Dive Brief:
-
Malicious cyber actors have targeted programmable logic controllers in water and wastewater systems in at least seven states, and some of the cyberattacks “have degraded water operations,” the Federal Bureau of Investigation said in a July 30 announcement.
-
Minnesota state, local and federal officials responded to “malicious cyber activity targeting technology at more than 30 community water systems across Minnesota,” Minnesota IT Services announced Thursday. Michigan on Saturday reported cyberattacks on nine of the state’s water systems but said all were working safely, multiple news outlets reported. Authorities did not identify the other states involved in the cyberattacks.
- The FBI and the Cybersecurity and Infrastructure Security Agency are recommending that water organizations disconnect PLCs from the internet, enable password protection and limit remote access.
Dive Insight:
CISA warned in a July 22 advisory of “ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices,” including PLCs, “resulting in operational disruption and financial loss.”
The water utility attackers remotely accessed internet-facing devices and changed IP addresses and passwords, resulting in a loss of monitoring and control functionality, according to the FBI announcement. The attackers last week targeted Rockwell Automation/AllenBradley PLCs, the FBI stated, but “similar considerations should also be made with other branded PLCs.”
CISA is urging critical infrastructure owners, operators and integrators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible. “These threat actors are targeting water entities of all sizes,” it said in a July 30 alert. “Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans.”
Water systems are particularly vulnerable to cyberattacks because the sector is so fragmented, Sean Tufts, field chief technology officer, industrial, for cybersecurity firm Claroty, said in an email. “Minnesota has fewer than 100 electric utilities, but more than 1,000 water systems supporting roughly five million residents. Many of those systems operate with small teams and tight budgets, which creates exactly the kind of uneven security environment attackers look for.”
The incident stands out because attackers targeted more than 30 systems at once, indicating “a shared dependency, whether it is a common technology, service provider or broader state-level IT backbone,” Tufts said.
The attacks on Rockwell PLCs in Minnesota should create urgency beyond the state, he added, because Rockwell controllers “are used across critical infrastructure and have increasingly become points of entry since the conflict with Iran kicked off.”