The FBI and Cybersecurity and Infrastructure Security Agency warned Thursday that cyberattacks targeting water utilities are escalating and operators have been locked out of their operational technology networks.
CISA said it was seeing a “significant escalation” of attacks targeting programmable logic controllers (PLCs) and urged water utilities to remove publicly exposed devices from the internet, according to an advisory issued Thursday. PLCs are used to automate and monitor pumps and other functions used for drinking water and wastewater treatment.
The agency warned that hackers have been able to lock operators out of their own devices by modifying passwords and disconnected PLCs by changing their IP addresses. Operators in a number cases have been forced to issue boil-water notices and revert to manual operations.
The FBI said that reported attacks have spread to seven states, following the initial series of attacks earlier this week in Minnesota, according to a public service announcement issued Thursday.
Operators told the FBI that certain attacks have led to flooding and reduction in water pressure. The loss of pressure can lead to untreated water seeping into pipes, according to the advisory.
“The FBI and our interagency partners are fully engaged to protect critical infrastructure and we remain well-equipped to protect against cyber threats of all varieties,” a spokesperson told Cybersecurity Dive on Friday.
Minnesota recovery
The attacks began Sunday with a series of coordinated strikes that impacted more than 30 water systems across the state of Minnesota. State officials have not formally attributed the attacks, but authorities connected them to prior warnings about Iran-linked threat groups targeting vulnerable PLC devices from Rockwell Automation and other makers.
Those attacks took place on Sunday and Monday and threat researchers suspect the attacks were linked to Iran-nexus threat groups.
Minnesota officials said most of the confirmed attacks affected PLCs as well as human machine interfaces, which are the computer screens that operators use to interact with their water systems.
Officials at the Environmental Protection Agency have been working with state and local officials and water system operators to help coordinate their response to the attacks.
“Many systems have experienced operational disruptions due to loss of communications with remote sites, including wells, pump stations, lift stations, and water towers,” a spokesperson for the Environmental Protection Agency told Cybersecurity Dive.
The agency, which oversees drinking and wastewater treatment, held a conference call Wednesday with hundreds of water utility officials to share information and technical assistance about how to prevent additional attacks.
Iran-linked threat groups have been targeting U.S. water and energy systems for months since the start of the Iran war in February. The attacks have targeted vulnerable devices from Rockwell Automation and more recently expanded to include Schneider Electric and Siemens.
Rockwell Automation issued an advisory on Thursday warning about hackers targeting its MicroLogix 1400 series devices. Hackers have been able to change IP addresses and modify passwords, effectively blocking the ability of water system operators to monitor their own devices.
The company said customers could regain access to tampered devices by turning off power, removing and reinstalling batteries. The procedure erases the IP address and program. The company also suggested creating offline backups and removing the devices from the public internet