Story Highlights • Officials from local municipalities say they were not targeted by cyberattacks over the weekend. • The cyberattacks targeted water systems and several of the local municipal water systems aren’t connected to the internet, meaning they could not be hacked in this way. • Some officials said they also take a number of precautions to prevent a successful cyberattack, including having secure passwords, firewalls, multi-factor authentication and monitoring for unusual activity in the system.
Municipalities in the area that provide water to residents were not targets of widespread cyberattacks that occurred over the weekend in multiple states, including Michigan.
Officials from Cadillac, Manton, Mesick, Lake City, Evart, Reed City, Marion, Buckley and Haring Township all said to the best of their knowledge, no attempt was made to hack into their water systems.
The Cadillac News reached out to the McBain department of public works and mayor to find out if hacking impacted the village’s water infrastructure but didn’t hear back by press time.
According to Associated Press reporting, Michigan on Saturday joined Minnesota in reporting cyberattacks on nine of the state’s water systems but an official said all systems were operating “safely.”
Earlier in the week, authorities said cyberattacks targeted over 30 water systems in Minnesota. The source of the attacks is being investigated, but they came amid warnings that Iranian hackers have been focused on such systems.
The reports in Michigan surfaced after the state received a federal cyber alert Tuesday about attempts to tamper with operational technology at water systems.
Soon after, the state received “a small number of reports from Michigan communities indicating activity consistent with what federal agencies described,” said Dale George, the director of communications at the state’s Department of Environment, Great Lakes, and Energy. He later said nine systems were impacted.
The FBI, which is investigating, has not publicly identified a culprit and a spokesperson declined to say Thursday who the bureau thought might be responsible. The FBI, Cybersecurity and Infrastructure Security Agency and other agencies warned in an advisory last week that Iranian hackers have been targeting water and wastewater systems and the operational controls of other critical infrastructure sectors.
Several municipal officials in this area said there’s no way a hacker from a remote location could gain access to their water systems because they’re not connected to the internet.
Mike Guernsey, water operator for Buckley, said he considered installing an internet-based system for the village’s new well house but ultimately decided against it.
A system being online allows operators to control certain components remotely using a device such as an iPad.
Guernsey said this would have made certain maintenance duties more convenient but he’s glad he decided against it.
“This is the perfect reason I probably never will (connect the system to the internet),” Guernsey said.
Rich Saladin, city manager for Reed City, said a hacker gaining access to a municipal water system could manipulate the water pressure and turn off pumps, which could impact homes and businesses that use a lot of water, such as factories.
Thomas Lutke, with Infrastructure Alternatives — the company that runs Haring Township’s municipal water system — said the internet-connected systems he’s familiar with don’t allow for chemical treatment levels to be controlled remotely.
“That still has to be done by hand,” said Lutke, who added that a hacker wouldn’t be able to overload a water system with chemicals to harm those who consume it.
Saladin said it’s still a concern for people, however, which is why they take a number of precautions to prevent a successful cyberattack from occurring, including having multiple firewalls in place, encrypting data and requiring multi-factor authentication for users.
Lutke, with Infrastructure Alternatives, said other measures they take to bolster security include having secure passwords for users and constantly monitoring the system for unusual activity.
“Just being vigilant is the best practice, I think,” Lutke said.
Click Here For The Original Source.
