Water systems in at least a dozen US states have been affected in a series of cyber incidents. Security experts warn this could be the first of a pending wave of attacks on critical infrastructure.So far, Minnesota appears to have been hardest-hit, with more than 30 community water systems impacted. The attacks have resulted in drops in water pressure and advice to boil water, although no contamination has been detected.The attacks target internet-exposed programmable logic controllers (PLCs) – Rockwell Automation/Allen-Bradley’s MicroLogix 1100 and 1400 series.The attackers remotely tamper with device configurations by changing IP addresses and turning on and setting passwords, leaving the water firms unable to view connected equipment, and in some cases shutting it down.”These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans,” the US Cybersecurity and Infrastructure Security Agency (CISA) warned. “OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage.”The attacks have been widely attributed to Iran. However, Martin Riley, chief technology officer at Bridewell, said attribution is the “least interesting part of this story”. “Whether the activity traces back to Iranian-aligned actors, a hacktivist crew reusing a commodity scanner, or an opportunist, the precondition is identical. A Rockwell Automation/Allen-Bradley MicroLogix 1100 or 1400 sat on a public IP address with its management interface exposed, and in many cases credentials that were never changed from the shipped default.”According to the National Association of Water Companies (NAWC), while more than 90% of its members have comprehensive cybersecurity plans in place, many are missing even basic protections.They lack continuous OT monitoring, centralized logging, accurate asset inventories, and dedicated cyber staff. This means that unauthorized access, credential testing, configuration changes, and reconnaissance could fly under the radar unless they produce visible disruption.Fresh critical infrastructure attacks could comeThere are fears that the same techniques could be used against other critical infrastructure. CISA is advising not only water firms, but all critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible. Kevin Kirkwood, CISO at Exabeam, said that weaknesses exploited in water systems “are not unique to water” and pose risks across a range of other industries. “Exposed controllers, default credentials, insecure remote access, aging equipment, weak IT-OT segmentation, and understaffed operations also exist across electric utilities, pipelines, manufacturing, transportation, and building-control systems,” he commented.”The most troubling possibility is that these water-system attacks are not the end state, but a test case. They allow adversaries to map networks, identify vendors, measure response times, study manual operating procedures, and determine how quickly federal and state authorities react. Water may be the proving ground. Power and other OT-heavy sectors may be the intended scale.”FOLLOW US ON SOCIAL MEDIA

Belarusian cybercriminal behind Ransom Cartel gets 16-year prison sentence – The Record from Recorded Future News
Belarusian cybercriminal behind Ransom Cartel gets 16-year prison sentence The Record from Recorded Future News


