More than 30 community water systems in Minnesota were impacted on July 26 and 27 by a coordinated cyberattack targeting operational technology (OT) at the facilities. While few specifics have been made public, news of the attacks came four days after an updated joint cybersecurity advisory from law enforcement and the government warning of Iran-affiliated groups exploiting programmable logic controllers (PLCs) across U.S. critical infrastructure.
The original joint advisory warned of attacks leveraging vulnerabilities in Rockwell Automation PLCs; last week’s update expanded to include targeting of Schneider Electric, Siemens, and other PLCs that were internet-facing.
This blog will explore the Minnesota incident:
Underscoring why the fragmented water sector is a target
Explaining the risk of internet-facing CPS and OT assets
Providing advice for organizations potentially in the crosshairs of similar attacks
The Minnesota incident underscores the fragile, fragmented nature of the water and wastewater critical infrastructure sector. The country’s 148,000-plus public water systems are notoriously under-resourced, with every dollar and every scrap of expertise given to keeping water clean and available for the cities and towns they support.
While recognizing the risks posed by threat actors, resources for OT cybersecurity and control system protection, is generally at a minimum. Often, IT help is shared between towns through service providers; there’s little in the way of an OT cybersecurity program.
This dynamic ramps up the interest of threat actors, including state actors such as Iran, wishing to shake the confidence of Americans in the government’s ability to protect them by targeting critical resources such as water and energy.
None of the affected communities in Minnesota reported water quality issues, however, on July 27 the City of Braham reported that its plant was offline and requested that citizens minimize public water usage, such as watering lawns or recreation. The City of Maple Plain, meanwhile, enacted a state of emergency in order to pursue state and federal resources; it said drinking water remained safe.
Further compounding the risk at these sites is the continued practice of connecting OT, PLCs, supervisory control and data acquisition (SCADA) systems, and human-machine interfaces (HMIs) directly to the internet. This is leading to a rise in opportunistic attacks where state actors or hacktivist groups sympathetic to adversarial nation-states are using publicly available internet scanning services to enumerate exposed cyber-physical systems (CPS) assets, and exploit known vulnerabilities, weak authentication, legacy protocol communication, or poor configurations in order to disrupt services.
The accessibility of HMIs, PLCs, and SCADA online is particularly concerning given their impact on physical processes. Not only can any malicious manipulations of these assets cause outages, but could also threaten public safety or the welfare of plant employees.
Exposed internet-facing CPS and OT assets are also enabling threat actors to better understand how critical infrastructure ecosystems fit together. In the case of the Minnesota attacks, the fact that 30 systems were targeted in a coordinated manner indicates a shared dependency. At this point, it’s only speculation as to whether that’s a common technology such as the affected PLCs noted in the joint advisory, a common service provider, or weakness in a broader state-level IT backbone.
Attackers are scanning broadly for widely used devices exposed to the internet, and in this case, found a concentration of exposures in Minnesota that should create urgency well beyond the state. These controllers are used across critical infrastructure and have increasingly become points of entry since the beginning of fighting in Iran and across the Middle East.
The Iran-affiliated CyberAv3ngers and Handala groups have been prominent in Iran’s offensive cyber operations. The groups’ activity—notably the CyberAv3ngers’ targeting of Unitronics integrated PLCs/HMIs and the IOCONTROL malware framework, and Handala’s takedown of a U.S. healthcare supplier Stryker—focuses on OT and connected IoT devices important to civilian infrastructure.
Attackers have also invested in developing malware frameworks, exploit kits and other purpose-built platform-specific attacks against legacy edge devices and even big-iron firewalls from leading vendors. Attackers can use these exposures to map network traffic and understand pathways that lead to CPS and other exposed assets.
Opportunistic attackers are taking advantage of a perfect storm of exposures and technical debt to attempt to disrupt critical services and sow chaos among U.S. citizens. Asset operators should take a number of steps to lock down CPS assets.
Disconnect Internet-Facing Controllers
Operational controllers should not be directly exposed to the internet. Inbound port exposures should be closed off to keep CPS and OT assets from direct connectivity to the internet. Any inbound communication that is essential should go through a secure gateway or jump host to ensure it’s monitored and controlled if need be. In the case of Plymouth, Mn., city officials said the affected OT equipment communicated over cellular connections, which are often used for remote field access. Asset operators should ensure that access to those cellular modems are protected with strong authentication at a minimum.
Control Network and Remote Access to CPS, OT Assets
Communication between assets should be configured via firewall rules and access control lists, and only authorized communications permitted. A list of threat actor-controlled IP addresses available from the joint advisory should also be used to block unauthorized access. Secure access to OT and CPS assets, meanwhile, should be enabled only through a purpose-built solution that logs activity and enables operators to close off sessions in the event of malicious activity. In addition, all default passwords should be changed.
Review PLC Project Files for Unauthorized Changes
Last week’s updated joint advisory indicated that malicious OT project files were being downloaded to PLCs causing disruption at numerous critical infrastructure organizations. The advisory recommends using integrity checking tools to compare the running project file to a known good logic. If restoring a compromised asset from backups, organizations must verify that the backup does not include the malicious logic before deploying.
Segmentation a Key Compensating Control
Segmentation and microsegmentation of CPS and OT assets is an integral part of a CPS protection strategy. Virtually isolating sensitive network segments helps contain the blast radius of any incident. Asset operators can use segmentation to prevent lateral movement among assets in the event of a compromise, and enforce security policies per zone.
Understanding OT in Healthcare to Strengthen Resilience
Beyond the Purdue Model: ICS Security in Modern, Complex Network Architectures
OT Asset Discovery: 5 Steps to Gain Visibility for Your Network Assets
Interested in learning about Claroty's Cybersecurity Solutions?
Life, uninterrupted
We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.