CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks
Overview
A coordinated cyberattack targeted the operational technology systems of over 30 community water utilities in Minnesota from July 26 to 27. The attack prompted the Cybersecurity and Infrastructure Security Agency (CISA) to recommend that utilities remove programmable logic controllers (PLCs) connected to the internet and enhance their operational technology security measures. This incident raises significant concerns about the safety and security of critical infrastructure, as water systems are vital for public health and safety. By exposing PLCs to the internet, utilities may unintentionally open themselves up to similar attacks in the future. CISA's guidance aims to prevent further incidents and protect these essential services from cyber threats.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Community water utilities in Minnesota, specifically those using internet-exposed PLCs.
- Action Required: Remove internet-exposed PLCs and strengthen operational technology security.
- Timeline: Ongoing since July 26, 2023
Original Article Summary
After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT). “A coordinated cyberattack targeted operational technology […]
Impact
Community water utilities in Minnesota, specifically those using internet-exposed PLCs.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since July 26, 2023
Remediation
Remove internet-exposed PLCs and strengthen operational technology security.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Critical.