World News

Industry news and insights from Europe and around the World

UK News

Latest news and developments in the United Kingdom

Products

Keep up-to-date with the latest new products and technology

Features

General articles, applications and industry analysis

Hackers expose vulnerable refrigeration systems

UK: Controls manufacturer RDM says it will be contacting customers reminding them to set secure passwords after hackers revealed that hundreds of its systems are vulnerable to cyber attack.

Israeli hackers and activists from the Safety Detective research lab have exposed the extent to which users’ failure to change manufacturers’ default passwords have left thousands of refrigeration and air conditioning systems vulnerable.

Using Shodan, the search engine for internet-connected devices, the hackers uncovered a major security breach in systems manufactured by Glasgow-based controls manufacturer Resource Data Management (RDM).

These control systems are used by a wide range of companies and industries including hospitals and supermarket chains all over the world.

A basic scan is said to have revealed hundreds of installations in the UK, Australia, Israel, Germany, the Netherlands, Malaysia, Iceland, and many other countries around the world. Safety Detective argues that as each installation has dozens of machines under it, many thousands of units could be vulnerable.

The systems all use the unsecured HTTP protocol and the 9000 port (or sometimes 8080, 8100, or even simply 80) and use the default username and password combination. The hackers say that not only can you change refrigerator and freezer settings through this system, you can also modify user settings, alarm settings, and more.

Sites exposed included a UK Marks and Spencer supermarket in Surrey, Italian food manufacturer Menu Italiano, one of the largest pharmaceutical company in Malaysia, a coldstore in Dusseldorf, and a food storage facility in Iceland.

RDM insists that its controls documentation states that the default passwords must be changed when the system is installed, and argues that it has no control over how its systems are set up by the installer. However, it said it would write to all its known customers, installers and distributors reminding them of the importance of changing the default user names and passwords as part of their installation and set up.

Concerns

Concerns over the vulnerability to the increasing numbers of internet-connected devices prompted European manufacturers’ group ASERCOM to publish a free-to-download guide to securing components against the threat of cyber-attacks.

Last month the Cooling Post revealed that a Dutch man had received a prison sentence for hacking into a supermarket refrigeration system and changing the temperature settings. 

Related stories:

ASERCOM guide to cybersecurity24 October 2018
GERMANY: ASERCOM has published a free-to-download guide to securing components against the threat of cyber-attacks. Read more…

Man jailed for supermarket refrigeration hack27 January 2019
NETHERLANDS: A Dutchman has been sentenced to four months prison after hacking into a supermarket refrigeration system. Read more…

Latest News

1st April 2026

US manufacturers face price-fixing lawsuit

USA: Leading US residential and commercial air conditioning manufacturers have been accused of price fixing and overcharging in a civil antitrust action.
1st April 2026

A-Gas to sponsor Milan data centre event

ITALY: Refrigerant supplier and management company A-Gas is to attend Data Center Nation (DCN) in Milan as a gold sponsor.
1st April 2026

Panasonic provides an edge in HVAC control

UK: Panasonic Heating & Cooling Solutions Europe has announced Commercial Smart Edge, described as a next generation tool for secure, unified and scalable HVAC management across commercial buildings. 
1st April 2026

Abstracts invited for ASHRAE conference

USA: Abstract submissions are now being accepted for next year’s ASHRAE Winter Conference to be held in Chicago, Illinois, from January 23 – 27, 2027.
1st April 2026

Star prank is virtually real

UK: Star Refrigeration created a stir today, April 1, with the announcement of the launch of StarCore, the world’s first AI-powered robot maintenance engineer. 
1st April 2026

Panasonic merges HVAC and cold chain businesses

JAPAN: Panasonic has combined its Air Quality & Air Conditioning Company and Cold Chain Solutions business, to establish a new company, Panasonic HVAC & CC Corporation.