The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector.
The agency's urgent alert comes after hackers disrupted more than 30 community water systems in Minnesota in attacks that started last Sunday and continued through Monday.
CISA's alert refers to threat activity involved hackers targeting exposed programmable logic controllers (PLC) and changing passwords to lock operators out, modifying IP addresses to disconnect devices from the internet, and other actions that disrupted operations.
"CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible."
Organizations of all sizes running water and wastewater systems are being targeted, including some with mature cybersecurity programs.
The bulletin notes that exposed operational technology (OT) may include undocumented cellular modems installed by operators, vendors, or system integrators.
Internet-facing assets are exposed to defacement attacks, configuration changes, operational disruptions, and even physical damage, the agency said.
CISA recommends immediately removing these assets from direct internet exposure. If this is not possible, organizations should use a VPN connection or gateway devices for secure access.
Additionally, default passwords should be changed, and access should be limited to an IP address allow-list.
The agency also pointed owners of Rockwell Automation MicroLogix 1400 PLCs to vendor guidance for recovering access if passwords have been changed.
... continue reading