Weak Passwords Just Exposed Our Water Supply to Iranian Hackers
The water system attacks
Our critical utility infrastructure can make the same classic mistakes as we do with our everyday connected devices.
Iโve spent years writing about the need to update default passwords on internet-connected devices, but the recent cyberattacks on our water systems show that the same preventable flaws continue to leave our most critical infrastructure vulnerable. Starting on July 26, more than 30 water systems in Minnesota started experiencing symptoms of a coordinated cyberattack. A week and a half later, those attacks had spread to at least a dozen states, leading to widespread disruptions in service, boil-water notices, drops in pressure and flooding.
In a joint statement on July 30, the Federal Bureau of Investigation and Environmental Protection Agency described a situation that will sound familiar to anyone whoโs followed cyberattack stories in recent years: Malicious actors gained access to internet-connected devices, changed the IP addresses and passwords and took control of their operations. Iranian hackers are likely behind the attacks, according to multiple news reports. In most cases, facilities were able to restore services within hours by switching to manual operations. But experts say the attacks highlight alarming vulnerabilities in the security of our critical infrastructure.
โWeโre in a lot worse shape than you would think,โ says Maurice E. Dawson, a professor at the Illinois Institute of Technology who studies critical infrastructure cybersecurity.
The attacks shouldnโt have come as a surprise to anyone. As far back as 2023, the Cybersecurity and Infrastructure Security Agency issued an alert about threats targeting water systems by exploiting internet-connected devices with default passwords or no password at all. In April this year, CISA put out another warning to water facilities about Iranian-affiliated actors potentially targeting US water and energy systems. The agency updated the advisory with additional guidance four days before the first attack in Minnesota was reported, listing the specific devices it had observed being targeted. Again, it urged operators to โensure device passwords are changed from their default.โ
How malicious actors access critical infrastructure
Iโve been writing about attacks on Wi-Fi routers for years, and itโs shocking how much CISAโs guidance to water systems mirrors what I tell internet users all the time: Change default credentials, use a VPN, keep devices updated with the latest security patches. In the recent attacks on water systems, the open doors were industrial computers called programmable logic controllers, or PLCs.
Like Wi-Fi routers, PLCs โserve as the central nervous system for complex industrial control systems,โ according to Process Solutions, a company that manufactures the devices. Youโll find them in virtually every industrial setting across the country, including food processing plants, water treatment facilities and electrical substations. Many of them have been in service for decades without security updates, making them inviting targets for attack.
Once found, the passwords were either too weak or too obvious. โIt was very much a low-hanging fruit for an actor to go and attack these systems,โ said Michael Garcia, policy director of the industry group Operational Technology Cybersecurity Coalition and former CISA associate chief.
On July 30,
Comments
No comments yet. Start the discussion.