A coalition of security firms specializing in operational technology is calling for immediate action to strengthen the nation’s critical infrastructure following a coordinated attack against U.S. water infrastructure sites.
Federal and state authorities are investigating a campaign targeting vulnerable industrial devices used in thousands of drinking and wastewater treatment facilities across the country.
Threat actors, believed to be linked to Iran, were able to lock operators out of their own systems by targeting industrial devices exposed to the open internet. Thus far, water utilities in at least seven states, including Minnesota and Michigan, were impacted.
The series of attacks began July 26 and 27, striking about 30 systems in the state of Minnesota. Federal and state officials said the incidents were consistent with hackers targeting vulnerable logic controllers, which are often poorly configured, use default passwords, do not require multifactor authentication and can be found via the open internet.
CISA and the FBI last week urged water system operators to harden their systems, particularly programmable logic controllers, which are widely used to monitor water quality and other functions at local utilities.
After receiving warnings from federal authorities, Michigan officials confirmed similar attempts to tamper with their OT systems, according to a spokesperson for the Department of Environment, Great Lakes and Energy.
“All systems continued to operate safely. Issues were addressed by local operators, and there are no known impacts that posed a public health concern,” spokesperson Dale George told Cybersecurity Dive.
Widespread risk
There are currently about 148,000 public water systems within the U.S., including about 50,000 community water systems and 16,000 wastewater treatment sites, according to Alison King, chair of the OT Cybersecurity Coalition and vice president of government affairs at Forescout.
“These systems are fragmented, many are underfunded and security is uneven,” according to King. “Only a small fraction participates directly in threat intelligence sharing, leaving many operators with limited visibility into what adversaries may already know about their infrastructure.”
In a statement released Friday, Tatyana Bolton, executive director of the Operational Technology Cybersecurity Coalition, called the attacks a wake-up call. The coalition is urging the Cybersecurity and Infrastructure Security Agency to issue a Binding Operational Directive that would require Federal Civilian Executive Branch agencies to take immediate action to mitigate risks at thousands of critical sites used by the government for heating and cooling, power, access management and other functions.
Bolton also urged Congress and CISA to immediately take three specific measures.
-
Congress should reauthorize and fund the State and Local Cybersecurity Grant Program. The program provides money to state, local and territorial governments to protect critical infrastructure sites.
-
Congress should support Andrew McClure as director of the Office of Cybersecurity, Energy Security and Emergency Response at the Department of Energy. McClure was named director of the office late last month. The office is in charge of securing the nation’s energy sector, including the electric grid, against malicious cyber activity.
-
CISA is being urged to pass long-term authority for the Cybersecurity Information Sharing Act of 2015. The authority would allow private-sector partners to continue sharing information with CISA regarding potential cyber threats, and allows CISA and the FBI to pass that information along to a wider set of potential victims. Authorization is set to expire at the end of September.