CISA still finds water system controls exposed online amid multistate hacks

Brandon Bell/Getty Images

The agency is working with the FBI to help victims but is not attributing the cyber intrusions to any group, acting director Nick Andersen told Nextgov/FCW.

LAS VEGAS — Federal cyber officials are still finding water system controls exposed to the public internet, even as the Cybersecurity and Infrastructure Security Agency and the FBI help utilities recover from a series of cyberattacks affecting at least 12 states, acting CISA Director Nick Andersen told Nextgov/FCW on Thursday.

“We’re seeing things like [programmable logic controllers] that are open and accessible on the internet with either no password set or default password set,” Andersen said in a brief interview on the sidelines of the Black Hat cybersecurity conference. “We’re not making ourselves hardened targets.”

Programmable logic controllers, commonly dubbed PLCs, are small computers used to operate pumps, valves and other equipment inside water facilities. Connecting them to the internet can allow operators to manage equipment remotely but it can also give hackers a path into systems that directly control physical processes.

Andersen said CISA’s immediate guidance to utilities remains straightforward: “Get your operational technology off the internet, set a password.”

The remarks come about a week after CISA warned that hackers were increasingly targeting internet-connected controllers used by water and wastewater utilities. The agency said attackers had changed passwords and other settings, locking out operators and contributing to water pressure problems, boil-water notices and extended periods of manual operation.

More than 30 community water systems in Minnesota were targeted late last month, according to state officials. Around 12 states have reported similar activity in recent days, though state officials said they continued operating safely and experienced no known effects on public health. The FBI has said it is aware of the incidents. Andersen also said CISA is working with the FBI on incident response.

But the cyberdefense agency isn’t attempting to determine publicly who was responsible for the hacks, he said. 

Some U.S. officials suspect Iran-linked hackers carried out the attacks. A CISA notice distributed to water utilities last month said the activity in Minnesota shared characteristics with an earlier campaign involving Iran-affiliated hackers, though it didn’t provide direct evidence linking the latest incidents to Tehran. 

“For us, we’re not doing anything with attribution right now,” Andersen said, explaining the agency is instead focused on assisting affected organizations, educating operators and improving the sector’s security over the longer term.

CISA also tries to identify vulnerable organizations before they are attacked by examining the broader collection of internet-facing systems, Andersen said. When the agency discovers a potentially exposed device or another security problem, it coordinates with other agencies and contacts the operator, he added. 

Andersen couldn’t provide a precise estimate of how many exposed or poorly secured devices remain online.

Water utilities can be difficult to secure because many are small, have limited budgets and depend on aging equipment installed and maintained by multiple contractors. Still, Andersen said infrastructure operators bear some responsibility for taking basic precautions that can make their systems more difficult to compromise.

“There’s a degree of personal responsibility there to sort of engage in these minimum requirements that are feasible for helping to continue to secure yourselves,” he said.