Business

Cyberattacks Target US Water Utilities via Exposed Control Systems, FBI and EPA Warn

Federal advisories follow intrusions into Minnesota facilities, exposing systemic cybersecurity risks across public drinking water infrastructure.

Federal law enforcement and environmental regulators have issued operational warnings following direct cyber intrusions into municipal water utilities in Minnesota, where hackers bypassed corporate office networks to gain control of physical infrastructure regulating public drinking water.

According to a July 30 advisory released jointly by the FBI and the Environmental Protection Agency, attackers gained unauthorized remote access to Rockwell Automation MicroLogix programmable logic controllers connected directly to the internet. Once inside the operational network, the intruders altered the controllers’ IP addresses and administrative passwords to secure access.

The targeted hardware serves as the primary automated control layer for physical water management. Programmable logic controllers interpret operational data from field sensors measuring water chemistry, system pressure, tank levels, and equipment status, automatically executing commands for pumps, filtration hardware, and chemical treatment valves across municipal networks.

Utility operators countered the intrusions by disconnecting automated control networks and deploying field personnel to manage equipment manually. Municipal officials confirmed that drinking water safety was maintained throughout the incidents.

The Minnesota intrusions highlight structural vulnerabilities across the nation’s approximately 152,000 public drinking water systems. Many municipal utilities operate with minimal staffing and constrained technical budgets, relying on remote internet connections to monitor geographically dispersed pumps, reservoirs, and treatment infrastructure.

Industrial control systems are routinely exposed through automated internet scans searching for public IP addresses, unpatched software vulnerabilities, or default credentials. The Cybersecurity and Infrastructure Security Agency reported that in 2023, Iranian-linked threat actors targeted internet-connected Unitronics programmable logic controllers deployed at U.S. water facilities that still utilized factory-default passwords.

Legacy equipment operating across public utilities compounds cyber risks, as industrial machinery deployed for decades often lacks modern security features, while operators delay firmware updates to prevent operational shutdowns. Cyber researchers at the National Institute of Standards and Technology noted that intruders gaining access to controller networks can overwrite legitimate instructions with malicious commands.

Following the Minnesota incidents, CISA urged water utilities to isolate all programmable logic controllers and operational dashboards from direct internet visibility. Federal guidance recommends routing remote operational communications through firewalls, encrypted virtual private networks, and multi-factor authentication while completely disconnecting control networks from corporate email and administrative systems.

Resource limitations remain a key barrier for small and rural utilities attempting to implement defensive upgrades, where volunteer cybersecurity advisors provide guidance but lack the capacity to cover thousands of underfunded municipal systems nationwide.

The Conversation

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button