The FBI reported that malicious attackers targets attacks on both water and wastewater facilities in 12 states. The attack appears to have targeted at least in part hardware controllers used to manage water operations. Initial indications were that controllers like Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLC’s) were impacted. The attackers performed several tasks including changing network IP addresses and passwords, resulting in loss of monitoring and some control capabilities.
The impacts of these attacks included loss of water pressure as well as flooding. The hazards noted included the possibility of infiltration of untreated ground water into piping systems.
As always, it is prudent for PLC systems to run on isolated Internet of Things (IoT) networks in isolation from any public-facing internet. Any inbound traffic should always be blocked…if possible it is preferable to use cloud-based isolated control systems. Passwords should:
- Always be changed from defaults
- Passwords should be strong, complex passphrases
- Credentials should be periodically changed in a coordinated manner
- Access should be monitored and alerted on 24/7
- Additional guidance is provided by FBI

