Advisory says attackers accessed controllers connected directly to internet

A July 30 advisory from the FBI and the Environmental Protection Agency stated that attackers remotely accessed Rockwell Automation MicroLogix programmable logic controllers connected directly to the internet and changed the controllers’ IP addresses and passwords.

Initial suspicion has fallen on hackers allegedly aligned with Iran, but the U.S. government has yet to attribute the attacks to anyone. The methods used in the incidents are typical of international cyberattacks, UPI reported.

About 152,000 public drinking water systems operate in the United States, according to the federal government. Programmable logic controllers are small computers that read sensors measuring conditions such as water pressure and tank levels, and automatically operate pumps, valves and alarms. Many utilities rely on remote connections to monitor distant equipment, but controllers connected directly to the internet present fewer defensive barriers, making them easier targets for attackers who can scan for IP addresses and attempt weak or stolen passwords.

In 2023, U.S. officials reported that Iranian-linked hackers targeted internet-connected Unitronics programmable logic controllers used by water utilities, and the Cybersecurity and Infrastructure Security Agency noted at the time that some utilities were still using the manufacturer’s default password. Sophisticated malware is not always necessary for such intrusions.

Following the Minnesota attacks, CISA urged water utilities to place controllers and dashboards behind properly configured firewalls and other safeguards. The agency recommended routing remote access through secure gateways or virtual private networks, requiring multiple levels of authentication, changing default passwords, disabling unused remote-access services and installing vendor-approved updates.

CISA also recommended separating operational networks from email and other business systems, a measure designed to make it harder for attackers to move between the two, and advised utilities to back up controller programs, log remote-access activity and practice restoring systems and operating manually. Rural water utilities with limited resources face particular challenges implementing such defenses. A group of volunteer cybersecurity experts is providing guidance to water utilities, but their reach is limited, and smaller utilities may need government funding or shared cybersecurity services to defend themselves, UPI reported.