Cybersecurity agency warns that water utilities are vulnerable to hackers after Pennsylvania attack
Advertisement
Read this article for free:
or
Already have an account? Log in here »
To continue reading, please subscribe:
Digital Subscription
One year of digital access for only $205*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.
To continue reading, please subscribe:
Add Free Press access to your Brandon Sun subscription for only an additional
$1 for the first 4 weeks*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.
Read unlimited articles for free today:
or
Already have an account? Log in here »
Hey there, time traveller!
This article was published 29/11/2023 (1046 days ago), so information in it may no longer be current.
HARRISBURG, Pa. (AP) — Hackers are targeting industrial control systems widely used by water and sewage-treatment utilities, potentially threatening water supplies, the top U.S. cyberdefense agency said after a Pennsylvania water authority was hacked.
The U.S. Cybersecurity and Infrastructure Security Agency issued the warning Tuesday evening, three days after hacktivists shut down a piece of equipment at the Municipal Water Authority of Aliquippa, Pennsylvania, just outside Pittsburgh. The hack effectively idled pumping equipment in a remote station that regulates water pressure for customers in two nearby towns. Crews switched to manual backup, officials said.
The attackers likely accessed the device by exploiting cybersecurity weaknesses, including poor password security and exposure to the internet, U.S. officials said. The Aliquippa water authority did not respond to messages Wednesday.
The equipment identified as vulnerable is used across multiple industries, including electric utilities and oil and gas producers. It regulates processes including pressure, temperature and fluid flow, according to the manufacturer.
While there is no known risk to the Pennsylvania towns’ drinking water or water supply, the cyberdefense agency urged water and wastewater utilities across the United States to take steps to protect their facilities.
The equipment at issue is made by Israel-based Unitronics, which did not immediately respond to queries about what other facilities may have been hacked or could be vulnerable. According to Unitronics’ website, the controllers at issue are built for a wide spectrum of industries.
The Biden administration has been trying to shore up cybersecurity in U.S. critical infrastructure — more than 80% of which is privately owned — and has imposed regulations on sectors including electric utilities, gas pipelines and nuclear facilities.
But many experts complain that too many vital industries are permitted to self-regulate and administration officials want software providers to also assume a higher burden for safety.