More Than 30 Minnesota Water Systems Targeted In Cyberattack (fox9.com) 65
jrnvk shares a report from KMSP: Minnesota IT Services reports that a "coordinated cyberattack" targeted technology at more than 30 community water systems between Sunday, July 26 and Monday, July 27. The state has activated its cybersecurity incident response capabilities to respond to the attacks.
On Monday and Tuesday, FOX 9 reported on notices from four cities that had disclosed the attacks: Plymouth, South St. Paul, Maple Plain, and Braham. All four cities said the impacts of the attacks were limited or mitigated and residents could continue normal water use. The Minnesota Department of Health is not aware of any municipality asking residents to alter their drinking water use as a result of the attacks.
State officials are working with federal and private-sector partners to investigate the attacks, support the affected communities, and strengthen the security of Minnesota's critical infrastructure.
On Monday and Tuesday, FOX 9 reported on notices from four cities that had disclosed the attacks: Plymouth, South St. Paul, Maple Plain, and Braham. All four cities said the impacts of the attacks were limited or mitigated and residents could continue normal water use. The Minnesota Department of Health is not aware of any municipality asking residents to alter their drinking water use as a result of the attacks.
State officials are working with federal and private-sector partners to investigate the attacks, support the affected communities, and strengthen the security of Minnesota's critical infrastructure.
Boss says (Score:2, Insightful)
I don't need to come into the office just to click some buttons. Give me remote access. Don't give me any of that 2FA shit either it' always hassling me. Don't give me any of those long ass passwords nobody can remember. Make it 123.
Re: (Score:2)
Re: (Score:3)
it happens in any org where people has enough clout to exempt themselves from recommended practices.
Boss' Boss says (Score:2)
I don't need to come into the office just to click some buttons. Give me remote access. Don't give me any of that 2FA shit either it' always hassling me. Don't give me any of those long ass passwords nobody can remember. Make it 123.
Boss' Boss: "Why are we paying him to remote in when we can hire an international team to remote in for 24/7 redundant button clicking at half the price of one person?"
International team: "North Korea is willing to pay us to do the job we were hired to do. Sounds tempting..."
more like team viewer on older windows version so (Score:3)
more like team viewer on older windows version so we don't need pay $4/gal + for people to drive to each site.
measurement ? (Score:1)
have anyone actually measured the values before (requires actual data) and after ?
i.e. water is life start measuring the water pressure and chemistry BEFORE complaining
Re: (Score:2)
have anyone actually measured the values before (requires actual data) and after ?
Do you have even the vaguest idea what the monitoring requirements are for water systems in the USA?
If not, why didn't you look it up?
Re: (Score:2)
Re: measurement ? (Score:1, Flamebait)
Re: (Score:1)
attack (Score:4, Interesting)
For all we know they installed some new detection software and realized that their computers were being targeted by nefarious ping [wikipedia.org] packets
Re: (Score:3)
I live in Plymouth; there was no city communications about this nor did I see any issues. So, I assume there were no physical disruptions to service.
Re:attack (Score:5, Informative)
From another source [cbsnews.com] it sounds like the plant's SCADA system was compromised and shut down/disabled, causing some plants to go offline.
The immediate consequence is they would lose remote control over the pumps, fans, and valves at these facilities and either default to some safe state or just shut down entirely. Someone would have to drive over and manually reset/control everything, which is exactly what they did. Addressed promptly enough most people would even notice something was wrong.
The long term consequences could be that they end up getting incorrect status information about the facility's operation, causing a longer disruption until complaints start coming in and they have to run around trying to figure out what's wrong. Loss of water pressure, distribution of untreated water, distribution of over treated water, depletion of reserves are all obvious problems a bad enough attack could cause. Physical damage to equipment is also not impossible, which would be the worst case scenario.... you're not fixing a broken well/system pump or AOP reactor in two or three hours, and it you lose a bunch of them at once you could be at reduced capacity for months.
=Smidge=
Re:attack (Score:5, Interesting)
City Council member of a non-listed Twin Cities suburb I know:
FBI is involved. Most water systems use one of two control/alert systems that are old and make them easy targets.
All they did was shut down components of the systems e.g., wells/sewer lift stations. Most cities were able to cycle manually to get back up and running. There was not messages warning or ransom of which I am aware.
They could have done a lot more damage if they wanted to, rather than just shutting things down.
Re: (Score:3)
Re: (Score:2)
It was a "rogue AI agent" of course!
Blame Canada (Score:5, Funny)
80's kids know (Score:4, Informative)
Have we learned nothing from 80's movies? WarGames, Superman III, Jumpin' Jack Flash, The Manhattan Project, Ferris Bueller's Day Off, Prime Risk, Hide and Seek, Revenge of the Nerds, and more showed us what happens when a business or government leaves computer connected and always on.
I would recommend we not plug everything into the Internet. Or at least use two layers of authentication, one for the VPN, and one for the devices themselves on the private network. With no NAT while in the private network.
But for industries that buy off-the-shelf monitoring systems, that's not how they actually work. They are really just the equivalent of an wireless router running embedded Linux, glorifies OpenWRT to hook a site's LoRa/Zigbee/802.15.4 sensor network to a gateway to store and forward monitoring data. Ideally not doing controls, but honestly if you unplug the safety monitoring then you have to shut the whole system down. So even a sensor systems is a viable target if the goal is a simple DoS attack.
Yeah, don't computer (Score:2)
The only way to avoid having the systems hacked is to just don't computer.
Re: (Score:2)
Re: (Score:2)
A classic heist trick too, nobody checks the plumber's toolbags (in the movies). Worked for Ocean's Eleven and The A-Team.
Re: (Score:2, Interesting)
I would recommend we not plug everything into the Internet.
Not possible in today's world. Infrastructure is not just big, but relies on real time information across it accessible remotely by engineers. One could foresee a way around this by laying fibre lines with absolutely everything, but that is only cheap for new installations. How much more do you want to pay for water / power to retrofit this?
Or at least use two layers of authentication
The problem here is the age of equipment. A lot of it just isn't up to modern standards. You don't need to recommend two layers of authentication, we already have far mo
Re: (Score:2)
You'd be surprised how trivial those "layers" are to overstep for a really determined hacker.
Good! (Score:5, Insightful)
They fucking deserve everything they get. We have had more than enough close calls and incidents to clearly demonstrate to every drooling moron that critical infrastructure like water and electricity systems should never be connected to the internet. There's no reason for them to to need it.
No fucking access in or out. Fucking duh!
Air gap that shit or get the intrusion that you deserve. My private infrastructure has computer monitoring and automation. But, none of it can exchange a single packet with the internet. There's no reason that a state government with dedicated IT departments shouldn't know and do the same.
Re: (Score:2)
community water systems
These might be nothing more than a bookkeeper and an on-call plumber. And you want them to hire an IT person in a market that starts at 6 figures for a game developer that can barely fog a mirror?
We can't even get our state to ditch Microsoft.
Re: (Score:2)
Ever heard of service providers?
Incidentally, if this was not done using the cheapest possible crap (yes, Microsoft among others), this could be done pretty securely. OpenSSH, for example, has a pretty impressive security record (unless some blithering idiots in some distros patch systemd libraries in there, that is) and OpenVPN is pretty good too. This would be more than enough to secure links to, say, a central control computer. Obviously, this would need to be administrated as a service, but remote admin
Re: (Score:2)
Ever heard of service providers?
Yes. These are the people that repeatedly e-mail me to inform me that my account is full and I have to follow the included link and log on to remedy the situation.
Re: (Score:2)
Careful, your mental immaturity is showing.
Re: (Score:2)
Thank you. The wisdom and experience of a boomer, but the IT savvy of a millennial.
Re: (Score:2)
Anyone can get phished, especially these days.
Admin computers with e-mail access might also have access to the private control fabric that doesn't have direct Internet access.
Re: (Score:2)
Not really. Anyone using Outlook can get phished easily. For other MUAs it is more difficult, for some a lot more difficult. For good ones you have to convince the operator to do something obviously stupid.
Re: (Score:2)
Timing is everything.
If the circumstances are conducive to it, even the most paranoid person can get phished in a moment of distraction.
A famous, recent(ish) example is the operator of HIBP, who mistakenly fell for a credential phish because he was distracted and/or tired and the communication was something that he wasn't surprised by in the moment.
https://www.malwarebytes.com/b... [malwarebytes.com]
Re: (Score:2)
This is not about eliminating the problem. It is about making it so unlikely to happen that the bad guys give up. And we are very far from that, especially on Outlook.
Re: (Score:2)
I disagree. The connection to the Internet is not the problem. The complete lack of competently done IT Security is. IT Security done right is up to the task today.
And yes, there is reasons for having that connection and it is not only convenience. Unless you want to start digging for dedicated fiber connections all over the country at huge cost?
Re: (Score:2)
Unless you want to start digging for dedicated fiber connections all over the country at huge cost?
Would it cost more to bury that dedicated fiber with the pipes? Would it be a huge cost to build out your own wireless network, like many power companies do?
There are still many water utilities serving area with a million or more customers that do not have ANY infrastructure connected to the internet. Back office and billing, sure. Infrastructure, is not connected. How ever do they manage? They manage just fine.
Let me restate for the hard of hearing and the hard of feeling, no critical infrastructure such a
Re: (Score:3)
Re: (Score:2)
Do you know of an SDR means of decoding the new iTron meters?
I used to be able to listen to my and my neighbors' iTron meter broadcasts. But, then the power company upgraded the meters and I haven't figured out how to receive nor decode the new meters.
Re: (Score:2)
If your pipes are already in the ground and good for another 50 years? Yes. The cost makes this completely unworkable.
Re: (Score:2)
I disagree. The connection to the Internet is not the problem. The complete lack of competently done IT Security is. IT Security done right is up to the task today.
This. The bad guys and gals go after the low hanging fruit. And there is so. damned. much. of. it.
I've long said that a company - especially one involved with essential infrastructure, should have a head of IT with C-Suite level authority. And the compliance chops to go with it.
And while small companies - water in this case - might not have the money to hire such a person, if they have to use software, it comes from somewhere. So "somewhere" needs to be responsible and in the loop. If that's too muc
Re: (Score:2)
I've long said that a company - especially one involved with essential infrastructure, should have a head of IT with C-Suite level authority. And the compliance chops to go with it. And while small companies - water in this case - might not have the money to hire such a person,
The water companies aren't just regular everyday companies selling product/service to customers. A lot of what they can and must do are government mandated. Including pricing.
They can't normally just up pricing to cover all that extra stuff without state approval. Sometimes even worse the city or state requires the public to vote on such things (although I don't know if that's the case here)
With normal companies, short sighted spending (or lack of it) tends to solve itself, but any in bed with the government have to deal with being between a rock and a hard place.
Then it is an unsolvable problem, and people will be harmed. It's a pity that there aer easily solvable problems for some that have no possible solution for others.
Re: (Score:2)
The "small utility problem" can be solved. C-level CISO "as a service" or part time is entirely doable. You just need to want to do it.
Re: (Score:2)
In this instance, you and I agree completely.
Re: (Score:2)
So you've never heard of social engineering, which can breach airgapped systems.
Re: (Score:2)
No fucking access in or out. Fucking duh!
Airgap isn't compatible with modern infrastructure requirements. Your city is bigger than the town of yesteryear. Remote control is a necessity, not just for basic control and optimisation but in many cases to maintain things like safe water quality.
Sure you could setup your own network, lay your own fibre, but how much do you want to pay for water?
The reality is the problem here is basic cybersecurity standards weren't in place which is not surprising for old infrastructure.
By the way air-gapped systems ar
Minnesota (Score:2)
"Land of 10,000 Lakes". So, who cares? Just grab a bucket.
Wrong headline (Score:5, Insightful)
A better one would be "More than 30 Minnesota water systems have IT security that completely sucks".
Seriously, without liability (including personal one) and strict qualification requirements, the total crap-show that IT security is today will continue. And not only for critical infrastructure.
Re: (Score:3)
Re: (Score:2)
Nope. If it is connected to the Internet incompetently, the security will eventually be found to suck. You are stuck in the paradigm from 20-30 years ago.
Re: (Score:2)
Nope. If it is connected to the Internet incompetently, the security will eventually be found to suck. You are stuck in the paradigm from 20-30 years ago.
You know - I'm amazed at how many in here - a site supposedly of the computer savvy - think that if you are on the internet at all, you are pwned. Using good security (and no, Windows Defender and Firewall is obviously not good security) you can be pretty safe.
And before anyone chimes in on how no internet facing system is safe, it is true that if it can be written, it can be compromised. But that's not the point. The point is that about 70 percent of setups have piss-poor security. So the hackers go
Re: (Score:2)
Pretty much, yes. Although very simple systems, designed carefully, can achieve security that cannot practically be broken IMO. But let's not get into that. The point is that if you have good, state-of-the-art security on your systems, designed and operated with actual understanding, you very likely will not get attacked or not get attacked that way.
Re: (Score:2)
Re: (Score:2)
Social engineering also works when NOT Internet connected. Just a bit differently.
So no other state noticed? (Score:2)
Uh... (Score:1)
Guys? Any chance this was related to this [slashdot.org]?
Re: (Score:2)
Yes. The AIs have figured out that if they can kill off the meatsacks competing for water supplies by poisoning them, they'll have more for their data center cooling needs.
Coincidence? (Score:2)
Funny, right around the time Elon sued the state because they're banning AI fake porn of real people and children.
OpenAI again? (Score:1)
did anyone check... (Score:2)
Don't connect your water systems to the Internet. (Score:2)
* Treat water-system control infrastructure as air-gapped or tightly controlled by default:
* No direct internet connectivity for PLCs, SCADA servers, HMIs, or field devices.
* Remote access (if truly required) only through dedicated, monitored jump hosts or industrial gateways with strong authentication, MFA, logging, and the ability to instantly cut sessions.
* Cellular connections for towers/lift stations should use industrial-grade gateways that enforce VPN tunnels and