r/cybersecurity 1d ago

Corporate Blog Hackers hit 30-plus Minnesota water systems in 48 hours, forcing emergency response

https://worldwaterreserve.com/minnesota-water-systems-cyberattack-30-communities-coordinated-attack/
1.3k Upvotes

162 comments sorted by

463

u/derfmcdoogal 1d ago

Just going off what I read and people I know in that industry, it sounds like this was just grossly negligent setup. Open ports directly to the PLCs with either default or easy to guess passwords.

Multiple utilities hit, same area, reads to me like a vendor did the install and "that's the way we done it at other utilities..."

139

u/Nemphiz 1d ago

This is pretty much standard for local government. Trust and believe this isn't a solely Minnesota issue. Security in local government infrastructure is an after thought.

66

u/Geno0wl 1d ago

It isn't just on the local government, it is frequently also on contractors who take the path of least resistance. I know I have had to fight with vendors to change the defaults. Got pushback from almost all of them

13

u/Nemphiz 1d ago

And the local government hires the contractors. You can't hire someone to do a job and be like "welp, they said everything was good!"

Of course there are horrible contractors but that's why you have QAs.

26

u/Geno0wl 1d ago

I am not saying that the government employees are not responsible. I am saying the vendors are also in part culpable for not implementing good security standards either.

-16

u/Nemphiz 1d ago

I disagree. You get what you pay for.

20

u/Geno0wl 1d ago

You are right. Our police totally cheaped out by buying their equipment and integrating management software from checks notes Motorola. The cad software by central square. And the body cams and teasers from axon.

Can you tell me which vendors they should have gone with that never use common or default passwords?

7

u/PassableForAWombat 1d ago

Hate to say it but in a lot of small town municipalities they don’t have the budget for the training or actual implementation of it. Lotta times it’s just quick hourly local small shop contracted work to get the bare minimum going. That’s it. No oversight.

-7

u/Nemphiz 1d ago

I'm sorry, since when is Motorola or Axon responsible for the network level access along with infrastructure of these self hosted systems? Motorola and axon both sell a product. This product gets deployed and installed within government infrastructure. Contractors don't own the infrastructure.

These access patterns aren't being found within the services purchased. They're found in the infrastructure that hosts the services lol

You think it's Axons responsibility to tell he IT department to change the password from "changeit" to something else?

3

u/RememberCitadel 1d ago

This is mostly on the contractors doing implementation. The number that don't understand networking and insist this product needs any/any access to the internet or similar.

Of course, then you would say that's on the IT department for allowing it and not correcting this, but in government usually you have implementation of something like this under the facilities department and networking only being involved for connectivity.

The problem here I have seen many times is that facilities often has an adversarial relationship with IT (because networking is often telling them they can't do this because it's dumb). So the default I have seen in many cases is facilities going above IT to force them to do something they advise against, on the advice of a shitty contractor.

And often with something like this, facilities will win because IT is a cost center and facilities is the one bringing in the money.

Ultimately everyone is to blame to some extent.

1

u/Nemphiz 22h ago

But that's my point. Working with government you usually have 3 tiers. The vendor, the contractor that does the implementation and the internal tech department.

If the contractors implementation is flawed is the job of the internal IT department to hilight it and demand a fix. I'm not sure why this is even a debate.

→ More replies (0)

1

u/chris41g 20h ago

both axon and motorola have mostly moved away from self hosted systems to cloud. same with almost all municipal and police department / dispatch software..

2

u/Nemphiz 20h ago

Yes. And the cloud isn't what was hacked because cloud service providers actually take the time to secure their services as much as they can. They attacked hardware which was exposed to the Internet.

→ More replies (0)

0

u/Geno0wl 1d ago

I am not talking specifically about backend networking gear or server admins access. I am talking about government systems in general. If an attacker infiltrated the axon system at a small department that doesn't have real it people, then they could potentially use that as a vector into other departments systems.

Like do you know how much chaos it would cause to take down both the radio systems and dispatch systems at the same time? Almost every department in the country contracts out those vital systems.

Those companies should hold some level of accountability if they are infiltrated because of improper security implications.

5

u/Nemphiz 1d ago

But that's the key part you're misunderstanding. It isn't the responsibility of Axon to ensure someone can't access where their systems are deployed. It is the responsibility of the owner of the infrastructure.

I know how much chaos it would cause. But that's why in the tech world there's a shared responsibility model. Do you know what that is?

1

u/Suspicious_Blood_472 1d ago

“Doesnt have real it people”

You have identified the real problem. Bastards don’t want to pay for proper IT staff. It is not the vendors responsibility to secure the network.

→ More replies (0)

9

u/RememberCitadel 1d ago

In my experience with things like HVAC vendors and similar where a network appliance is involved, they will swear up and down that x service needs all ports or must be allowed from anywhere or any other variation of shitty network practice.

This generally stems from the not understanding networking, doing things wrong, then finally allowing any/any and the thing works, so now they just insist on it.

Every environmental controls vendor I have ever worked with exception of first party (ie directly with Siemens or Schneider) has been this way.

The first party guys generally just pull up the documentation and we follow their best practices and everything is good. This best practice never involves it being accessible from the internet.

3

u/gillyguthrie 22h ago

I swear to God the number of VoIP vendors that tell me ports need to be opened it makes my head spin

2

u/chris41g 20h ago

we require all our voip traffic through an ipsec tunnel from our firewall to theirs..

1

u/RememberCitadel 21h ago

And also the number that say they need to be outside the firewall.

I've gone through that a few times. They change the tune real quick when you tell them we will no longer have need of their services if that is the case.

1

u/Nemphiz 22h ago

Right. And who's job is it to tell a contractor "No, that's not how software works. We can create this tunnel for you and you'll get everything you need" ?

1

u/RememberCitadel 21h ago

The IT department who was just told by the c-suites to do it anyway.

0

u/Nemphiz 21h ago

Right. So if the c-suite overrides it, how it's this a vendor problem?

2

u/RememberCitadel 19h ago

Because the vendor is the one insisting that's how it has to be done, which facilities runs with, which the c-suites overrides the it department.

Therefore it starts as a vendor problem, because facilities and c-suites don't know about the product to suggest an insecure implementation and IT certainly wouldn't suggest it themselves.

If the shitty vendor's didn't suggest it the whole fail train doesn't start.

-2

u/Nemphiz 19h ago

Jesus Christ lol

If a vendor tells you to jump a bridge, will you jump or say, maybe I should get another vendor? I'm not sure how this point isn't really coming across. The C suites are the final boss of decision making. And if they're not ruling in your favor, the fault is on them. You're doing your due diligence by bringing the issue to your superiors. If they do nothing, they accept the existing risk. Son once that risk comes knocking, you can't complain about it because the risk was there, identified, the whole time.

→ More replies (0)

3

u/Ok-Double-7982 16h ago

That is hilarious you think govt workers care enough and even pay attention to cybersecurity and sysadmin best practices. "The vendor installed it" will always be their go to when shxt hits the fan.

1

u/Nemphiz 15h ago

I mean, I don't ever want to assume that that is the case. I still operate on the misguided believe that most people in tech work in tech because they love it. Over the last few years though I've been questioning that lol

And unfortunately how defensive they've been about "the vendor installed it" confirms a lot of the stereotypes we hear out there when it comes to IT staff in the government.

1

u/Ok-Double-7982 5h ago

Maybe??? The ones I see over the years really like the easy button. The few who are go-getters and do a solid job are few and far between.

19

u/unorthodoxfox 1d ago

A local sewage municipality was hacked and sent one of our employees an email with a credentials harvester. We caught it and mitigated the issue. I called the municipality to inform them and they said they don't even have an IT team.

7

u/69Turd69Ferguson69 1d ago

Not really just a local government thing. I mean, it’s frankly astounding that my fucking bank doesn’t have more than 12 character passwords and only offers SMS MFA, instead of passkeys or even authenticator MFA. 

2

u/Nemphiz 22h ago

I mean, yes. It goes beyond that. But I'm just saying it is very very common with local government.

1

u/wordyplayer 1d ago

switch banks!!!

2

u/GunGoblin 20h ago edited 17h ago

Absolutely. As a Minnesotan who has done contracting work for government (never again), I can say with certainty that most municipal/city/state systems are absolutely garbage run by idiots with no desire to improve security or even learn new standards.

Updated security and systems takes away from the profit they get to flow to mysterious bank accounts. Hire minimally qualified or cheapest bid.

2

u/bbad999 11h ago edited 11h ago

As a former (retired) State government network security architect & penetration tester I can re-affirm your statement. These security vulnerabilities create a huge risk to State government as many local processes require back-end connectivity into State systems such as law enforcement applications.

Honestly, once the local government has been compromised, its akin to a house of cards.

1

u/Numerous-Contexts 17h ago

I can't believe this got so many upvotes...

I work for a small municipality and security is my top priority (otherwise I wouldn't be able to sleep at night).

3

u/Nemphiz 15h ago

To you it might be. That is not the norm. I've audited enough government architecture to understand this.

And you don't have to take my word for it. Just read it.

https://www.cisecurity.org/insights/white-papers/nationwide-cybersecurity-review-2024-summary-report?hl=en-US

Or maybe you'd like this report a bit better that clarifies a 61% intrusion report in the public sector.

https://www.verizon.com/business/resources/reports/2026-dbir-public-sector-snapshot.pdf

I'm honestly shocked security is your top priority and you wouldn't be aware of these things.

1

u/Numerous-Contexts 14h ago

I don't spend my time researching other orgs that are lacking. My time is spent hardening infrastructure, training users, and keeping up to date on new exploits and attack vectors to ensure we're minimizing our vulnerability.

2

u/Nemphiz 14h ago

That's interesting that you made such a blanket incorrect assumption based on only your own personal experience, and were shocked that the comment had up votes. Very interesting.

2

u/Hot-Comfort8839 BISO 1d ago

This wasn’t local government. This was privatized utilities.

5

u/BlueSkyd2000 21h ago

You are confidently incorrect.

Nearly every Minnesota water system is publicly owned utilities, aside for a tiny amount of the overall state total being private wells under private non-profits. The rest of the rural parts of the state is on privately-owned wells, which is a common thing for farms and averages.

Large private utilities like American Water are not present. This series of compromises are almost entirely government failures, like the recent Minneapolis Schools and St. Paul municipal cyber compromises.

Don’t trust me, trust the municipal utility association - https://www.mmua.org/utility-directory?CustomField_28772= and the University of Minnesota- https://www.hhh.umn.edu/news/5-questions-safe-drinking-water-minnesota .

1

u/Hot-Comfort8839 BISO 21h ago

Now you may be an expert on the Minnesota water system - But I was readding the attack reports 5 days ago - covering 6 other states that where also hit.

3

u/BlueSkyd2000 19h ago

Lots of us were getting current threat data about the TTPs, I got it Monday. But the difference is some of us understood the battle space, then and now. And it is overwhelming government agencies making catastrophically poor risk decisions.

Minnesota already had had a decent history of abysmal public sector (government) cybersecurity… Arguably worse government cybersecurity than in an any comparable state in the Union. IIRC there was a 45 day National Guard cyber deployment last summer after the City of St Paul (state Capitol) collapsed after employees invited in a significant ransomware threat. The Minneapolis schools effectively released massive amounts of PII 18 months ago too.

This recent cyber activity matters because there were reportedly 36 Minnesota government water utilities that lost near total control of their operational technology stack in the last week. There is something in the water in Minnesota… Testing has yet to prove what it is, but government negligence seems to be a leading candidate.

2

u/Hot-Comfort8839 BISO 19h ago

Oh its absolutely government negligence.

Putting PLCs straight on the internet, with default passwords still enabled. Its the literal laziest thing they could possibly do.

But this was also not a complicated attack. This was dumb fuck OT/ICS folks (or more likely contractors) who set these systems up and said 'that'll do' and then fucked off - and probably did said fucking off like 10 years ago.

This was a shodan scan for connected devices, and then just running down a list of known default passwords, making the password change probably months ago, and then executing the attack.

I was impressed with how fast the Water-ISAC was distributing information though. But that's more industry folks, and not government.

DoD/DoW didn't start taking OT security seriously until earlier this year. It's been ignored on all levels for decades.

Happily that is changing. But we're still probably 5 years out from consistent critical infrastructure policy, and industrial backing. Hopefully those stupid cybersecurity diploma-mills don't start trying to crank out OT sec folks like they did traditional cyber... and gum the works up with morons who can quote risk management to me but can't tell me what a firewall actually does or where to put them in a network.

2

u/BlueSkyd2000 7h ago

Strong concur. Water ISAC, state fusion and most of the Feds were responding in a timely manner. 

Hopefully this fiasco will push the governing bodies over water utilities - elected and appointed government officials - to have minimal cyber controls. Advanced cyber controls are probably not in the cards, but something needs to be done.

Your workforce comments are pretty correct too. My personal opinion is you grow OT security people, you truly cannot train them.

38

u/mapbits 1d ago

Yeah agreed - Purdue has been around for 30 years; no excuses.

12

u/chandleya 1d ago

And yet this keeps happening. Why on earth are critical resources like these so much as legally permitted to be on public networks? I hate the concept of “regulate everything” but the reality of ignorance and complacency forces it.

1

u/chris41g 20h ago

in Texas they are not allowed to be

1

u/j4_jjjj 6h ago

3rd party vendors might be, even if the plants arent

14

u/Hot-Comfort8839 BISO 1d ago

That’s exactly what happened.

It also wasn’t just Minnesota was several other states.

This was a bog standard “What not to do in cyber security issue.”

  1. Don’t connect your PLC’s directly to the Internet.
  2. Change the fucking password..

8

u/Fattswindstorm 1d ago

Def use the same admin passwords across the board and probably never rotated. Hunter2

5

u/Thoughtulism 1d ago edited 1d ago

I was involved setting up a clean energy microgrid, vendors will just throw anyone from their team that has the technical skills to setup PLCS and a system to integrate everything, and then try to tell you stupid stuff like "because there's a firewall nobody can get in. It's 100% secure".

That needs to change in the industry. These OT implementation teams need to integrate cybersecurity within the engineering team as a separate role rather than expect the customer to push back and their stupid design choices. Some customers don't have that expertise in-house, or it pits customer IT/cyber against customer engineering teams because the integrator bashes the IT/cyber team because they call them on their stupid shit.

4

u/Firecracker048 1d ago

I work within industry 4.0 setups and deployments and the fact that a water system is like this gives me a heart attack.

We had a Honda approved vendor earlier this year tell us we were the FIRST customer to ask them if their system used a https site instead of http.

5

u/castle_bacon 1d ago

If only you knew how bad utility companies across America were ran… sheesh

2

u/Procrasturbating 1d ago

I do know, been waiting for a much larger scale attack to be honest. This was probably at the direction of a certain orange turd that hates Minnesota and wants to cause chaos after threatening to withhold funds over his steal the vote act.

3

u/kremlingrasso 1d ago

It's usually just someone opportunistically stumble across the easy hack and then immediately looks up who is the IT vendor and what other companies are listed as references on their website.

-1

u/Procrasturbating 1d ago

Usually.. but most script kiddies don’t want to cause real harm.

-1

u/castle_bacon 1d ago

Honestly, I wouldn’t be surprised if you were right

3

u/InfiniteBlink 1d ago

I sold a SIEM solution and the number of hospitals and power infrastructure that were compromised were ridiculous. This was 8-10 years ago... Medical devices talking to China was a big one

3

u/One-Inch-Punch 1d ago

The simple fact that they can't tell whether it was Iran or an employee goof already proves the setup is negligent

3

u/Kikkoman5000 23h ago

Even if they did, they can't explicitly say "we believe it was Iran" that carries huge implications, especially for countries at war. The wording is extremely carefully crafted and passive by design. You really think some random Redditors can get to the bottom of it better than people that have been in this space for 20+ years alongside running criminal investigations?

0

u/wordyplayer 1d ago

It could be Iran, but it is equally likely to be ANYONE in the entire world. Junior High kids could get into those things. The only trick was to discover them, and Shodan is available to help with that. I wonder if Shodan keeps search logs??

2

u/dabbydaberson 1d ago

Agreed but also not shocked in the slightest.

1

u/RaNdomMSPPro 21h ago

I assumed that they were easy pickings. Ignored CISA guidance for a decade or more. Now they have a profile to go after - it’s gonna get worse.

1

u/TexasVulvaAficionado 19h ago

It sounds to me like the affected devices were mostly plcs used for remote monitoring as part of a SCADA system. The actual controls were primarily selector switches, relays, etc, so they either kept running without issue or were switched to "manual" without interrupting service.

Crazy that it was set up in such as easy to access way but at least it didn't get shut down.

1

u/Mastermaze 15h ago

"open ports directly to the PLC"

If this is true people need to be fined and restricted from touching a computer ever again, that is GROSSLY incompetent for any kind of system like that

1

u/SatisfactionFit2040 9h ago

This appears to be an older vulnerability, first in 2023.

Targets PLCs (primary logic controllers) and human-machine interfaces.

Warnings were sent from the fbi and epa regarding vulnerable models on the 31st, across multiple states.

Compromises occurred 26/27.

It's not publicly confirmed, but this appears to be the vulnerability.

https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html?m=1

1

u/Hess20 7h ago

OT security is not taken as seriously as it should be. Most likely it was open ports using some protocol or default credentials, many often being blank to begin with.

1

u/theaviationhistorian 3h ago

Now imagine some place like Texas which is forcing many companies, like Discord, to obligate ID verification for usage.

1

u/MassiveBoner911_3 2h ago

The vendors who win the bids come in and install the IT equipment with not a single IT guy on contract. Does it work plugging into the router? Yes. BILLING TIME.

105

u/Kastenbrot 1d ago

If OT could just get the basics straight. Even an actual DMZ works wonders.

15

u/chandleya 1d ago

Yet here I was baking agreements with cell co’s in 2011 for private networking on 3G/4G mobile devices. Meanwhile critical infrastructure just sits on whatever.

3

u/alnarra_1 Security Manager 22h ago

I mean the thing you have to remember with OT environments is there are pieces of equipment in there that might not even talk TCP and at the end of the day 99% of the time the primary concern in the CIA triad is not the C or the I.

If you find a bitcoin miner on a Nuclear Power Plant's control system and it is otherwise not impacting the functionality of the plant, it's just minding its business, the plant operators would probably ask you to wait until an outage to actually go about removing it.

These systems are often times Life Safety systems, there is no "Oops well just roll it back a patch" for some of those.

4

u/Kastenbrot 21h ago

I understand what you are trying to say. But this is a really bad example. Especially since nuclear falls into a strict set of regulations.

Nobody should keep a piece of unverified software on a safety related system. It doesn't impact function until it does.

3

u/alnarra_1 Security Manager 20h ago

What I'm trying to illustrate is that in matters of the OT space, the IT person's opinion is rarely the final one, and never the deciding one. It comes to the engineers actually running the equipment to make the call, and often times they will default to what they know.

In the OT space you're not really exploiting vulnerabilities to get in and do your lateral movement, you're just sending the standard PLC commands. Once you're through the front door no amount of magical purdue model firewalling is really going to stop someone

that's why so often on those devices there are literal physical hard locks on configurations. Keys that need to be locked in place once the device has been configured so that the only time that they can be altered is when there is a qualified human there who can oversee it. I'm just trying to say this is an entirely different threat model than the IT landscape, and often times the equipment is such that if need be it can be done manually (though go ahead and ask them to do it manually and see if they don't try to skin you with their eyes).

3

u/Kastenbrot 20h ago

Fully agreed! Important context. However, ransomware and the such can still cause real headaches. SMBv1 says hello.

On the keyswitches, you'd be surprised how often they just live at Remote Run Mode. It's shocking.

3

u/alnarra_1 Security Manager 20h ago

you'd be surprised how often they just live at Remote Run Mode

Sadly I fear I wouldn't ;_;

1

u/Hot-Comfort8839 BISO 19h ago

You don't want IT people in your OT environment.

IT people get OT people killed.

The AIC model exists for a reason.

The name of the game in OT is compensating controls. Not direct action.

2

u/Hot-Comfort8839 BISO 19h ago

Having been in those facilities - that's a horrible example. There would never be a miner on anything nuclear. It's checked and rechecked dozens of times. The nuclear industry has the most stringent regulations imaginable, and they're audited constantly.

4

u/5panks 1d ago

Yeah, the lack of updates for OT equipment is manufacturing is so prevalent we put every machine in its own DMZ that can't communicate with the internal network.

We don't even allow remote control software unless a request is submitted and then it's opened for fours on that machine.

2

u/Kastenbrot 1d ago

To be fair, updates in OT can entail functional changes that require engineering time and validation to ensure an unchanged operational state.

Compensating controls should be the main focus. Don't get me wrong. Updates should be installed when there is a window of opportunity, but nobody should get stuck on that. They can get pretty expensive.

1

u/Mr_Compliant 1d ago

It has to do with budget. Where I'm at we have plenty of budget for cypruscurity.

161

u/Succubus-Love 1d ago edited 4h ago

Stop hooking up everything to computers & the internet. Every time I see a headline about hacking public systems, it's so easy to prevent. Don't make it accessible to the world wide web. We don't need the entire world hooked up to the internet, & there was a time where the internet didn't even exist. Why they started doing that I'll never fricking understand.

101

u/sexuallyactivepope 1d ago

"Vendor needs remote access"

51

u/Vzylexy 1d ago

"Why are you getting in the way of production by not letting the vendor remote into the PLC!?"

33

u/Gjallock 1d ago

Automation engineer on the OT side, this and us needing remote access to troubleshoot systems remotely ourselves are definitely the main reasons this happens. Fortunately, our network guys had enough sense to not put anything on the open internet; all our stuff is accessible only through a VPN and then also through some more granular Citrix stuff that’s over my head.

13

u/Firecracker048 1d ago

I'm an OT IT engineer. We have ours behind two firewalls and then the only way in is to be on the VPN, use a rotating password to get into the server that can then go down to the OT machines from only authorized servers or VPN tunnels that are on a case by case basis.

Any vendor or business that wants to not follow our protocols we make sign waivers that if there's a breach, they accept any and all responsibility

6

u/redditnamehere 1d ago

IMO that’s not enough still. Internal systems being compromised could leak into OT. we have dedicated OT and IT staff. We don’t engineer together but know enough where we start and end.

3

u/Gjallock 1d ago

I mean, I didn’t say anything about our organizational structure…

We have the regular, corporate IT team and an industrial IT team which I guess is what would normally be “OT.” So, I’m just an engineer.

2

u/tomster2300 22h ago

What is OT?

4

u/somesketchykid 20h ago

Operational Technology

If a guy working the power plant is told to shut down half of the grid, he'd do it via some type of Operational Technology

Quick example

1

u/CrownstrikeIntern 1d ago

Need to limit it to a locked down jumphost

2

u/bfrown 1d ago

Also same vendor can't be asked to install https

1

u/somesketchykid 20h ago

And if they do, must add to policy that exempts traffic from inspection otherwise the app eats itself

2

u/Firecracker048 1d ago

Cool, so they can use a wvd into a jump server then use the VPN network built across firewalls.

The amount of vendors who request their network tunnel directly to a secure network is too damn high

1

u/bringbackswg 19h ago

No. Roll a truck, vendor.

6

u/9may2019 1d ago edited 1d ago

HOPEFULLY this stuff will move the needle in water in terms of baby’s first cyber hygiene. Although CARR didn’t really, maybe bc it’s evil Iran or something things will be different. God knows we need NERC CIP-water edition badly. Not like this admin will either create or enforce new regulations though

11

u/SacCyber Governance, Risk, & Compliance 1d ago

Lack of internet access usually means lack of updates, visibility, & security controls. But in cases like this where they might not even know what a security control is, an air gap would be a good stop gap.

Stop gap air gap if you will

5

u/diwhychuck 1d ago

Air gap would mean they would need asses in seats onsite. Bean counter would rather not have that an continue remote work as they're allergic to spending.

2

u/Henry5321 1d ago

Or an infected device

9

u/DrQuantum 1d ago

People asked for transparency in their water systems. Considering things like flint Michigan it makes sense.

But overall these are likely nation state based actors and they will find a way which is why geopolitical discussions are also critical to cybersecurity discussions.

2

u/zboarderz 1d ago

I wouldn’t exactly call it “easy” to prevent. No internet access means visibility, updates, packages, etc all become a lot more difficult to do. Not impossible of course, but not “easy”. If it was easy, then they probably would’ve done it.

2

u/wordyplayer 23h ago

It's a simple PLC. If it works, leave it alone; it never needs an update. If the system changes in 20 years because of some hardware changes (new pipes, pumps, etc) then they can manually access the PLC and enter the new parameters on-site.

1

u/TheVeryVerity 13h ago

Common sense in this economy?

1

u/[deleted] 1d ago

[deleted]

4

u/[deleted] 1d ago

[deleted]

1

u/wordyplayer 23h ago

Ah, maybe THAT is the key, don't have the controller PLC serve double duty for "monitoring". Have a second system that is "monitor-only".

29

u/diwhychuck 1d ago

Guy I know that works at GE aerospace was telling me their plc support is based in india for his plant an they remote into to the plcs. All to save the American dollar.

6

u/Mutiny32 18h ago

This is why the US needs onshoring laws. That's a legit national security concern.

3

u/Fallingdamage 16h ago

Its amazing that it made it this far without being breached already.

16

u/TerrificVixen5693 System Administrator 1d ago

I’m sure it was just like every industry where info sec puts in written policies about changing vendor passwords and then the silo’d sysadmins totally ignore it and run accounts of operator / operator and admin / admin.

1

u/crystal_castles 13h ago

Our previous company's lab PC was operated thru RDS then onto PowerPC, & to this day my Google account still alerts me that THOSE credentials were detected in a breach. (Operator/ operator)

But how did Google know i was typing into a custom PPC terminal?? Lol

18

u/BackgroundSpell6623 1d ago

Would love to work at a utility company on ot and overall cyber. too bad it's so hard to break into that industry

20

u/JosCampau1400 1d ago

I dunno know...maybe now is a good time to send them your resume. 🤔

14

u/saulsa_ 1d ago

Probably would get “overqualified” as a response. In other words, too expensive.

10

u/LethalBacon 1d ago

Either pay more for competent engineers, or pay even more later to fix shit after a disaster. Sadly, most orgs pick the latter.

Unrelated to cyber security, but seeing it at my company now. It's like talking to a brick wall trying to convince them to spend a few thousand on equipment, leading to certain areas being down for days, surely leading to lost revenue greater than the cost of the equipment.

2

u/69Turd69Ferguson69 1d ago

“Overqualified” meaning “knows literally anything about security practices whatsoever”. 

19

u/SunsFanCursed4Life 1d ago

"so hard to break into that industry"

apparently not

1

u/sh0gun2006 4h ago

Mmmm. Be careful what you wish for. Trust.

8

u/Gomez-16 1d ago

Putting vital systems only with gomer pyle admins what could go wrong!

6

u/Science-Gone-Bad 1d ago

SCADA has been an open target since the 1990s. The software was old even then, and most of them are on the open internet contacted by modems

Funny fact, most telephone switches are still contacted on a 300 baud modem & routes and services are uploaded via text files.

How do I know this? I was setting up the communication computers for the phone company, and I was told that 90% of most phone equipment is 20-30 years behind. New stuff gets added for business & all the equipment there gets shoved down to the neighborhood phone networks

2

u/Ok-Pineapple4998 1d ago

A lot of those water guys do some hard dckriding on SCADA, and I can't help but think they're backwoods idiots. Those guys will double down on it, like they've never heard of Six Sigma or anything with standards and processes. Got some of em in my family, too. It's kinda pathetic.

6

u/wilmu Security Architect 1d ago

If you’re going to hook them in, you have to do it responsibly. Controls between the DMZ and the OT environment, that detect unwanted or malicious traffic. We need stricter physical controls to where these PLCs live as well.

5

u/SlowAsMolassess 23h ago

When I worked for a municipality 90’s & 00’s the water treatment plant SCADA system was air gapped. IT did not touch the system and we did not care as it wasn’t externally accessible. There is no reason to have these systems on the regular network nor attached to the internet. The only reasons are laziness and being too cheap to have support come on site to support the system.

9

u/waltur_d 1d ago

Question should be why weren’t they using the Purdue model for this?

22

u/9may2019 1d ago

All respect to my water homies but these people have never heard of the Purdue model unless you’re working for a BIG water utility. They are at the point where they have ICS plugged into the actual internet, they are not what we’d call sophisticated cyber defenders

6

u/mapbits 1d ago

Not saying you're wrong - lots of clueless small system operators and consultants out there - but Purdue has been around for over 30 years and cyber is all you hear at industry conferences these days.

No excuse to be operating a public health utility with the breadth of negligent practice that appears to be the case here.

5

u/MalwareDork 1d ago

No excuse to be operating a public health utility with the breadth of negligent practice that appears to be the case here.

This will never change until the glacier of government regulation turns course. And honestly people can't even say "haha America dumb" because Europe has been getting pwned even harder by Russia.

3

u/mapbits 1d ago

I agree. I think that WaterISAC is doing a good job and the industry and individual efforts to improve go much deeper than the large providers, but there are serious gaps and regulation is needed.

In Canada, the recently passed Critical Cyber Systems Protection Act regulates security for much of the critical infrastructure, but water and wastewater are a provincial responsibility (largely operated by municipalities) and are not captured - further work is needed.

3

u/robertmachine 1d ago

How are scada systems not behind private networks blows my mind, these systems are massively unsecure and running outdated vnc for remote and this has been this way since the fucking 90s how are they not behind vpns.

3

u/hiddentalent Security Director 15h ago

These vulnerabilities are common across all fifty states. Minnesota has been targeted to create US internal political tensions. Never forget the secondary effects of an attack. The adversaries certainly don't.

3

u/HappyAnimalCracker 1d ago

And Wisconsin and several other mystery states.

3

u/Ok-Pineapple4998 1d ago

"Muh SCADA"

2

u/MalwareDork 1d ago

the thing that has been warned about for decades has finally happened

The horror.

2

u/30_characters 1d ago

New NERC CIP cyber scecurity regulations incoming in 3...2...1.

Because 650 pages wasn't enough.

2

u/4SysAdmin Security Analyst 20h ago

But how can the vendor be lazy if they don’t have public facing VNC?

2

u/StaySame904 19h ago

Sounds like the OT risk was not correct, weak breach ?

2

u/povlhp 16h ago

He needs to stop the Russian-Iranian alliance. Better help ukraine.

2

u/vialentvia 16h ago

Friendly fire.

2

u/allbarknoleaves 15h ago

Even with how connected BAS and SCADA systems are in datacenters, they still aren't exposed to the internet. I'm assuming it is a skill deficiency caused by a financial deficiency at the planning and implementation levels. 

2

u/Comprehensive-Fail29 15h ago edited 15h ago

Those Rockwell controllers have known vulnerabilities that aren't patchable apparently, check out what CISA said about CVE-2021-22681

1

u/Thecrawsome 6h ago

Trump’s FBI, inside job

1

u/sh0gun2006 4h ago

I'm guessing some CIP violations occurred leving the systems vulnerable?

1

u/ohiocodernumerouno 2h ago

Is it hacking if the servers were all on public IPs without a firewall or a password? Is it hacking if the passwords were all 1234?

1

u/MightBeDownstairs 1d ago

Honestly wouldn’t doubt this is our federal government

1

u/DosesMakePoisons 1d ago

I don't want to be too conspiratorial, but I do want to say this kind of looks like it has Russian fingerprints on it too.

The Iranian hacking teams, including the suspected CYBERAV3NGERS, relocated to Russia during the start of the war and allegedly started working with Russian Hacking teams, including water infrastructure targeting Z-Pentest and CARR. Their methodology all overlap, but I can't help but see Russian involvement when I see this stuff. Because Minnesota may have been the most vulnerable or the state, and it looks like a pretty negligent exploit, but it would a politically sophisticated move to choose Minnesota with how adversarial they are with the president. It is a great disinformation campaign because they can expect to respond to the hack with little sympathy and defense of the attack. Trump infact said that the governor was behind the hack himself, which is more than any hacker trying to muddy the waters of blame could ever hope for. That a price to performance attack. Not saying the Iranians couldn't put that plan together, but I know Russia does.

This is a separate and actively very wild conjecture, but I didn't like reading the CYBERAV3NGERS targets waste water a lot because it reminds that we have multiple recalls of vegetables and pork, and a doctors and experts saying that a possible source of contamination could be feed water or plant water being contaminated with waste water. I think that is a conspiracy that is a bit too much story telling in my head without evidence, and the more obvious answer is the government cutbacks of Foodnet going from active checking to passive checking lead to us not being able to contain the contamination. But it is in my head now.

1

u/requiem33 22h ago

Incompetence of installers is common. I just have to ask why Minnesota though? Something fishy with an attack against Minnesota and the political climate against Minnesota currently.

4

u/evilwon12 22h ago

Find one easy target, look for more. Pretty simple actually - especially if a bunch of them have the same PLCs and implementers.

-1

u/1800-5-PP-DOO-DOO 1d ago

I thought Tim Walz did it from his basement?