Latest News

US Cyber Defense Agency warns that hackers are increasingly targeting water system

U.S. civilian cyber defense agency warned on Thursday of an increase in hackers who target?technology that is used to maintain, control and monitor water and wastewater systems.?Operators of these systems are advised to remove them as quickly as possible from the internet. The warning comes just two days after Minnesota’s state IT agency reported that more than 30 water systems were the target of a “coordinated cyberattack” on July 26-27. In a late-night statement on Thursday, the FBI stated that at least seven state water and wastewater utilities had reported incidents to them. Some of these activities "degraded" water operations.

The New York Times reported that U.S. officials are reviewing the case and believe it is probable that hackers with Iranian links are behind the Minnesota attacks. The Iranian government's representatives did not respond immediately to a comment request. The attacks come amid an intensification in the war between Iran and the U.S., as both sides have been exchanging missile attacks and are threatening to increase destruction.

Hacking activity linked to Iran targeting the U.S. Water facilities date back to before the war. However, a number of groups have launched a series prominent cyberattacks against domestic U.S. organisations, including Stryker Medical Services and the Los Angeles County Metropolitan Transportation Authority. The FBI was contacted by the White House to answer questions regarding the Minnesota incidents. The FBI didn't immediately respond to an inquiry about the alleged Iranian involvement in these incidents. Officials from the state and local governments of Minnesota have said that these attacks do not pose a threat to water safety. However, in some cases systems had to be taken offline manually and reset. Cybersecurity and Infrastructure security agency issued an alert on Thursday warning that hackers had, in some instances, changed passwords in order to lockout operators and disconnect specific devices from networks. This resulted in "boil-water notices and sustained manually operations." According to the FBI, unidentified victims reported that the "operational effects of the attacks" included, in some places, loss of pressure and flood.

Minnesota IT Services, which is the information technology agency of the executive branch in the state, said that an investigation was ongoing. The majority of confirmed incidents involved the technology used by water systems to remotely monitor equipment and control it, such as programmable logic controls (PLCs) and the computer screens that operators use to manage these.

John Israel, Minnesota’s chief information security officer, stated in the statement that Minnesota has “provided relevant data to the federal government which is evaluating these activities in a broader national context, and leading efforts to determine if it can be attributed a specific threat agent.”

IRAN SUSPECTED

Cynthia Kaiser, a senior FBI cybersecurity official told reporters that it is highly likely that Minnesota hacking campaigns are a continuation of prior Iranian-affiliated attacks on PLCs and critical infrastructure technology, as noted by CISA and the FBI in an April advisory. The advisory was updated by CISA, the FBI, NSA and other federal agencies on July 22, to include more devices that were targeted than initially tracked as well as current techniques and hacking activities.

The fact that "a new advisory" was released is indicative of either a broadening or new technical details, or a re-invigoration of the campaign.

Chris Day, chief technical officer for cybersecurity firm Tenable in the public sector, said that the Minnesota incidents were "consistent" and "interesting" with previous events. He also noted the information publicly reported about some systems temporarily being taken offline. (Reporting and editing by Stephen Coates, Shri Navaratnam and AJ Vicens from Detroit)

(source: Reuters)