The Cybersecurity and Infrastructure Security Agency is urging water utility operators to secure internet-exposed programmable logic controllers following a wave of coordinated cyberattacks targeting Minnesota water systems.
Key Points
- CISA issued an urgent alert on July 30 warning that threat actors are actively targeting programmable logic controllers (PLCs) within the water and wastewater sector.
- Over 30 community water systems in Minnesota experienced operational disruptions on July 26 and 27, leading to manual control procedures and localized boil water notices.
- Attackers are gaining access to OT systems by exploiting publicly exposed devices, modifying passwords, and altering IP addresses to lock out legitimate operators.
- The agency specifically identified risks associated with undocumented cellular modems and controllers manufactured by Siemens, Rockwell Automation, and Schneider Electric.
- Operators are advised to disconnect PLCs from the public internet, implement VPNs for remote access, and maintain clean, offline backups of all controller configurations.