How local water providers are responding to recent nationwide cybersecurity threats | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Water providers across Tennessee are stepping up efforts to prevent cybersecurity threats after federal officials reported attempts to hack into water systems in other states. METRO

In a time of rapid technological advancements, cybersecurity has become increasingly more important after Tennessee water companies were put on high alert between late July and early August following a series of incidents affecting facilities in at least 12 states.

The Federal Bureau of Investigation (FBI) and the Environmental Protection Agency issued a public service announcement on July 30, warning the Water and Wastewater System sector to stay vigilant against “malicious cyber actors.” The notice came after authorities in Minnesota disclosed more than 30 water systems across the state had been attacked by hackers between July 26-27. Similar reports were made to the FBI in several other states over the following days. 

According to the release, hackers targeted publicly exposed programmable logic controllers (PLCs), modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses, resulting in a loss of monitoring and, in some cases, control of connected equipment.

The release went on to detail that at least one organization reported modified PLC project files after noticing discrepancies across several sites. Several third-party facilities with similar network setups were also noted to be subject to cybersecurity threats.

Reported operational effects included loss of pressure, which could potentially allow untreated groundwater to seep into the pipes, and flooding.

While agencies have been reluctant to attribute these threats to ongoing conflict with Iran, similar cyberattacks were carried out in 2023 and 2024 by a group known as the CyberAv3ngers, who are associated with the Islamic Revolutionary Guard Corps’ (IRGC), according to the U.S. government.

The group denied involvement in recent attacks in a public statement published on their Telegram channel, calling the claims “propaganda.”

The Tennessee Department of Environment and Conservation (TDEC) sent an email to local wastewater treatment plants on July 31, alerting them of an increase in cybersecurity threats targeting water entities of all sizes. A follow-up email was sent on Aug. 3 as the number of incidents continued to rise.

The FBI declined to comment on whether or not a Tennessee facility was attacked during this time.

Nashville’s Metro Water Services said that their employees are trained to recognize potential attempts to access systems before, during and after the event, but did not specify what those steps are for security purposes.

The City of Murfreesboro Water Resources Department also broadly said that precautions to combat potential attacks are part of regular security measures.

Columbia Power and Water Systems (CPWS) assured customers that their water supply is safe and that the integrity of the community’s drinking water is their highest priority, as they continuously evaluate and test operational security systems.

“As a multi-utility provider, owning and operating our own private communication infrastructure gives us an added layer of defense and isolation that many water systems do not have. We remain vigilant and committed to protecting the essential services our community relies on every day,” CPWS CEO Jack Baxter told Main Street Media of Tennessee.

The Water Authority of Dickson County also said its water treatment facilities were unaffected during this time because they do not use internet-connected operational technology.

“WADC has a thorough organization-wide cybersecurity plan in place to provide protection of the utility’s facilities from unauthorized use, alteration, ransom or destruction of electronic data,” WADC CEO Scott Miller said.

According to Miller, WADC partners with a vendor specializing in IT and cybersecurity. He said they are also enrolled in a program with the U.S. Department of Homeland Security that continuously assesses the health of their internet-accessible assets.

——————————————————-


Click Here For The Original Source.