THE Cybersecurity and Infrastructure Security Agency (CISA) is urging water and wastewater system operators to secure operational technology against cyber threats, especially targeting programmable logic controllers (PLCs). This call follows a coordinated attack that disrupted numerous water utilities in Minnesota, highlighting an increase in attempts by threat actors to compromise PLCs. CISA recommends removing exposed PLCs from the internet and implementing strict access controls.
The recent attacks are suspected to relate to Iran-linked hacker groups, with concerns raised about vulnerabilities in critical infrastructure devices. CISA urges operators to take immediate protective measures, including enhancing password security and verifying external connections.