do a PR

The repair stuff could make sense if they are liable for something like catastrophic failures

this contract was intentionally constructed to decouple servicing overhaul and train construction, with manufacturer obligated to provide full servicing documentation

they lied, sabotaged train and tried to sabotage companies competing for servicing overhaul tender

they were caught by hackers hired by one such sabotaged company (with first hard proof delivered 43 minutes before servicing contract would be broken by train company)

Newag continues to lie and try to blame others.

but it could also be at least partially a mistake or ineptitude on the part of Newag

Yes, and there are indicators of this. But none of them reduce that all this is nefarious and hopefully illegal.

Trains were programmed to falsely report being broken down after specific date, or after specific number of mileage or after being repaired at repair yards run by competition.

This was not documented, Newag lied about it when asked and continues to lie.

Newag was nefariously sabotaging competition.

Is this a generalised system or tailor-made for each train/competitor?

Newag claims that this system does not exist, and if exist it was added by competition and it is not their fault.

Obviously, competition sabotaging repair service done not be Newag seems quite unlikely. Not sure why they went with this idea.

That might be possible but it's not stated anywhere in the article.

it was in some later articles, including some Polish ones and their PR releases

https://www.newag.pl/wp-content/uploads/2023/12/Oswiadczenie-NEWAG-06.12.2023.pdf

They are claiming they never introduced software that simulated failures and if it existed it was added by competition.

They demand withdrawal from service trains that were analysed, threaten legal action against SPS and people who analysed software.

they failed to communicate what this security system was

it was a not a security system

https://youtube.com/watch?v=XrlrbfGZo2k CCC publication is making situation quite clear, even if they do not take final step (because it is not fully 100% provable and they will likely end as witnesses in court cases, and what is clearly provable is damming anyway)

spicier bits include Newag making software changes to specific trains, two/three days before being send to be repaired at workshop of their competition ( https://youtube.com/watch?v=XrlrbfGZo2k&t=2369 ), not mentioning software updates in paperwork, train predicted to break down at specific date (due to bug in sabotage code) and then doing this...

overall great presentation, though quite technical (presented at hacking conference)

...

"illicit" repairs at normal repair businesses? Might as well shut down the train if it's at the newag yard, could be some illicit activity going on there too.

This contract was intentionally constructed to decouple servicing overhaul and train construction, with manufacturer obligated to provide full servicing documentation.

Repairs done at repair yards of competition were NOT illicit, Newag lost bid for overhaul.

The repair stuff could make sense if they are liable for something like catastrophic failures, you really wouldn't want a someone else cheaping our on a repair in that case.

This can be rectified by entering a clause in the contract that if the train ever gets repaired by someone else they then become liable for all future failures etc., it's not even a big issue as the tender for repairs can include a term that the repairer takes upon themselves liability if any of the parts they repair later malfunctions and they bidders can price in the cost of this liability into their bids.

I want to understand more about what you're working with/where you're coming from.

shoddy black market repairs

As someone born in Poland with dual citizenship and spends 3 months of the year there on average, Poles execute the finest black market repairs in the world. There is a very high level of technical education left over from the communist era with a healthy disrespect for authority, also left over from the communist era. If I was going to have anything illegally repaired, I'd do it in Poland. (until recently Ukraine would have been #2, now I think its Czechia, maybe Slovenia)

...

This contract was intentionally constructed to decouple servicing overhaul and train construction, with manufacturer obligated to provide full servicing documentation.

Repairs done at repair yards of competition were NOT illicit, Newag lost bid for overhaul.