A recent string of cyber attacks on U.S. water systems underscores the threat the municipal water sector is facing and the criticality of emergency preparedness and cybersecurity measures. According to multiple news reports, cyber attacks across seven states last week were reported to the Federal Bureau of Investigation (FBI). News of the cyber incidents followed another report that more than 30 water systems in Minnesota were targeted in a coordinated cyber attack last weekend. The seven states affected in the most recent attack were not named, but according to a CBS News report and others, Minnesota and Michigan were among seven states with utilities affected. The Cybersecurity and Infrastructure Security Agency (CISA) is urging critical infrastructure owners, operators and integrators to remove publicly exposed programmable logic controllers (PLC) devices and other operational technology (OT) from the internet as soon as possible. CISA said it is currently observing a significant increase in cyber threat actors targeting PLC devices in the water and wastewater sector. The agency said threat actors targeting exposed PLCs have modified passwords to lock out operators and have disconnected the PLCs by changing their IP addresses. The activity resulted in boil water notices and sustained manual operations, CISA said. Despite the incidents, multiple reports have said there has been no reported contamination of municipal drinking water as as result.
Read more: Water Finance & Management