Oil companies hit by cyber attacks
The Christian Science Monitor goes into more detail on the story, including descriptions of the "phishing" and "spear phishing" techniques the infiltrators used to gain access. It also says that the companies didn't understand the depth of the attacks until the FBI filled them in.
While the hackers seemed to stay in what we would consider to be IT networks, those places can be the jumping-off point for attacks on SCADA and plant control systems. Moving into the next part of the network is much easier when the hackers are working from an established beach head.
You can find many cyber security resources at Control Engineering's Website, including a podcast with Ed Skoudis who was interviewed in the Christian Science Monitor story.
See the whole podcast catalog.
Read the Control Engineering industrial control system cyber security blog.

