Skip to content

Product1 publisher3 min readPublished

Attackers changed water plant PLC passwords and IP addresses to lock operators out, CISA says

Gizmodo counts dozens of US water treatment plants attacked since February. The security consortium director it interviewed says the connection itself matters less than what the utility does with the data coming back off the controller.

The Product Desk · Product desk

Illustration accompanying Attackers changed water plant PLC passwords and IP addresses to lock operators out, CISA says

What happened

  • CISA's July alert said threat actors had changed passwords on water plant programmable logic controllers to lock out the proper operators, and changed IP addresses to disconnect the controllers.
  • Gizmodo reports that dozens of US water treatment plants have come under cyberattack since the US and Israel went to war with Iran in February.
  • CISA issued the first warning of this kind in April, and that one specifically mentioned Iran.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint A remote link that replaced a site visit leaves a utility with nothing to fall back on the night the password changes, unless someone on shift still knows how to run the plant on paper.
  • contradiction The alerts point at the exposed controller. Jones locates the risk in how field data is protected once it moves into the utility's IT systems. Each reading means spending the money on a different thing.
  • exposure If the attacker's interest is usually downstream, as Jones says, then the defense sites and industrial customers fed by a small utility's water inherit the consequences of that utility's controller settings.
  • precedent Where state cyber rules track Department of Defense presence, utilities elsewhere carry the same exposure without the mandate that would pay for fixing it.

A controller's network port is sold as remote monitoring. An operator sees pressure and setpoints without driving out to the plant, and the controllers come from Rockwell Automation/Allen-Bradley, Schneider Electric and Siemens [7]. CISA's July alert describes the same access being used to change passwords so the proper operators are locked out, and to change IP addresses so the controller drops off the network [2].

The attacker gets in over the connection that saves the operator the drive. When the password changes, the operator loses the screen, and the plant's actual controls are where they have always been, inside the building.

CISA says tampering with a controller in even a relatively minor way can cause a loss of water pressure, and that lost pressure can let untreated groundwater seep into pipes [5]. In Georgia, according to the FBI and EPA, Clayton County Water Authority and Columbus Water Works were attacked in the past month and the attacks triggered water pressure disruptions [6]. Gizmodo's account does not describe how the attackers reached the controllers at either utility [16].

Betsy Soehren Jones, Executive Director of the Critical Infrastructure Security Consortium, puts the problem further inside the utility than the modem. "It's not the fact that they're connected to the internet that is always the issue. It's more about when the information comes back into the company. How is that company and that utility protecting the information as it's moving from that field device, into the water company, going into another IT system, et cetera," she told Gizmodo [8].

Jones also wants drills. She said utilities need exercises like the ones they already run for hurricanes and earthquakes, which means going back to paper and pencil and teaching staff how the plant ran 10 or 15 years ago [10]. "We just need to teach this generation how to get back to paper very, very quickly. It's gonna happen. This is not gonna stop," said Jones [9].

Her other point is about who the target is. "It's usually not the utility they're after; it's usually the downstream piece that they're after," said Jones [11]. "What if that water facility is feeding a nuclear power plant, you know, is it going to affect the cooling towers?" she said [12]. She named Maryland, Virginia and California as states where utilities are doing well, and tied that to the number of Department of Defense facilities those states host [13].

For the person who has to answer for this at a small utility, the useful test has two lines to fill in per remote connection. One: the site visit the connection replaced, and the named person on shift who would make that visit tonight if the link went dark. Two: the person who notices within an hour if a controller's password changes at 2am, and what they look at instead of the dashboard. If the connection replaced a trip nobody on shift can still make, it is the control path, and it should be protected and watched like one. The alerts Gizmodo describes ran from April to July, about three months apart, with the first one naming Iran [15][4].

What to watch

  • Whether CISA, the FBI or EPA describes the access path used at Clayton County Water Authority and Columbus Water Works.
  • Whether manual-operation drills of the kind Jones describes become a requirement rather than a recommendation for water utilities.
  • Whether cyber rules spread to states without the Department of Defense presence Jones credits in Maryland, Virginia and California.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories