CISA warns of cyberattacks disrupting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector.
The agency's urgent alert comes after hackers disrupted more than 30 community water systems in Minnesota in attacks that started last Sunday and continued through Monday.
CISA's alert refers to threat activity involved hackers targeting exposed programmable logic controllers (PLC) and changing passwords to lock operators out, modifying IP addresses to disconnect devices from the internet, and other actions that disrupted operations.
"CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."
Organizations of all sizes running water and wastewater systems are being targeted, including some with mature cybersecurity programs.
The bulletin notes that exposed operational technology (OT) may include undocumented cellular modems installed by operators, vendors, or system integrators.
Internet-facing assets are exposed to defacement attacks, configuration changes, operational disruptions, and even physical damage, the agency said.
CISA recommends immediately removing these assets from direct internet exposure. If this is not possible, organizations should use a VPN connection or gateway devices for secure access.
Additionally, default passwords should be changed, and access should be limited to an IP address allow-list.
The agency also pointed owners of Rockwell Automation MicroLogix 1400 PLCs to vendor guidance for recovering access if passwords have been changed.
Cybersecurity search company Censys published a blog post where it quantifies internet exposure, estimating that currently there are more than 4,100 internet-exposed Rockwell Automation/Allen-Bradley hosts, 4,100 Siemens hosts, and over 2,000 Schneider Electric hosts.
Exposure map for Rockwell/Allen-Bradley PLCsSource: Censys
However, it should be clarified that the map above shows devices reachable over the public internet, not systems that are necessarily being targeted or compromised.
Regarding the MicroLogix 1400 controllers mentioned in CISA's bulletin, Censys notes that many appear to be running EoS (end-of-sale) firmware versions.
The cybersecurity company also highlighted the problem of undocumented cellular modems as a common blind spot, reporting that nearly half of the exposed Rockwell devices are reachable via Verizon Business, AT&T, T-Mobile, Comcast, Charter, and Starlink networks.
ASNs hosting internet-exposed Rockwell/Allen-Bradley PLCsSource: Censys
Censys also provided an expanded set of indicators of compromise (IoCs) in its report, along with threat-hunting guidance.
Earlier this week, the Minnesota IT Services (MNIT) agency activated the state's cybersecurity incident response plan after identifying what it described as "a coordinated cyberattack targeting operational technology at more than 30 Minnesota community water systems."
Multiple municipalities reported disruptions caused by the cyberattack, with equipment malfunctions forcing some utilities to temporarily switch to manual operations.
MNIT has shared threat intelligence collected from the affected systems and provided guidance and best practices to help impacted utilities restore normal operations.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0


Comments (0)