Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack
… Earlier this year, the U.S. warned of Iranian hackers targeting programmable logic controllers PLCs in critical infrastructure organizations. …
The short answer is: we don’t know yet, but the No. 1 suspect is the Iranian government. As of today, officially, the U.S. government has yet to name the culprit behind the coordinated wave of hacks. However, the first incidents in Minnesota came days after the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that Iranian hackers were targeting internet-connected devices in water systems and the energy sector, without saying where those attacks were occurring. (CISA had originally published this warning in April, and updated it before the Minnesota attacks.) After the init
What we know about the alleged Iranian hacks on US water utilities | TechCrunchThe reality is that some systems inside critical infrastructure facilities are exposed to the internet and relatively easy to find. Earlier this month, cybersecurity firm Forescout reported finding more than 2,800 controllers in U.S. water systems exposed online. If a system is exposed, it doesn’t automatically mean hackers can take over control and cause real-world effects. But that has happened in some isolated cases in recent attacks. The FBI said some of the cyberattacks around the country caused loss of pressure, which “could potentially allow untreated groundwater to seep into pipes,” an
What we know about the alleged Iranian hacks on US water utilities | TechCrunch… Earlier this year, the U.S. warned of Iranian hackers targeting programmable logic controllers PLCs in critical infrastructure organizations. …
… Isolating vital systems The agencies recommend critical infrastructure entities first identify the minimum systems and networks required to continue delivering a critical service. …
… They are pretty sure it’s Iranian actors.” While states scramble to protect their utilities and other critical infrastructure, the White House has downplayed the suspected state-sponsored cyberattacks. …
… Australia Found Nation-State Hackers Inside Critical Infrastructure, Ready to Sabotage Australia’s Security and Intelligence Organisation ASIO said this week that it is establishing teams focused on countering nation-state cyberattacks on critical infrastructure after finding actors inside the coun…
… Iranian government hackers have a history of targeting critical infrastructure in the U.S., and it’s possible that these attacks are part of its strategy to retaliate against the country because of the six-month war. …
… But experts say the attacks highlight alarming vulnerabilities in the security of our critical infrastructure. “We’re in a lot worse shape than you would think,” says Maurice E. Dawson, a professor at the Illinois Institute of Technology who studies critical infrastructure cybersecurity. …
… In recent years, attackers have repeatedly exploited flaws in routers, VPNs, firewalls, and other internet-facing infrastructure to breach critical infrastructure and telecommunications providers , including in campaigns attributed to state-sponsored hacking groups such as Volt Typhoon and Salt Typ… …
… As the Colonial Pipeline attack demonstrated, compromising business-critical systems can cause just as much damage as breaching OT. How attackers break in and stay hidden The tactics of threat actors like Volt Typhoon show why critical infrastructure leaders need to rethink trust. …
… "By chaining these modifications, Velvet Ant established a remote-execution path into the segregated environment via simple HTTP requests, with no direct connection to the critical infrastructure network ever required." - Sygnia Having established their access into the isolated environment, Velvet … …
… According to the FBI, the hackers broke into one critical infrastructure provider and changed the controllers’ programming logic to disable processes that handled critical shutdowns and alarms. …