Water Utilities in Seven States Report Cybersecurity Breaches Affecting PLCs

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Recent cybersecurity incidents involving Internet-facing programmable logic controllers (PLCs) have been reported by water and wastewater utilities in at least seven states, as highlighted by the FBI and the Environmental Protection Agency (EPA). These incidents, which began on July 27, have seen malicious actors remotely accessing PLCs, including models from Rockwell Automation/Allen-Bradley, leading to changes in device IP addresses and passwords. This has resulted in temporary loss of monitoring and control functions at some facilities, raising significant concerns for cybersecurity decision-makers in critical infrastructure sectors. For further details, refer to the report by GovTech.

Nature of the Cyber Incidents

The reported incidents have caused operational impacts such as pressure loss and flooding, with the potential for untreated groundwater to seep into pipes. The extent of these impacts varies based on the configuration of the PLCs and the ability of utilities to switch affected systems to manual operation. The FBI and EPA have detailed that attackers gain remote access to these PLCs, subsequently altering IP addresses and passwords, effectively locking utilities out of their monitoring and control functions.

Specific Cases in Minnesota

In Minnesota, officials have confirmed that at least 30 community water systems were targeted by malicious cyber activity, prompting an ongoing investigation. While the Minnesota IT Services (MNIT) noted similarities among the attacks, they have not yet attributed them to a specific actor. Importantly, the affected systems have not resulted in water service disruptions, and no public health risks have been reported from these incidents.

Recommendations for Utilities

In light of these incidents, MNIT has issued recommendations that align closely with guidance from the FBI and EPA. Utilities are urged to identify and secure Internet-accessible operational technology, including PLCs and human-machine interfaces. Key recommendations include:

  • Removing unnecessary Internet access
  • Strengthening access controls and passwords
  • Implementing multifactor authentication
  • Reviewing logs and configurations
  • Separating operational technology from other networks
  • Maintaining accurate inventories and offline backups
  • Testing incident-response and recovery plans

Ongoing Threat Landscape

The incidents come amid warnings from the Cybersecurity and Infrastructure Security Agency (CISA) and its federal partners about the attractiveness of Internet-connected industrial control systems to malicious actors. An advisory updated on July 22 indicated that Iranian-affiliated attackers have exploited PLCs across various sectors of U.S. critical infrastructure. However, Minnesota officials have not linked the recent incidents to any specific threat actor.

As the cybersecurity landscape continues to evolve, it is crucial for utilities to remain vigilant and proactive in securing their operational technology against potential cyber threats.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Cybercriminals Leak Grand Theft Auto VI Footage, Prompting Legal Action from Take-Two Interactive

Grand Theft Auto VI, anticipated as the game event of the decade, faced a major setback last week when a cybercriminal leaked gameplay footage...

Cybersecurity Patch Window Collapses, Urging New Control Strategies for Risk Management

For decades, cybersecurity defenders have relied on a straightforward model: when a vulnerability is disclosed, security teams assess exposure, test fixes, deploy patches, and...

Tehran-linked hackers shut down UK power plant in recent cyber attack

A recent cyber attack attributed to hackers linked to the Iranian regime has resulted in the shutdown of a small power plant in the...

AI-Enabled Malware Analysis Reveals 97% Remains in Research Environments, with Limited Production Activity

AI-Enabled Malware Analysis: Limited Production Activity Observed Research conducted by Palo Alto Networks reveals that while AI-enabled malware is a growing concern, approximately 97% of...