Cyberattacks have reportedly targeted municipal water systems in at least seven states over the past week.
The activity led the FBI and the Environmental Protection Agency to warn utilities nationwide that hackers are trying to disrupt critical water infrastructure. All water systems are reported to be operating safely.
Earlier this week, authorities said cyberattacks targeted over 30 water systems in Minnesota. The source of the attacks is being investigated, but they came amid warnings that Iranian hackers have been focused on such systems.The reports in Michigan surfaced after the state received a federal cyber alert Tuesday about attempts to tamper with operational technology at water systems.Soon after, the state received “a small number of reports from Michigan communities indicating activity consistent with what federal agencies described,” said Dale George, the director of communications at the state’s Department of Environment, Great Lakes, and Energy. He later said nine systems were impacted.“All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern,” George said in an statement.
According to one official, the attack had the “hallmarks of Iranian meddling”.
In a public service announcement Thursday, the agencies said water and wastewater utilities have reported incidents to the FBI, with some malicious activity degrading water operations. The announcement does not name the states.The warning comes after hackers targeted more than 30 municipal water facilities in Minnesota in an attack that had hallmarks of Iranian meddling, according to a law enforcement official. It is still under investigation….Thursday’s federal advisory said the malicious cyber actors, or MCAs, targeted specific brands of control systems used by municipal water utilities, though the FBI and the EPA urged operators of all systems to take precautions.Earlier this week, the Wisconsin Department of Natural Resources issued a bulletin to water contacts in the state, saying intelligence officials believed that “systems within Wisconsin may be susceptible to connections from malicious cyber actors.”
The attacks are targeting internet-exposed industrial controllers.
The FBI, Environmental Protection Agency and CISA all warned Thursday that attackers are targeting internet-exposed industrial controllers used by water and wastewater utilities.In at least some cases, federal authorities reported loss of monitoring and control functionality at critical infrastructure sites, leading to pressure loss and flooding.Most confirmed cases in the Minnesota cyberattack involved technology used to remotely monitor and control water system equipment, including devices called programmable logic controllers, according to Minnesota IT Services….Nick Anderson, acting director of CISA, confirmed that the agency “is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLC) at water utilities.”
As investigators work to identify the source of these attacks, the incidents are a much-needed reminder that water systems are now a frontline target in cyberspace.
Utilities will need to move quickly to harden internet-facing controls and tighten monitoring to reduce the risk of similar disruptions… and maybe begin making arrangements for options to return to more traditional technologies that are less exposed to cyberspace. Sometimes, the old ways are the best ways.
Just as important, federal and local partners must use what they learn from this investigation to strengthen defenses before a more serious attack can take hold.
CLICK HERE FOR FULL VERSION OF THIS STORY