Iranian hackers are actively compromising internet-connected industrial controllers across the U.S., impacting critical infrastructure. These cyberattacks pose significant risks to essential sectors such as water, energy, and government services. By altering control logic, hackers can cause severe disruptions with potentially dire consequences.
Methods and Impact
The attackers exploit publicly accessible programmable logic controllers (PLCs), gaining unauthorized access to modify project files that control these systems. This interference extends to altering operator screens, obscuring any abnormal system behavior from staff. Such actions have reportedly led to operational disruptions and financial losses for affected organizations.
The Cybersecurity and Infrastructure Security Agency (CISA) has observed the campaign’s spread across multiple industrial automation manufacturers, raising alarms about the vulnerability of exposed industrial equipment. Iranian-linked actors are leveraging third-party infrastructure and industrial programming software to infiltrate inadequately secured systems.
Manipulation of Safety Controls
A particularly concerning aspect of these cyber intrusions is the tampering with safety controls. Attackers have been able to modify or erase PLC project logic, including critical safety-related components. In one case, harmful project instructions were introduced while retaining enough legitimate logic to mask malicious activity.
The manipulation extends to data presentation on human-machine interfaces, leading operators to perceive normal system metrics while the underlying controllers have been compromised. This discrepancy poses grave risks, especially in sectors where safety shutdowns are crucial to preventing hazardous conditions.
Security Recommendations
To mitigate these threats, it is imperative for organizations to shield PLCs from direct internet exposure. Essential remote access should be routed through monitored gateways or jump hosts, upholding secure connectivity principles. Additionally, reviewing controller project files against trusted versions and inspecting connected devices for unauthorized changes is crucial.
Security practices such as employing strong, unique passwords, enabling multifactor authentication, and enforcing firewall restrictions can enhance protection. Regular log reviews and vigilance for unusual network activities are also vital to maintaining industrial security.
The ongoing cyber threat underscores the necessity for accurate asset inventories and defined ownership of remote connections. As attacks on PLCs continue, organizations must prioritize securing all externally reachable controllers.
