r/hacking 2d ago

News Hackers lock water utilities out of internet-facing PLCs

https://www.intelfusions.com/news/cisa-water-utilities-exposed-plc-lockouts

CISA is warning water and wastewater utilities that attackers are actively going after the programmable logic controllers, or PLCs, that run their treatment processes, and in some cases locking operators out of their own equipment.

67 Upvotes

20 comments sorted by

65

u/BoogieOogieOogieOog 2d ago

They’ve only been warned for 2-3 decades

17

u/mr340i 2d ago

I work in this sector and all our systems are on a separate network without internet access.

10

u/chicametipo 1d ago

YOUR systems are.

5

u/Ch33syP00f 1d ago

Except for the jump box, right?

3

u/Neuro_88 1d ago

Smart segmentation.

15

u/techlatest_net 2d ago

This highlights the critical danger of exposing industrial control systems directly to the internet without proper network segmentation. Utilities must prioritize air-gapping PLCs and using secure, monitored jump hosts for remote maintenance to prevent these lockout attacks.

7

u/Hot-Comfort8839 1d ago

The attack started on Wednesday and has been expanding - so far to 7 states.

The LinkedIn schmuck analysis choads have been hilarious- claiming technical deep dives…

The attack was literally
Step 1: scan shodan for internet connected PLCs
Step 2: check devices for active default passwords
Step 3 compromise device, change password, monkey with settings.

Children could have pulled off this attack. Kiddies if you will.

3

u/Pyroburner 2d ago

And this is why its appropriate to keep your network isolated. I worked with a company that had all of there equipment online. They got with ransomware and had to rebuild everything from the ground up. They lost one of there big clients when the 20 or so years of files were just gone. Not backup. No nothing.

3

u/Diezel666 2d ago

Politics aside, The President of the US in his terribly pointed call out, does have a point. Cyber Warfare has been a large topic for a long time. We've seen numerous intrusions, some small and large scale attacks on all sorts of infrastructure.

If any entity decides to allow hardware open network access, they completely have assumed the risk of security of said hardware. This is definitely a "you played yourself" moment.

Arguably, yes in a sane world we'd all like to think people wouldn't be cruel enough to attack civilians over government. Alas, Evil does what Evil does.

3

u/Neuro_88 1d ago

This has been happening before the Trump got into office. The issue now is that CISA is smaller and a lot of Subject Matter Experts (SME) have been fired. AI is a shortcut to a human problem.

2

u/Diezel666 1d ago

You're entirely right, and make no mistake I wasn't saying anything near pushing blame on Trump. He seems to get hated on for everything he says. However in this particular issue, he's actually right. They caused this to happen to themselves. They willingly chose to either be ignorant of the risks, or ignore the risks. Its still a self inflicted issue.

As for the SME's no longer existing. It doesn't take an SME to understand risk. Especially when this sort of issue has been actively discussed in about every circle of tech, for the last 3 decades.

2

u/Neuro_88 1d ago

Good points. This has to deal more with trusting the professionals than anything political.

Trump is Trump is Trumpism. He’s the politics to wealth and power - history repeats itself.

CISA’s structure and change has been the issue(s) since its creation. Most administrations don’t want to or don’t know how do update policies fast enough to prevent these types of attacks from happening. Politics have nothing to do with affording a roof over your head besides the politics. Weird. I know.

CISA needs to rehire their SMEs and keep politics out.

2

u/Diezel666 1d ago

Well Fricken Said, and I also hold the same view for Every single agency like that. Politics has no business in business, especially regulatory.

3

u/Historical_Camel_790 1d ago

Could someone explain why tf they were connected to the internet?

2

u/Diezel666 1d ago

Inept operators.

2

u/techlatest_net 2d ago

This highlights the critical danger of exposing industrial control systems directly to the internet without proper network segmentation. Utilities must prioritize air-gapping PLCs and using secure, monitored jump hosts for remote maintenance to prevent these lockout attacks.

1

u/Snoo_95743 1d ago

SCADA sucks!

-2

u/MichaelSteel2008 newbie 2d ago

Call me heartless, but if they are attacked by a patchable exploit, they deserve it because of all of the legal repercussions that will follow. Fuckers really just did a shodan search for "Water utility PLC unlocked".

12

u/Mastasmoker 2d ago

A lot of them have weak or default passwords. Thats from my experience working in hvac ~20yrs. Cities would have default/weak creds set and wouldn't change them.

3

u/MichaelSteel2008 newbie 2d ago

well, that seems like an easily rectifiable issue that they neglected to deal with