A water authority in Pennsylvania reportedly suffered a cyberattack, prompting officials to reassure people in the area that drinking water has not been affected by the incident.
The Municipal Water Authority of Aliquippa, which serves thousands of customers in communities northwest of Pittsburgh, did not respond to requests for comment but told local news outlet that computer screens at a facility were plastered with a message from hacking group Cyber Av3ngers. The facility, which contains a collection of pumps that maintain water pressure and regulate water flow, sent an emergency notice to the main headquarters after it was attacked. Others reported that workers took the equipment offline and are using backup tools to maintain water pressure.
The Chairman of the Board for the Aliquippa water authority said alarms went off on 25 November at a station located on the outskirts of town and that local police were called to investigate the incident. "They did not get access to anything in our actual water treatment plant, or other parts of our system, other than a pump that regulates pressure to elevated areas of our system,” he said. “This pump was on its own computer network, separated from our primary network, and is physically miles away." Also noted that the hacked system uses software or components from Unitronics, an Israeli-owned technology company. He reiterated that the attack had no effect on drinking water or the water supply.
The Cyber Av3ngers group has filled its social media feed with references to the leaders of Iran and has pledged to attack any entities with products or ties to Israel already touting attacks on 10 water treatment plants in Israel.
Congressman Chris Deluzio (D-PA) said he is “closely monitoring” the attack. “My office is in touch with leadership, which reports that there has been no loss of water service for folks. Federal officials are assisting the investigation, and I remain ready to help with federal agencies. Attacks on our critical infrastructure like water are unacceptable,” he said in a statement. “I intend to push for a full investigation here and accountability for the attackers, and I will continue the important bipartisan work on the House Armed Services Cyber, Information Technologies, and Innovation (CITI) Subcommittee to shore up America's defenses.”
The attack comes one month after Republican lawmakers and water industry companies forced the US Environmental Protection Agency (EPA) to back off efforts to add cybersecurity to annual state-led Sanitary Survey Programs that evaluate water systems across the US. Lawsuits against the rules were backed by two powerful industry groups, the AWWA and the NRWA, which argued that the EPA should allow utilities to create their own requirements. Despite their work in scuttling EPA efforts to better protect water systems, the groups acknowledged that cyberattacks against water utilities are increasing at an alarming rate.
US law enforcement agencies said ransomware gangs hit five US water and wastewater treatment facilities from 2019 to 2021 and those figures did not include three other widely reported cyberattacks on water utilities.
This article is presented at no charge for educational and informational purposes only.
Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization. For questions, comments, a demo or assistance, please contact the office directly at 1-844-492-7225, or feedback@redskyalliance.com
Weekly Cyber Intelligence Briefings:
Reporting: https://www.redskyalliance.org/
Website: https://www.redskyalliance.com/
LinkedIn: https://www.linkedin.com/company/64265941
Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/5993554863383553632
Source: Pennsylvania water authority hit with cyberattack allegedly tied to pro-Iran group (therecord.media)
Comments