FBI: Hackers Targeted Water Utility Providers in at Least 7 States | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


The FBI indicates that a growing number of water systems in the US have been fending off cyberattacks aimed at disrupting their operations.  

The incidents began on Monday and involved water and wastewater utility companies in at least seven US states. “Some of that activity degraded water operations,” the agency said in a Thursday alert with the Environmental Protection Agency. 

The alert arrives after Minnesota reported a “coordinated cyberattack” targeting more than 30 community water systems on Sunday into Monday. The FBI’s advisory shows the hacking attempts have been much wider in scope. 

The agency warns that hackers have been exploiting programmable logic controllers (PLCs), or specialized computers used to control industrial systems, specifically the MicroLogix 1100 and 1400 series from Rockwell Automation/Allen-Bradley. Hackers are targeting internet-exposed PLCs and then changing device configurations, such as the IP addresses and passwords. This can block a utility provider from monitoring and controlling its water system. 

“Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated groundwater to seep into pipes,” the alert adds. In response, the FBI and EPA are urging affected companies to disconnect their PLCs from the public-facing internet, implement firewall rules, and ensure their IT systems are secured with complex, unique passwords. 

On Thursday, Minnesota officials said they’re continuing to investigate the breach of its water systems, which also involved hackers tampering with PLCs and computer screen operators. “State agencies are working directly with impacted water systems to contain the activity, assess potential impacts, restore normal operations, and reduce the risk of further disruption.”

Recommended by Our Editors

US officials reportedly suspect that Iran was behind the attack in Minnesota, but for now, the state says it “has not attributed the activity to a specific actor.” In April, the FBI and NSA warned that Iranian hackers were working to exploit vulnerable PLCs from Rockwell Automation.

The water system intrusions occur amid renewed military strikes between the US and Iran. Other hacks earlier this year, including an intrusion into the personal Gmail account of FBI Director Kash Patel, have also been blamed on Iran.

About Our Expert





Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW