Nick Andersen warns of significant increase in cyber threats targeting water and wastewater systems across the United States
Nick Andersen, the acting director of the Cybersecurity and Infrastructure Security Agency (CISA), warned of a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) at water utilities. These automated computers control systems and can be locked out by hackers, forcing some utilities to switch to manual operations. The warning follows a coordinated cyberattack that affected more than 30 community water systems in Minnesota earlier this week. While investigators are currently probing whether Iran-linked hackers were responsible for the Minnesota incidents, the federal government has not yet made a formal attribution. The FBI and the Environmental Protection Agency have also joined the investigation to determine the scope of the attacks, which have been reported in at least seven states. Andersen urged critical infrastructure owners and operators to remove publicly exposed PLCs from the internet as soon as possible. He noted that even mature cybersecurity processes should include validating external connections, such as cellular modems, that may not be documented in routine scans.