Top 5 This Week

Related Posts

Colorado Water Systems Targeted in Suspected Foreign Cyberattack: Governor’s Office

Foreign hackers breached equipment at two small, privately owned Colorado water utilities in late August, changing operational settings but causing no known harm to water quality or service, a spokesperson for Gov. Jared Polis’ office said on Friday.

Each utility serves fewer than 200 people, according to Ally Sullivan, a spokesperson for the governor. The providers quickly addressed the intrusions and later notified the state, she said.

There was “no impact to public safety or water services,” Sullivan said.

The attackers disabled remote access and alarms and modified pumping cycles. State officials have not identified those responsible.

“These were brief incidents and the risks were quickly addressed by the providers themselves, who subsequently alerted the state,” Sullivan said. “To our knowledge, treatment processes and water quality were not impacted at either provider.”

Sullivan said the governor’s office “cannot confirm what foreign actors may have been involved, but we are aware of ongoing efforts across the nation by an Iranian-backed group to access drinking water and wastewater systems.”

Attacks Span States

The Colorado breaches followed a broader series of cyberattacks against local water systems in about a dozen states, affecting roughly 100 water entities, according to an Aug. 21 advisory from the Cybersecurity and Infrastructure Security Agency (CISA).

Some cybersecurity specialists said the earlier activity resembled previous Iranian-linked attempts to compromise programmable logic controllers.

Earlier attacks disrupted water operations by changing internet protocol addresses and enabling passwords, causing operators to lose visibility into—and, sometimes, control of—connected equipment, the FBI said in July.

A federal advisory updated July 22 warned that Iranian-affiliated hackers were targeting internet-connected operational technology, including programmable logic controllers, according to CISA, the FBI, National Security Agency, Environmental Protection Agency, Department of Energy, U.S. Cyber Command’s Cyber National Mission Force and Treasury Department.

According to the advisory, hackers manipulated controller project files and information shown on human-machine interface and supervisory control and data acquisition displays. The activity disrupted organizations in the water, energy, and government sectors and, in some cases, caused financial losses.

The campaign had escalated amid hostilities involving Iran, the United States and Israel. At one U.S. site, investigators found hackers downloaded a malicious project file that preserved downstream functions while adding code that overrode instructions intended to maintain safe operating limits.

The activity expanded beyond Rockwell Automation and Allen-Bradley equipment to include Schneider Electric and Siemens controllers, and potentially other brands.

Federal agencies advised operators to remove controllers from direct internet exposure through secure gateways and firewalls, follow manufacturers’ security guidance, and inspect logs for evidence of compromise. The advisory also urged operators to review suspicious traffic involving ports 44818, 2222, 102, and 502, particularly when it originated from foreign hosting providers.

Reuters contributed to this report.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Popular Articles