Categories
Blogs

Malicious #Cyber Actors Targeting #Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions Malicious cyber actors are actively targeting U.S. water and wastewater systems https://share.google/aimode/wt0G6O5xV0Eo1aPZP Yes, the FBI, EPA, and CISA have issued urgent warnings following a massive surge in cyberattacks targeting U.S. water and wastewater systems. [1, 2, 3] A coordinated cyberattack hit more than 30 community water systems in Minnesota, prompti

Malicious  #Cyber Actors Targeting  #Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions —  #FBI  fbi.gov/news/press-releases/…
x.com/mikenov/status/2083132…
Malicious cyber actors are actively targeting U.S. water and wastewater systems
share.google/aimode/wt0G6O5x…
Yes, the FBI, EPA, and CISA have issued urgent warnings following a massive surge in cyberattacks targeting U.S. water and wastewater systems. [1, 2, 3]
A coordinated cyberattack hit more than 30 community water systems in Minnesota, prompting federal agencies to sound the alarm for utility companies nationwide. Investigators heavily suspect Iranian-affiliated threat actors are behind the campaign. This escalation builds directly upon ongoing warnings regarding hostile nation-state actors from Iran and China actively trying to compromise American critical infrastructure. [2, 4, 5, 6]

The Attack Vector: Target and Impact
Malicious hackers are directly scanning for and exploiting internet-exposed Operational Technology (OT) and Programmable Logic Controllers (PLCs). They are specifically targeting Rockwell Automation/Allen-Bradley (MicroLogix 1100 and 1400 series) devices. [1, 2, 3]
Once hackers locate an internet-facing controller, they execute the following disruptions:

Password and IP Lockouts: Hackers remotely alter the PLC passwords and IP addresses, completely locking out human operators.
Operational Disruption: The attacks have caused immediate physical issues, including sustained pressure loss and localized flooding.
Public Health Risks: Several targeted municipal systems have been forced to issue emergency boil water notices and rely on manual operations. [2, 3, 5, 7]

The vulnerability is largely driven by unmapped cellular modems or internet-connected process software installed by vendors that sit exposed without a firewall or multi-factor authentication. [3, 8]
Mandatory Defense Mandates for Water Utilities
The CISA Alerts and FBI Public Service Announcements require water systems of all sizes to execute immediate security protocols: [1, 3, 4]
Security ActionTechnical RequirementDisconnect PLCsImmediately remove all PLCs and OT devices from direct public-facing internet exposure.Enforce GatewaysForce all remote operational access to pass strictly through a secure VPN or gateway with Multi-Factor Authentication (MFA).Rotate CredentialsEliminate all manufacturer default passwords; implement complex, unique credentials.Toggle Physical ModePhysically set PLC hardware switches to “Run” mode to block unauthorized remote programming alterations.IP AllowlistingRestrict network access exclusively to known engineering laptops or trusted internal assets.Maintain Manual ResiliencyEnsure plant operators are fully trained and capable of running water treatment completely offline via manual operations if the digital network fails.

Are you looking to secure a specific model of water control systems? I can provide the technical indicators of compromise (IOCs) or help draft an incident response checklist for your team.
-Michael Novakhov (@mikenov)U.S. investigating whether Iran was behind cyberattack on Minnesota water systems – CBS News  cbsnews.com/news/us-investig…—  https://x.com/mikenov/status/2083132952448262190