What we know so far about the hacking campaign against US water systems | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Federal and state authorities are investigating a series of coordinated cyberattacks targeting drinking and wastewater treatment facilities across the U.S. Threat groups with suspected links to Iran have targeted vulnerable programmable logic controllers, the devices used to monitor and control various industrial systems, including those of water utilities. 

Utilities in at least 12 states were impacted by the attacks, including Minnesota, Michigan, Georgia, South Dakota and New Jersey. 

The first public discovery of the threat began in Minnesota, where more than 30 community water systems were targeted in a “coordinated attack” from July 26-27. Hackers hit PLCs as well as human machine interfaces, the dashboards for monitoring water levels or temperatures. 

Officials in South St. Paul, Plymouth, Maple Plain and Braham have confirmed they were attacked, but stated that water safety was not affected.

In Georgia, the Clayton County Water Authority said an attack on July 27 briefly disrupted its OT systems. Officials issued a boil water advisory and restored service within a few hours after testing confirmed the water supply was safe. 

Authorities in New Jersey responded to two confirmed cyber incidents in July and have been working with the affected utilities, along with the FBI and CISA. Both of the incidents involved vulnerable internet-exposed devices, which temporarily prevented operators from monitoring or managing them remotely. 

“In both cases, staff shifted quickly to manual operations, and there was no disruption to service,” a spokesperson for the NJ Office of Homeland Security and Preparedness told Cybersecurity Dive. “Customers had uninterrupted access to safe drinking water throughout.”

Vulnerable PLC devices

The attacks began days after CISA and the FBI issued a July warning about expanded targeting of vulnerable PLCs in the water and energy sectors. Hackers originally began targeting PLCs made by Rockwell Automation in the early weeks of the Iran war, and in recent months expanded their attacks to Schneider Electric and Siemens PLCs.

Rockwell Automation in March issued an updated warning about a legacy authentication bypass vulnerability tracked as CVE-2021-22681 in its Studio 5000 Logix Designer software. If exploited, the flaw could allow an attacker to use an unauthorized third-party tool to alter the configuration of a Logix controller. 

Among these newly targeted devices were the Schneider Electric BMX P34/Modicon M340 PLCs, as well as the Siemens S7-1200 series PLCs. U.S. authorities on Wednesday warned of a wider campaign of AI-enabled hackers targeting internet-exposed and out-of-service Siemens S7 series devices across multiple industries, including water. 

Hacktivist attacks

The threat against water systems is not a new phenomenon. Iran-nexus adversaries, for example, have been targeting water systems in Israel and the U.S. since the launch of the Gaza war in 2023. CyberAv3ngers, a group backed by the Islamic Revolutionary Guard Corps, targeted vulnerable Unitronics PLCs in multiple cyberattacks across the U.S.

The Biden administration engaged with state and local officials in an attempt to strengthen water utility security. A 2024 investigation by the EPA’s Office of Inspector General uncovered vulnerabilities in hundreds of water utilities across the country. 

Multiple initiatives were made to provide assistance to rural water systems, including DEF CON Franklin, which was supported by the National Rural Water Association and the University of Chicago.

Iran-linked attacks against water and energy systems ramped up earlier this year following the U.S. and Israeli bombing campaign in February. The FBI and CISA warned that the attacks led to operational disruption and financial losses. 

Authorities suspect Iran-nexus groups are behind the July attacks. However, questions emerged whether more than one group was involved: Minnesota officials called the attacks “coordinated” and said it was not clear whether all of the attacks were carried out by the same actor. 

Earlier this month, a group called APT Iran claimed credit for the Minnesota attacks, saying it was working with CyberAv3ngers, according to Check Point Research. The hackers made additional claims, saying they had access to power grids and telecommunications systems as well.



Click Here For The Original Source.

——————————————————–

..........

.

.