التكنولوجيا

FBI, EPA Warn of Cyberattacks on Water, Wastewater Facilities

FBI, EPA Warn of Cyberattacks on Water, Wastewater Facilities

AAdmin
٤ أغسطس ٢٠٢٦
3 دقيقة قراءة
FBI, EPA Warn of Cyberattacks on Water, Wastewater Facilities

Following cyberattacks targeting more than 30 municipal water systems across Minnesota, the FBI and EPA have issued a warning to critical infrastructure asset owners and operators that malicious actors are targeting operational technology devices used in water and wastewater facilities.

Since July 27, water and wastewater companies in seven states have reported incidents to the FBI, some of them causing a degradation of service, the agencies said in a public service announcement.

Operational effects reported to the FBI have included loss of pressure and flooding, the announcement added. Pressure loss in water systems could potentially allow untreated groundwater to seep into pipes, it explained.

A primary target is Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), particularly the MicroLogix 1100 and 1400 series. When those PLCs are exposed to the internet, attackers can remotely tamper with the devices' configurations.

Once the attackers have access to a PLC, they can change its IP address and password, resulting in a loss of view and, in some cases, function of connected equipment in targeted facilities. The FBI also reported that one organization discovered modified PLC project files after identifying ladder logic discrepancies at multiple sites.

Attacks on water and wastewater facilities appear to be a growing trend. "The American public needs to be aware of, not fearful of, cyberattacks that can impact their daily lives," observed Andrew Chipman, director of GRC and ISO at ProCircular , a cybersecurity consulting firm in Coralville, Iowa.

"Water, power, internet — these things are increasingly under attack from foreign nation states, ideologically aligned cybercriminals and activists," he told TechNewsWorld. "The reason is that they are easy targets — rarely secured appropriately — and cause a big impact to affected cities."

In addition, he noted, "PLCs are notoriously hard to patch and are not supported by manufacturers with frequent enough updates."

PLCs attract attackers because they directly control physical processes, allowing cyberattacks to produce real-world consequences, such as service disruptions or equipment damage, explained David Kertai, a research assistant with the Information Technology & Innovation Foundation (ITIF), a science and technology think tank in Washington, D.C.

"Many water and wastewater facilities still rely on legacy PLCs designed for reliability rather than cybersecurity," he told TechNewsWorld. "These systems often lack strong authentication, encryption and modern access controls, making them attractive entry points for adversaries."

Kertai noted that attacks targeting critical infrastructure have increased as adversaries recognize that many water and wastewater systems still rely on aging technology and often have limited cybersecurity resources.

"Utilities have adopted digital tools for remote monitoring, automation and operational efficiency, improving performance while expanding the number of systems that require protection," he explained. "Many facilities continue to operate legacy equipment that was not designed to withstand today's cyberthreats, creating opportunities for both nation-state actors and cybercriminals."

The OT and ICS threat environment has crossed a threshold, contended James Maude, a field CTO at BeyondTrust , maker of privileged account management and vulnerability management solutions in Carlsbad, Calif.

"Last year, multiple threat groups…