The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning to water and wastewater system operators, emphasizing the need to secure operational technology (OT) from cyber threats targeting programmable logic controllers (PLCs).
This advisory follows a recent cyberattack that affected automated systems at numerous water facilities in Minnesota. Released on July 30, the alert highlights a marked increase in cyber threats directed at PLCs in the water sector, urging stakeholders to disconnect internet-exposed OT devices immediately.
Recent Cyberattacks in Minnesota
On July 26 and 27, over 30 community water systems in Minnesota experienced coordinated cyber intrusions. According to Minnesota IT Services (MNIT), these attacks disrupted some automated functions, although contingency measures ensured that water services continued largely unaffected. Local authorities assured residents that water quality remained safe.
Though investigations are ongoing, and no attribution has been confirmed, the incident underscores the vulnerabilities within the sector. CISA’s alert outlines methods used by attackers, including password alterations to lock operators out and IP address changes to disconnect PLCs.
Connection to Iranian Cyber Campaigns
The timing of the Minnesota attacks coincides with US warnings about Iran-linked threats against industrial control systems. An updated advisory, AA26-097A, issued on July 22, extended the list of targeted devices to include Siemens, Rockwell Automation, and Schneider Electric products.
Iranian groups, such as CyberAv3ngers, have historically targeted small water utilities. Past incidents have involved exploiting vulnerable cellular routers, similar to the tactics observed in these latest attacks, although no specific group has been identified as responsible for the Minnesota breaches.
Recommendations for OT Security
To mitigate these threats, CISA recommends three immediate actions: disconnect PLCs from the internet, use VPNs or gateways instead of direct access, and implement password changes alongside IP address allowlisting to restrict remote access.
Furthermore, CISA advises maintaining a clean backup of PLC images to recover from potential lockouts. Rockwell Automation users are specifically guided to consult company resources for password recovery.
Operators are also encouraged to review CISA’s advisory AA26-097A for tactics and indicators of compromise, ensuring they remain vigilant against both current and historical cyber threats.
For further insights, stakeholders can refer to the full CISA alert and consider participating in the upcoming ICS Cybersecurity Conference in Nashville.
