Following cyberattacks targeting more than 30 municipal water systems across Minnesota, the FBI and EPA have issued a warning to critical infrastructure asset owners and operators that malicious actors are targeting operational technology devices used in water and wastewater facilities.

Since July 27, water and wastewater companies in seven states have reported incidents to the FBI, some of them causing a degradation of service, the agencies said in a public service announcement.

Operational effects reported to the FBI have included loss of pressure and flooding, the announcement added. Pressure loss in water systems could potentially allow untreated groundwater to seep into pipes, it explained.

A primary target is Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), particularly the MicroLogix 1100 and 1400 series. When those PLCs are exposed to the internet, attackers can remotely tamper with the devices’ configurations.

Once the attackers have access to a PLC, they can change its IP address and password, resulting in a loss of view and, in some cases, function of connected equipment in targeted facilities. The FBI also reported that one organization discovered modified PLC project files after identifying ladder logic discrepancies at multiple sites.

Growing Trend

Attacks on water and wastewater facilities appear to be a growing trend. “The American public needs to be aware of, not fearful of, cyberattacks that can impact their daily lives,” observed Andrew Chipman, director of GRC and ISO at ProCircular, a cybersecurity consulting firm in Coralville, Iowa.

“Water, power, internet — these things are increasingly under attack from foreign nation states, ideologically aligned cybercriminals and activists,” he told TechNewsWorld. “The reason is that they are easy targets — rarely secured appropriately — and cause a big impact to affected cities.”

In addition, he noted, “PLCs are notoriously hard to patch and are not supported by manufacturers with frequent enough updates.”

PLCs attract attackers because they directly control physical processes, allowing cyberattacks to produce real-world consequences, such as service disruptions or equipment damage, explained David Kertai, a research assistant with the Information Technology & Innovation Foundation (ITIF), a science and technology think tank in Washington, D.C.

“Many water and wastewater facilities still rely on legacy PLCs designed for reliability rather than cybersecurity,” he told TechNewsWorld. “These systems often lack strong authentication, encryption and modern access controls, making them attractive entry points for adversaries.”

Change in Tactics

Kertai noted that attacks targeting critical infrastructure have increased as adversaries recognize that many water and wastewater systems still rely on aging technology and often have limited cybersecurity resources.

“Utilities have adopted digital tools for remote monitoring, automation and operational efficiency, improving performance while expanding the number of systems that require protection,” he explained. “Many facilities continue to operate legacy equipment that was not designed to withstand today’s cyberthreats, creating opportunities for both nation-state actors and cybercriminals.”

The OT and ICS threat environment has crossed a threshold, contended James Maude, a field CTO at BeyondTrust, maker of privileged account management and vulnerability management solutions in Carlsbad, Calif.

“Last year, multiple threat groups moved past reconnaissance into actively mapping industrial control systems to understand how physical effects can be induced,” he told TechNewsWorld. “We are also seeing ransomware groups take a significant interest in OT environments and begin to specialize.”

“It’s not just the number of threat actors that is going up,” he said, “the sophistication of the attacks is also increasing.”

“Under-resourced municipal utilities have become recurring targets for cyber adversaries because they provide an opportunity to disrupt essential services and expose systemic weaknesses,” added Matthew Hartman, chief strategy officer for the Merlin Group, a Tysons Corner, Va.-based network of affiliates that invests in, enables, and scales cyber technology companies.

“Every disruption like this chips away at public trust, which is exactly why operational resiliency has to reach the communities that need it most,” he told TechNewsWorld.

A change in the tactics of malicious actors is also contributing to the rise in attacks on critical infrastructure. “The attacks are becoming repeatable,” observed Harry Thomas, CTO and co-founder of Frenos, a provider of a security assessment and penetration testing platform for critical infrastructure and industrial environments, in Charlotte, N.C.

“Internet-connected PLCs, cellular modems, and standardized third-party configurations give attackers similar paths into multiple utilities,” he told TechNewsWorld. “One successful method can be reused without developing a unique attack for every facility.”

Protection Tips

The FBI and EPA recommended several steps for protecting water and wastewater systems from cyberattacks. They include:

  • Disconnecting PLCs from the public-facing internet;
  • Ensuring device passwords are complex, unique combinations of letters, numbers, and symbols;
  • Strictly controlling network access to PLC devices;
  • Placing physical and software key switches into the run position to block unauthorized changes to logic, configuration and firmware;
  • Practicing and maintaining the ability to operate OT systems manually;
  • Reviewing project files running on PLCs for unauthorized changes; and
  • Planning for end-of-life replacements when possible.

Strong Foundation

The ITIF’s Kertai noted that the FBI’s and EPA’s recommendations provide a strong foundation for improving cybersecurity across water and wastewater systems. “Strengthening password policies, segmenting networks, restricting remote access, and training operators to maintain manual operations all reduce risk while improving resilience,” he said.

“The guidance also emphasizes replacing outdated hardware, which remains one of the sector’s greatest vulnerabilities,” he added. “Combined with sustained investment in modernization, these recommendations give utilities a practical, risk-based roadmap for strengthening cybersecurity.”

“They made some good recommendations, but did not go nearly far enough,” asserted Bill Moore, CEO and founder of Xona, a provider of secure remote access for critical infrastructure, in Hanover, Md.

“They are not prescriptive about what is needed most,” he told TechNewsWorld. “For example, communication protocols such as web and VNC should not tunnel outside the critical network.”

“Everything stated as recommendations has been recommended by security professionals for years, if not decades,” added Dahvid Schloss, COO of Suzu Labs, provider of AI-powered cybersecurity services in Las Vegas.

“If this is what gets organizations to listen, then so be it,” he told TechNewsWorld, “but there is a reason why many of us have been pounding the book for so long.”

Critical to Infrastructure Resilience

Schloss maintained that the public should be very concerned about these kinds of cyberattacks.

“That being said,” he continued, “these attacks aren’t anything new and have been a common point of interest for nation-states as they try to position themselves in the greater game of geopolitics.”

“The reason why the public should be concerned is that disruption of public services like water, power, gas, or other utilities can cause far more and longer-term damage than typical forms of kinetic aggression,” he said, “while also providing potential mis- or even non-attribution of the originating actor.”

A key takeaway is that PLC security is no longer solely an operational concern, added the ITIF’s Kertai.

“It is a critical component of infrastructure resilience,” he asserted. “Water systems support essential public services and economic activity, so disruptions can have consequences far beyond a single utility.”

“Many operators need sustained investment, workforce development and technology modernization to keep pace with evolving cyberthreats,” he continued. “Strengthening collaboration among utilities, technology providers and federal agencies will be just as important as deploying new cybersecurity tools.”

“Treating cybersecurity as a core part of infrastructure modernization, rather than an optional upgrade, will better position the sector to address future threats,” he said.

Read the full article here

Share.
Leave A Reply

Exit mobile version