Update, Insights from Water Infrastructure Hacks

The terrifying potential of these attacks offers an inflection point for ICS and OT security upgrades.

Hacktivist Peshkov
istock.com/peshkov

As reported earlier this week, a cyberattack that originated in Minnesota has now been linked to incidents impacting public water treatment and delivery systems in as many as a dozen states. In addition to up to 30 systems in Minnesota, facility operators in Michigan, South Dakota and California have also reported intrusions that either temporality shut down or manipulated on-site operations.

As of press time, FBI investigations have not found evidence of water supply tampering, malware drops or ransomware demands. All effected systems have restored operations or implemented manual controls to address pressure drops or communications issues. Additionally, while law enforcement and the cybersecurity community at large believe these intrusions are the work of Iranian hackers, no proof has been found linking these groups to the hack.

Pointing the finger towards these groups is hardly a reach, however. Going back less than three years, a state-sponsored Iranian group dubbed the CyberAv3ngers targeted Programmable Logic Controllers used by Israeli water treatment plants. That attack leveraged vulnerabilities associated with weak credentials used with internet-facing PLCs made by Unitronics. 

While the attack was focused on Israel, the use of these same PLCS throughout the U.S. also impacted breweries, beverage makers and water treatments plants in the U.S. and around the world.

The Cybersecurity Infrastructure and Security Agency (CISA) has released numerous warnings related to protecting industrial control systems used by critical infrastructure organizations. Of late, the guidance has been especially focused on state-sponsored groups from Iran and Russia targeting water treatment plants and other utilities.

In their most recent guidance, which was issued just days before the Minnesota exploit became public, CISA urged “critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.

“Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations. These threat actors are targeting water entities of all sizes.

“Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. 

“CISA recommends organizations implement the following mitigations:

  • "Disconnect the PLC from the internet. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC.
  • "Enable password protection and change default passwords.
  • "Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets.”

CISA also called out owners and integrators of Rockwell Automation MicroLogix 1400 PLCs, directing them to the company’s product-specific guidance. Additional industry stakeholders also weighed in, offering insights ranging from gratitude for CISA’s guidance to frustrations over the continued deficiencies of outdated OT security strategies and tools.

James Winebrenner, CEO, Elisity

“Concern is only useful if it turns into one question a resident puts to their utility: is anything at the treatment plant reachable from the internet. 

“Escalated is the agencies’ own word, not mine. A joint advisory in April said Iranian-affiliated targeting of U.S. organizations had recently escalated, and a 2023 campaign against internet-exposed Unitronics controllers reached at least 34 US water and wastewater facilities.

“Changing IP addresses is exactly what the FBI describes happening at water utilities. Federal authorities said the Unitronics controllers breached at U.S. water utilities in 2023 were sitting on the internet with the default password 1111. Neither MicroLogix line named in this alert has a physical key position, so the mode is set from the keypad or in software and stays reachable over the network.

“Mediated access through a secure gateway or jump host is what the FBI and EPA ask for, not an air gap. Cutting every remote path into a plant costs the operator the view of that plant. Loss of view is precisely what the FBI says the reporting utilities suffered. One organization noticed ladder logic discrepancies across several sites. Somebody was changing the logic that runs a plant.

“Money is the real constraint for a municipal water utility: the MicroLogix 1100 named in the FBI’s alert is discontinued, and Rockwell now tells buyers to migrate to its Micro800 platform. Replacing a discontinued controller is a capital project, and removing inbound internet exposure is a configuration change. Do the cheap work first.

“The mechanism in this alert was turning a password on, which means there was no password to break. On the MicroLogix 1400 the password typed at the controller’s keypad is capped at ten digits and entered with arrow keys, so the advice to use letters, numbers and symbols can’t be followed on that credential. A utility that hurries unvalidated devices back into RUN locks in whatever file is loaded, and calls it remediation.

“Poland’s security service found weak password policies and internet-exposed systems behind breaches at five of its water treatment plants. After the Polish grid attack, CISA told operators to require integrators and OT suppliers to enforce password changes. The most useful call a utility makes this week is to the integrator who built the plant.”

Kevin E. Greene, Chief Cybersecurity Technologist, Public Sector at BeyondTrust

“The reality is that more than 80 percent of this nation’s water facilities operate below the Cyber Poverty Line with single-operator staffs. This is not a viable working model for protecting our critical infrastructure. An all-hands-on-deck approach with Whole-of-State initiatives is needed to enhance these water systems with Cyber-Informed Engineering, capital investment, and centralized, managed access planes—making unauthorized access to physical controls nearly impossible, regardless of a utility’s local budget.

“Securing OT across the water sector requires combining cybersecurity with engineering disciplines that design out cyber risk—like preventing a cyber-induced water hammer. But to completely constrain a threat actor's leverage, we must disrupt privileged access to collapse nation-state campaigns and strip away the authority they need to become operationally dangerous in our water systems. The true test is measuring how much cyber risk we can design out so that limited budgets never dictate our ability to adequately protect critical water facilities.”

Louis Eichenbaum, Federal CTO at ColorTokens

“Many of these Operational Technology (OT) systems were never designed with cybersecurity in mind. We are never going to patch fast enough or prevent every intrusion. The focus now must be on resilience, assuming an adversary may gain access and ensuring they cannot move laterally or manipulate critical operations at scale.

“Granular microsegmentation and Zero Trust principles are essential in OT environments because they help contain breaches, restrict unauthorized communications, and reduce the blast radius when a compromise occurs. The goal is not simply to stop every attack, but to ensure that a localized intrusion does not become a catastrophic operational event.”

James Maude, Field CTO at BeyondTrust

“The OT and ICS threat environment has crossed a threshold. Last year, multiple threat groups moved past reconnaissance into actively mapping how industrial control systems to understand how physical effects can be induced. We are also seeing ransomware groups take a significant interest in OT environments and begin to specialize.

“It’s not just the number of threat actors that is going up, the sophistication of the attacks is also increasing.

“The common thread amongst all these threat actors is how they gain leverage. Compromise an identity, escalate privilege, and move laterally until you can access something that matters. OT environments can be a perfect playground for threat actors as privilege is often unmanaged and identities are largely ungoverned.

“One challenge we have is that when it comes to the OT and ICS threat landscape, we tend to take a Hollywood view and overestimate dramatic, advanced attacks when the reality is most successful attacks are mundane, but highly effective. Organizations should start with the basics. Visibility and asset inventory to know every device, firmware version, connection path, and account with access to OT systems.

“That last part is where most organizations fall short. You can map every PLC on the floor and still be blind to the service accounts, vendor credentials, and standing admin rights that an attacker would actually use to reach them. Enforce least privilege across the entire IT-OT boundary. Eliminate shared credentials, remove standing access for vendors and contractors, implement just-in-time access for anyone touching control systems.

“Too many environments still have administrator accounts with permanent, always-on access to both IT and OT domains. Every one of those is a lateral movement opportunity waiting to be exploited.”

Manish Sharma, CISO, Aurigo Software

“The coordinated cyberattack targeting more than 30 Minnesota community water systems should serve as a warning that cyber risk does not stop at the edge of an IT system. It can extend directly into the physical infrastructure that communities depend on every day.

“Water infrastructure presents a particular challenge because utilities often operate across a patchwork of aging assets, legacy control systems, newer connected technologies, and equipment installed and maintained by multiple contractors over decades. Cybersecurity has to account for that complexity. It must be treated as an infrastructure requirement throughout the asset lifecycle, from planning and design through construction, commissioning, operation, modernization, and replacement.

“Minnesota’s response shows why manual fallbacks, coordinated response plans, and recovery exercises matter. But those capabilities do not begin when an incident occurs. They are built into the way infrastructure is planned, procured, delivered, commissioned, and managed.”

Patrick Gillespie, Practice Director of OT at GuidePoint Security

“The updated government advisory, including Schneider Electric, Siemens, and potentially others as new PLC manufacturers being targeted by Iran is significant but not surprising. What these threat actors are exploiting isn't a vulnerability unique to one vendor; it's a systemic deployment failure.

“These are programmable logic controllers sitting on public IP addresses, directly reachable from the internet, with no cybersecurity protections between them and the outside world. No firewall, no VPN, no authentication gateway, nothing. The actors aren't using sophisticated zero-days; they're using the same legitimate engineering software that integrators use, connecting to devices that were never meant to be internet-facing.

“The fact that this has expanded across manufacturers tells us the adversary isn't hunting for product-specific bugs, they're scanning the internet for any exposed industrial controller they can find, regardless of brand. This will continue to expand until the fundamental deployment problem is addressed.

“By the time CISA expands an advisory to include additional manufacturers, the threat actors have already been active against those targets. The original advisory in April documented disruptions dating back to March. Critical infrastructure operators need to stop treating these advisories as informational reading and start treating them as incident response triggers. If you have PLCs with public IP addresses and no protections in front of them, you should assume they've already been touched.

“The good news is that the single most impactful mitigation doesn't require a massive budget or a dedicated security team. Take the PLC off the public internet. If you need remote access for maintenance or monitoring, put a VPN or secure gateway in front of it. If you can't do that today, at minimum put the controller's physical mode switch into "Run" to prevent remote program changes.

“The public should understand that these attacks are succeeding because too many of them were deployed without any defense at all. When a water treatment PLC is sitting on a public IP address with no authentication, no encryption, and no monitoring, that's not a sophisticated nation-state problem, that's a basic hygiene failure.

More in Operations