CISA Releases Guidance Urging Water Treatment Facilities to Disconnect Equipment From the Internet
CISA released an urgent message warning water utilities to disconnect their logic controllers from the internet in the face of rising cyberattacks.
In what CNN described as "one of the most serious cyberattacks on water systems in the US in years," water treatment facilities in seven US states have been hit with a coordinated wave of attacks suspected to be perpetrated by Iran.
The suspected goal of the cyberattacks was "to cause loss of system pressure and subsequent potential contamination of water supply," according to a memo from the Minnesota Bureau of Criminal Apprehension obtained by CNN in the same article.
No known instances of water contamination have been reported so far.
The hacks target internet-facing programmable logic controllers (PLCs) that control equipment and allow machinery to communicate. They monitor and control the water pressure, chemical dosing, and other factors to ensure the water is safe.
Many of the PLCs are apparently open to the internet and use default credentials, allowing a remote attacker to easily take them over.
The hackers have been locking out operators by logging in and changing the credentials and IP address of the PLCs.
CISA says the threat actors are "targeting water entities of all sizes." They warn that all water and wastewater treatment facilities should check for all external connections, including undocumented cellular modems installed by operators, vendors, or system integrators, since all external connections are a potential risk.
The specific advice they give is to disconnect all PLCs and only access them through a VPN, enable password protection and change the default passwords, and only allow IPs from known engineering laptops and other critical assets.
What's alarming is that it's apparently so common for water utilities to use no password or default passwords that they could give this advice in a general notice to all water utilities. Potentially the chips that control water for millions of Americans were left with no password accessible on the open internet like an old router or webcam.
It seems that many utilities that we rely on every day are simply not equipped to deal with even the most basic cyber threat. Previous cyberattacks like Volt Typhoon should have been a lesson that we need to shore up the security of public utilities, but nothing seems to change even as this keeps happening over and over.
Perhaps the best course of action is to keep these systems fully offline if they can't be secure managed remotely.
Community Discussion