**The number of US states affected by the recent hacking campaign targeting water and wastewater facilities continues to grow. **
At least 12 states have been hit, according to ABC News, but the names of only a handful of the affected states are currently known.
States affected by water system cyberattacks
Minnesota was the first to report attacks, with more than 30 community water systems targeted on July 26 and 27. Michigan has also officially confirmed that a “small number” of communities have seen malicious cyber activity.
At least one city in South Dakota has also reported a cyberattack that appears to be part of the same campaign.
The latest to provide official confirmation of attacks is the Clayton County Water Authority in Georgia, which said it “experienced a temporary disruption affecting a portion of its operational systems and water service”. The incident resulted in reduced water pressure in some areas, but water service was restored within hours.
Wisconsin has also been in the news, but it has yet to confirm any intrusions. Representatives of several major water utilities said they have not been impacted by cyberattacks.
New York has not said whether it has been affected by the campaign, but officials this week announced more than $9 million in grants to help 153 water systems boost their cybersecurity.
Utah has also reported a hacker attack aimed at industrial control systems in an oilfield saltwater disposal facility, but that intrusion was detected in March and it does not appear to be part of the recent campaign. There are currently no reports of new attacks in Utah.
FBI shares details on hackers’ actions and impact
As of July 30, the FBI had officially confirmed that at least seven states had been affected. The agency said in a cyber alert that the attackers had targeted Micrologix programmable logic controllers (PLCs) made by Rockwell Automation.
There have been no official reports of significant disruption, and drinking water has remained safe. However, the FBI has shared some details on the attackers’ actions and the potential impact. The agency explained:
“MCAs [malicious cyber actors] are targeting internet-exposed PLCs (Rockwell Automation/Allen-Bradley’s MicroLogix 1100 and 1400 series) to remotely tamper with device configurations by changing IP addresses and turning on and setting passwords, resulting in a loss of view, and in some cases function, of connected equipment in targeted facilities. At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Additionally, across several victims, similarities in network setup provided by third parties may provide MCA the opportunity to multiply successes when vulnerable network and hardware setups exist across customers.Operational effects reported to the FBI have included loss of pressure and flooding. Pressure loss in water systems could potentially allow untreated ground water to seep into pipes. Once compromised, the extent of impact to victims’ operations depended upon the type of function for which the PLC was configured (monitoring versus controlling equipment), the equipment itself (1100 versus 1400), the function the device supported, and capability to switch to manual operations.”
The US has yet to officially say who is behind the attacks, but Iran immediately emerged as the primary suspect as its hackers have been known to target ICS/OT, including in the water sector.
Federal investigators have been reportedly looking into Iran’s potential involvement, and a non-public report from WaterISAC, which serves as the information-sharing organization for the water sector, reportedly cited evidence that the attacks were “aligned” with hacking campaigns previously linked to Iran.
Information for defenders
CISA urged the water sector to protect OT systems, specifically PLCs.
In addition, federal agencies have updated an April advisory on Iranian attacks aimed at OT devices, warning that ICS devices made by Siemens, Schneider Electric, and Rockwell Automation have been targeted.
Censys reported that roughly 10,000 Rockwell, Siemens, and Schneider PLCs are exposed to the internet, but it’s unclear how many are actually vulnerable to attacks.
Infracritical has made available a report that summarizes all of the currently known technical information for the OT security community and defenders.
Related: Rockwell Patches Code Execution Flaws in Arena Simulation Software
Related: 1 in 5 Data Center Assets Are Within Easy Reach of Attackers