Background Image
 
Request a Demo
Claroty Toggle Search
Return to Blog

Minnesota Water Cyberattack Highlights U.S.'s Under-resourced, Fragmented Critical Infrastructure Systems

/ / 6 min read

More than 30 community water systems in Minnesota were impacted on July 26 and 27 by a coordinated cyberattack targeting operational technology (OT) at the facilities. While few specifics have been made public, news of the attacks came four days after an updated joint cybersecurity advisory from law enforcement and the government warning of Iran-affiliated groups exploiting programmable logic controllers (PLCs) across U.S. critical infrastructure

The original joint advisory warned of attacks leveraging vulnerabilities in Rockwell Automation PLCs; last week’s update expanded to include targeting of Schneider Electric, Siemens, and other PLCs that were internet-facing. 

This blog will explore the Minnesota incident:

  • Underscoring why the fragmented water sector is a target

  • Explaining the risk of internet-facing CPS and OT assets

  • Providing advice for organizations potentially in the crosshairs of similar attacks

Fragmented Water Sector Vulnerable to Cyberattacks

The Minnesota incident underscores the fragile, fragmented nature of the water and wastewater critical infrastructure sector. The country’s 148,000-plus public water systems are notoriously under-resourced, with every dollar and every scrap of expertise given to keeping water clean and available for the cities and towns they support. 

While recognizing the risks posed by threat actors, resources for OT cybersecurity and control system protection, is generally at a minimum. Often, IT help is shared between towns through service providers; there’s little in the way of an OT cybersecurity program.

This dynamic ramps up the interest of threat actors, including state actors such as Iran, wishing to shake the confidence of Americans in the government’s ability to protect them by targeting critical resources such as water and energy. 

None of the affected communities in Minnesota reported water quality issues, however, on July 27 the City of Braham reported that its plant was offline and requested that citizens minimize public water usage, such as watering lawns or recreation. The City of Maple Plain, meanwhile, enacted a state of emergency in order to pursue state and federal resources; it said drinking water remained safe. 

Internet-Facing CPS/OT Exposes Sector to Opportunistic Attacks

Further compounding the risk at these sites is the continued practice of connecting OT, PLCs, supervisory control and data acquisition (SCADA) systems, and human-machine interfaces (HMIs) directly to the internet. This is leading to a rise in opportunistic attacks where state actors or hacktivist groups sympathetic to adversarial nation-states are using publicly available internet scanning services to enumerate exposed cyber-physical systems (CPS) assets, and exploit known vulnerabilities, weak authentication, legacy protocol communication, or poor configurations in order to disrupt services. 

The accessibility of HMIs, PLCs, and SCADA online is particularly concerning given their impact on physical processes. Not only can any malicious manipulations of these assets cause outages, but could also threaten public safety or the welfare of plant employees. 

Exposed internet-facing CPS and OT assets are also enabling threat actors to better understand how critical infrastructure ecosystems fit together. In the case of the Minnesota attacks, the fact that 30 systems were targeted in a coordinated manner indicates a shared dependency. At this point, it’s only speculation as to whether that’s a common technology such as the affected PLCs noted in the joint advisory, a common service provider, or weakness in a broader state-level IT backbone. 

Attackers are scanning broadly for widely used devices exposed to the internet, and in this case, found a concentration of exposures in Minnesota that should create urgency well beyond the state. These controllers are used across critical infrastructure and have increasingly become points of entry since the beginning of fighting in Iran and across the Middle East. 

The Iran-affiliated CyberAv3ngers and Handala groups have been prominent in Iran’s offensive cyber operations. The groups’ activity—notably the CyberAv3ngers’ targeting of Unitronics integrated PLCs/HMIs and the IOCONTROL malware framework, and Handala’s takedown of a U.S. healthcare supplier Stryker—focuses on OT and connected IoT devices important to civilian infrastructure. 

Attackers have also invested in developing malware frameworks, exploit kits and other purpose-built platform-specific attacks against legacy edge devices and even big-iron firewalls from leading vendors. Attackers can use these exposures to map network traffic and understand pathways that lead to CPS and other exposed assets. 

How to Secure Critical Infrastructure CPS Assets

Opportunistic attackers are taking advantage of a perfect storm of exposures and technical debt to attempt to disrupt critical services and sow chaos among U.S. citizens. Asset operators should take a number of steps to lock down CPS assets. 

  1. Disconnect Internet-Facing Controllers

Operational controllers should not be directly exposed to the internet. Inbound port exposures should be closed off to keep CPS and OT assets from direct connectivity to the internet. Any inbound communication that is essential should go through a secure gateway or jump host to ensure it’s monitored and controlled if need be. In the case of Plymouth, Mn., city officials said the affected OT equipment communicated over cellular connections, which are often used for remote field access. Asset operators should ensure that access to those cellular modems are protected with strong authentication at a minimum.

  1. Control Network and Remote Access to CPS, OT Assets

Communication between assets should be configured via firewall rules and access control lists, and only authorized communications permitted. A list of threat actor-controlled IP addresses available from the joint advisory should also be used to block unauthorized access. Secure access to OT and CPS assets, meanwhile, should be enabled only through a purpose-built solution that logs activity and enables operators to close off sessions in the event of malicious activity. In addition, all default passwords should be changed. 

  1. Review PLC Project Files for Unauthorized Changes

Last week’s updated joint advisory indicated that malicious OT project files were being downloaded to PLCs causing disruption at numerous critical infrastructure organizations. The advisory recommends using integrity checking tools to compare the running project file to a known good logic. If restoring a compromised asset from backups, organizations must verify that the backup does not include the malicious logic before deploying. 

  1. Segmentation a Key Compensating Control

Segmentation and microsegmentation of CPS and OT assets is an integral part of a CPS protection strategy. Virtually isolating sensitive network segments helps contain the blast radius of any incident. Asset operators can use segmentation to prevent lateral movement among assets in the event of a compromise, and enforce security policies per zone.

Operational Technology (OT)

Related Articles

Tagged with Operational Technology (OT)

Interested in learning about Claroty's Cybersecurity Solutions?

Background Image

Life, uninterrupted

We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.

Claroty
LinkedIn Twitter YouTube Facebook