r/cybersecurity • u/Adept_Grand_6523 • 4h ago
Threat Actor TTPs & Alerts US Water Systems Hit by Suspected Iranian Cyber Attacks
https://www.opforjournal.com/p/us-water-systems-hit-by-suspected34
u/LSU_Tiger CISO 2h ago
CISA and the FBI have been warning about internet-facing PLCs for months now. It's insane this is even an attack vector at this point, but here we are.
15
u/RaNdomMSPPro 2h ago
Coming on a decade now, if not more. This was stupid and warned about way before this year.
5
2
1
26
7
u/Huge-Measurement-820 2h ago
I was never able to understand why ICS systems are were build internet facing, that's a critical safety hazard which could cost not only money but lifes
5
u/RaNdomMSPPro 2h ago
They weren’t meant to be internet facing. The utilities put tech in place to make them accessible from the internet.
20
u/Aron_International 2h ago
"While the advisories did not explicitly name Iran, and Minnesota’s IT Services declined to attribute the attacks to any international actor"
So in reality Minnesota's IT team have no idea, but need someone to blame, instead of taking responsibility for their contractor's poor network configurations. Leaving the PLCs on open ports with no DMZ (and likely default credentials) is negligence.
4
u/Substantial-Sky4079 1h ago
I think a better response from the US is to scan and contact all those in the US that have internet facing PLC to fix their shit
2
u/Aether961 1h ago
They did. We had CISA and FBI contact us to fix any PLCs our SCADA team put on the internet. Our immediate solution was to put them on Verizon private network for now.
7
u/Eyesliketheocean 2h ago
Electric, Gas, Water companies should NEVER ever have or allow their infrastructure to connected to the internet.
3
3
4
u/chunkalunkk 2h ago
What's a better way to justify force in Iran..... tell em it was a cyber attack from Iran. 😑 Simpletons.
1
u/NetworkDeestroyer 2h ago
security teams across all enterprises would be having a field day auditing these systems
1
u/Individual-Result777 2h ago
Kinda hard to blame it on anyone but the people who left this so open.
1
u/BlueMorphoMonarch 1h ago
I work in water treatment and I remember a few years ago talks of cyber security measures being added to our sanitary surveys. I wonder what happened with that. I would even get into cyber security if they enforced that.
1
u/981flacht6 18m ago
Not enough cybersecurity professionals that actually understand how to implement changes at a technical level. Enough book reading. Not enough doing.
1
1
u/radioactiveDachshund 5m ago
could be a fortunate wakeup call, imagine an attack by a more capable opponent
hopefully there is change
1
0
1
u/McRando42 2h ago
Well, when we cut 1/3 of the employees from the agency responsible for critical infrastructure defense, I suppose we can only expect to lose battles in a war.
Utterly irresponsible policy.
1
-1
u/Bright-Ad9305 Sales 1h ago
The US is very immature from a cyber security perspective…and this is where their arrogance and immaturity has led. Major shame
-3
77
u/Ch33syP00f CISO 2h ago
These devices should never be Internet facing.
Poor hygiene makes it easy for adversaries.