CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

https://www.securityweek.com/wp-content/uploads/2023/04/CISA-Cybersecurity.jpg

The US Cybersecurity and Infrastructure Security Agency (CISA) is urging water and wastewater system (WWS) operators to protect operational technology (OT) against malicious activity targeting programmable logic controllers (PLCs).

The alert is a fresh call to action that comes just days after a coordinated cyberattack disrupted automated controls at dozens of water utilities in Minnesota.

In an alert published July 30, CISA said it is observing a significant increase in threat actors targeting PLCs in the water and wastewater sector, and urged critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other OT from the internet as soon as possible.

The agency described specific tactics it has seen against exposed controllers: attackers have modified passwords to lock out operators and disconnected PLCs by changing their IP addresses. According to CISA, the attacks have resulted in “boil water notices” and sustained manual operations that closely mirror what...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more