US Cyber Agency Warns of Widespread Water and Wastewater Hacks
- The number of affected systems provides new context to the scale of the ongoing cyberattacks targeting water providers in Michigan, Min
- The federal agency, which oversees cybersecurity defense and critical infrastructure protections, shared in an advisory that the attack
- In recent weeks, hackers have targeted PLCs made CISA previously shared that the cyberattacks are relying in part on AI tools that rely
The number of affected systems provides new context to the scale of the ongoing cyberattacks targeting water providers in Michigan, Minnesota, and at least five other states.
The federal agency, which oversees cybersecurity defense and critical infrastructure protections, shared in an advisory that the attacks have largely targeted programmable logic controllers (PLCs), which are used to control physical systems and machinery across water providers, energy systems, and other parts of critical infrastructure. For related coverage, explore our detailed analysis on Technology and Digital Systems.
Recent Weeks Hackers Targeted Updates
In recent weeks, hackers have targeted PLCs made CISA previously shared that the cyberattacks are relying in part on AI tools that rely on public information to develop scripts capable of targeting vulnerable Siemens PLCs.
The intrusions have had little effect on water or waste water supplies to local communities, but have resulted in outages and disruption as matter responders investigate the breaches. CISA previously reported that some of the intrusions allowed hackers to modify affected PLCs to disable shutdown processes and alarms, potentially creating “unsafe conditions” without notifying the affected operators.
Many of the affected communities are in rural or isolated areas, where disruption to critical infrastructure systems can affect a large area of people.
Reports Citing Senior American Updates
Reports citing senior American authorities say that U.S. intelligence believes Iran is likely behind the largely opportunistic attacks on water providers, likely in response to the U.S. and Israel-led war against Iran, but authorities have fallen short of a concrete attribution.
Read More: Self-driving truck startup Gatik raises $200M following PepsiCo deal
The intrusions have sparked broader concerns about the cybersecurity and resiliency of critical infrastructure across the United States.
U.S. authorities have warned in recent years that hackers working for China have been planting destructive malware on critical infrastructure ready to activate as a distraction in the event of an anticipated Chinese invasion of Taiwan.
Russia has also been linked to several cyberattacks on water providers, and power and energy grids, across Europe as part of a growing campaign seen as aimed at testing the NATO alliance.
The attacks on US water and wastewater systems highlight the need for improved cybersecurity measures and collaboration between government agencies and private sector companies to protect critical infrastructure from cyber threats.
Back U.S. cybersecurity agency CISA stated it has observed cyberattacks targeting over 100 internet-exposed systems across the U.S. water and wastewater sector, amid a wave of hacks targeting American critical infrastructure.
Frequently Asked Questions
What's Your Reaction?
Like
1
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
2
Comments (0)