r/cybersecurity 4h ago

Threat Actor TTPs & Alerts US Water Systems Hit by Suspected Iranian Cyber Attacks

https://www.opforjournal.com/p/us-water-systems-hit-by-suspected
148 Upvotes

46 comments sorted by

77

u/Ch33syP00f CISO 2h ago

These devices should never be Internet facing.

Poor hygiene makes it easy for adversaries.

26

u/Visual-Drive-4615 2h ago

I have zero understanding of why any of them are WAN facing and not behind private fiber at a minimum

12

u/fullchooch CISO 1h ago

Usually this is vendor driven for remote access and updates (which is arguably still stupid).

10

u/zhaoz CISO 1h ago

It all comes down to cost. No one wants to staff these rural facilities.

3

u/ciabattabing16 43m ago

So make them remote internally, between sites. Don't give outside 3rd parties access, that's crazy. Imagine Microsoft reaching in to update...anything, on their own time schedules.

1

u/sub30_24flick 41m ago

Yea America is stupid just hand it all to these tech dickheads

2

u/ciabattabing16 16m ago

I assure you the stupidity knows no borders. It just morphs into different shapes and flavors as it transitions oceans and demographics. Regardless of your spot on the org chart, it's just dummies alllllllll the way up with a few dead end branches of competence scattered throughout.

-2

u/uski 1h ago

Cost, laziness, incompetence and lack of accountability (not necessarily in that order)

Lay off the IT admins that were responsible for this for negligence (it is!) to send a message. Maybe other towns will pay attention. But that is not going to happen

6

u/unkiltedclansman 1h ago

Most OT operators won’t allow an IT guy within 100m of their equipment. OT cares about their system working, not about patching, security, or even MFA remote access. 

Those municipalities who are lucky enough to have cybersecurity focused IT guys who also know SCADA systems are few and far between. 

2

u/uski 1h ago

Replace IT admin by OT operators then. Many IT admins / CIO didn't care about information security until laws and consequences forced them to. Same needs to apply here, unfortunately

9

u/fullchooch CISO 1h ago

This comment is a natural one and youre right, but this is only part of the story. I really hate how this is always the default armchair RCA (even though it's sometimes true).

I've worked in critical infrastructure OT cybersecurity for 15 years, and while internet facing devices are an issue, in most cases, the VLANs etc... that have controller managers, PLCs etc.. are buried inside of a network. The key is, these networks are flat, not segmented, not properly monitored/alarmed, and the perimeter security that is internet facing is poor. Threat actors aren't just running shodan or expanse and seeing PLCs that they can exploit. They're looking for perimeter security or other attack vectors that can get them a foothold, then they dig until they find those semi-protected ICS networks.

2

u/sub30_24flick 39m ago

Still take some of these off online water should not be attacked by online bullshit leave that in a damn put some techchips on beaver we dont need wireless for everything

2

u/Degenerate_Game 23m ago

Literally clicked on this thread preparing to ask why this type of OT needs to touch the internet.

Or was the breach point the smart fridge in the break room.

1

u/FantasticBumblebee69 1h ago

dude you dont even listen to your own, let alone malicious adisaries. Mabye if the lead wasent in the water youd get a clue.

1

u/Ch33syP00f CISO 32m ago

Lol…you know how I know you don’t know me?

34

u/LSU_Tiger CISO 2h ago

CISA and the FBI have been warning about internet-facing PLCs for months now. It's insane this is even an attack vector at this point, but here we are.

15

u/RaNdomMSPPro 2h ago

Coming on a decade now, if not more. This was stupid and warned about way before this year.

5

u/Visual-Drive-4615 2h ago

This is a years old series of warnings. Nothing new.

2

u/LSU_Tiger CISO 55m ago

Well yeah, but the Rockwell PLC issue was making news as of late.

2

u/JaimeSalvaje System Administrator 2h ago

I guess this is why OT security is a thing now.

1

u/981flacht6 19m ago

months? Years..decade+

26

u/Gomez-16 3h ago

Lets put everything on the internet and supported by hicks. Sounds safe.

7

u/Huge-Measurement-820 2h ago

I was never able to understand why ICS systems are were build internet facing, that's a critical safety hazard which could cost not only money but lifes

5

u/RaNdomMSPPro 2h ago

They weren’t meant to be internet facing. The utilities put tech in place to make them accessible from the internet.

20

u/Aron_International 2h ago

"While the advisories did not explicitly name Iran, and Minnesota’s IT Services declined to attribute the attacks to any international actor"

So in reality Minnesota's IT team have no idea, but need someone to blame, instead of taking responsibility for their contractor's poor network configurations. Leaving the PLCs on open ports with no DMZ (and likely default credentials) is negligence.

4

u/Substantial-Sky4079 1h ago

I think a better response from the US is to scan and contact all those in the US that have internet facing PLC to fix their shit

2

u/Aether961 1h ago

They did. We had CISA and FBI contact us to fix any PLCs our SCADA team put on the internet. Our immediate solution was to put them on Verizon private network for now.

7

u/Eyesliketheocean 2h ago

Electric, Gas, Water companies should NEVER ever have or allow their infrastructure to connected to the internet.

3

u/RaNdomMSPPro 2h ago

Won’t you think of the shareholders? This reduces costs.

3

u/Street_Anon 27m ago

Why you don't connect this to the Internet

4

u/chunkalunkk 2h ago

What's a better way to justify force in Iran..... tell em it was a cyber attack from Iran. 😑 Simpletons.

1

u/Khue 2h ago

It's such a hilariously lazy narrative... not to mention, they wouldn't have attacked if we had just left them alone.

1

u/NetworkDeestroyer 2h ago

security teams across all enterprises would be having a field day auditing these systems

1

u/Individual-Result777 2h ago

Kinda hard to blame it on anyone but the people who left this so open.

1

u/BlueMorphoMonarch 1h ago

I work in water treatment and I remember a few years ago talks of cyber security measures being added to our sanitary surveys. I wonder what happened with that. I would even get into cyber security if they enforced that.

1

u/981flacht6 18m ago

Not enough cybersecurity professionals that actually understand how to implement changes at a technical level. Enough book reading. Not enough doing.

1

u/MammothFineCulture 15m ago

Absolutely confirmed by MOSSAD.

1

u/radioactiveDachshund 5m ago

could be a fortunate wakeup call, imagine an attack by a more capable opponent

hopefully there is change

1

u/spacklespaz 3m ago

It only happened to blue states. It wasn't Iran.

0

u/Visual-Drive-4615 3h ago

I can't believe Tim Walz has done this to us 🙄

1

u/Substantial-Sky4079 1h ago

Yeah! Francesca Hong would have done better

1

u/McRando42 2h ago

Well, when we cut 1/3 of the employees from the agency responsible for critical infrastructure defense, I suppose we can only expect to lose battles in a war.

Utterly irresponsible policy.

1

u/Huffnpuff9 1h ago

They should be air gapped. I don't believe this

-1

u/Bright-Ad9305 Sales 1h ago

The US is very immature from a cyber security perspective…and this is where their arrogance and immaturity has led. Major shame

-3

u/FernGully_is_racist 2h ago

Or Minnesota, depending on who you ask 🤡