Number of US Water Systems Hacked or At Risk Grows
Remember when, in late July, we learned about a half dozen or so water systems in Minnesota that were hacked and the president said that was due to Minnesota’s ‘gross incompetence’ (Reference: Fox9) and not Iran?
Very quickly that number grew to 30 systems, still in Minnesota (Reference: Statescoop)
Within a day, reporting morphed to say that water systems around a half dozen states were impacted, causing some to issue boil water notices and others to go to manual control (Reference: CNN)
That same day the New York Times put that number at “at least 100” and attributed the attack, contrary to the president, to Iran (Reference: The NY Times via The Register).
Today it is being reported that two small Colorado water systems were compromised. The hackers changed equipment settings, disabled remote access and alarms and altered pumping cycles. The government is refusing to say what systems were impacted, other than that they were small (Reference: Security Week).
Now researchers are reporting that well over a thousand US water and wastewater providers are exposed to attack due to malware that stole employees’ passwords.
SpyCloud, a cybersecurity firm, said it was able to build a database of more than 66,000 public facing systems and those are just from those registered with the EPA. Note that the estimate is that there are actually about 150,000 water systems in the US, so again, this number is just the tip of the iceberg.
The 66,000 systems represents, they say, around 10,000 organizations.
They also say that the malware had stolen credentials from 1,787 organizations – roughly 2 out of ten that they checked. Meaning, that number is low.
They also said that at least 250 organizations had credentials stolen that exposed their water control systems (O.T.) and remote access systems. These are how these systems control pumps, water flow, chemicals, etc.
Likely, these stolen passwords are for sale on the dark web to anyone who has some Bitcoin or other cryptocurrency.
While Congress is a deer in the headlights when it comes to this and the president is testing a concept in some Texas critical infrastructure for a few months, the hackers are HONING their attack technique. At this point, they are just toying with the operators of water systems.
Most of these water systems and wastewater systems are small. Combine all of this with antiquated systems, horrible security practices, no security staff except at the largest systems and you have a recipe for disaster and it is just starting.
Recently a pipe failure in a sewage system near Pueblo, Colorado dumped 4 million plus gallons of raw sewage into the Arkansas River, causing public health officials to tell people to don’t even go near the river (Reference: Outside). While this was not a cyber attack, in many systems a cyber attack could produce the same result.
Are you prepared?
Credit: Tech Crunch
