US water facility OT infrastructure is under attack again
Hostile nations seem to be dead-set on damaging critical US infrastructure, as Russia has joined the fray with the likes of Iran and China in launching cyber attacks against water facilities.
Vulnerable operational technology (OT) used in US water and energy infrastructure are prime targets for state-sponsored actors looking to potentially poison water supplies or erode trust in energy reliability, with Chinese-backed probing suspected to be practice for if the two superpowers were to go to war.
A joint advisory issued by 6 US government agencies, as well as the UK’s National Cyber Security Center and Canada’s Center for Cyber Security warns that the water supply is at risk due to unsecured OT devices.
Water versus the world
While most of the attacks against US water facilities by Russia-linked groups only amount to “nuisance effects” and “limited disruption,” the joint advisory warns that there is the potential for threat actors to have considerable control over certain OT environments, particularly those that are “insecure and misconfigured.”
Russia-linked groups have accessed human machine interfaces (HMIs) by breaking into internet-exposed virtual network computing (VNC) using manufacturer-issued default passwords. In 2024, Russian groups have used the above method to augment water pump controls to operate outside of their recommended parameters, turned off the alarm systems that could recognize a potential overflow, and change the access credentials to prevent facility workers from reversing the changes.
Luckily, facilities usually have manual control over the internal mechanisms, with only minor tank overflows occurring before the facilities were secured. The joint advisory also issues a number of OT vulnerability mitigations which can be found here (PDF).
More from TechRadar Pro
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Hostile nations seem to be dead-set on damaging critical US infrastructure, as Russia has joined the fray with the likes of Iran and China in launching cyber attacks against water facilities. Vulnerable operational technology (OT) used in US water and energy infrastructure are prime targets for state-sponsored actors looking to…
Recent Posts
- Google’s making it easier for people with low vision to find objects using their phone
- Ransomware attacks hijack Windows Quick Assist feature
- LG’s $100,000 rollable OLED TV is canceled
- Strava is finally adding Dark Mode, AI analytics, family plans and more
- Strava will add AI, dark mode, and night heatmaps
Archives
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- December 2011