pwshub.com

American Water rinsed in cyberattack, turns off app

American Water, which supplies over 14 million people in the US and numerous military bases, has stopped issuing bills and has taken its MyWater app offline while it investigates a cyberattack on its systems.

On Thursday, the dihydrogen monoxide business, which claims to be America's largest regulated water provider, spotted unusual activity on its networks and later determined it was the result of a cybersecurity breach. American Water said it siloed off parts of its network to protect customer data, paused the MyWater billing app, and called in both law enforcement and outside security investigators.

"In an effort to protect our customers’ data and to prevent any further harm to our environment, we disconnected or deactivated certain systems. There will be no late charges for customers while these systems are unavailable," a spokesperson told The Register.

"Our dedicated team of professionals are working around the clock to investigate the nature and scope of the incident. As we continue to contain and remediate our environment, we will share updated information as appropriate on www.amwater.com. The company currently believes that none of its water or wastewater facilities or operations have been negatively impacted by this incident."

In an 8-K filing [PDF], the water biz filed with regulators that, while the situation is still under investigation, it "does not expect the incident will have a material effect on the company, or its financial condition or results of operations."

  • US warns Iranian terrorist crew broke into 'multiple' US water facilities
  • Despite cyberattacks, water security standards remain a pipe dream
  • America's enemies targeting US critical infrastructure should be 'wake-up call'
  • DEF CON Franklin project enlists hackers to harden critical infrastructure

As The Register has reported, the water industry is one of the key parts of America's critical infrastructure that is under active attack, and also very difficult to lock down. A big part of this is down to the industry's use of old operational technology that isn't patched as often as it should be, and is now under nation-state attack.

Last year the US government warned that an Iranian group calling themselves CyberAv3ngers had hacked into multiple water suppliers' networks by exploiting Unitronics programmable logic controllers that were likely using the default passwords they shipped with. The group, backed by Iran's revolutionary guard, has claimed to have broken into multiple water company systems in both the US and Israel.

China too has been active in trying to find weaknesses in America's water supply, Congress has been warned, and in March 2023 the US Environmental Protection Agency started requiring US states to audit the security of water systems, but rescinded the rule after some states and water companies went to court over the issue. This year the EPA also announced the creation of the Water Sector Cybersecurity Task Force to look at ways of hardening up America's suppliers to attack.

While American Water declined to say if the attackers in this latest case had been in touch, water systems are an obvious target for ransomware operators. Once the taps dry up people will get desperate and even the FBI is now helping victims negotiate a payoff if lives are at stake from systems going down. ®

Source: theregister.com

Related stories
1 month ago - Why You Can Trust CNET Our wellness advice is expert-vetted. Our top picks are based on our editors’ independent research, analysis, and hands-on...
1 month ago - Did you know that you shouldn't rinse your mouth right after you finish brushing your teeth? According to experts, this is why.
1 month ago - Looking to get your teeth whitened? Our picks of the best teeth whitening kits let you easily whiten your teeth at home, even if you have tooth sensitivity.
1 month ago - These are three simple and affordable hacks to keeping your air indoors so your AC bill doesn't get so high.
1 month ago - Despite its popularity and natural-sounding hook, using charcoal toothpaste has some risks. Here's what to know.
Other stories
39 minutes ago - The SaaS-only provider and Cognizant snag £144.3M in gov software shake-up A cluster of government departments has opted for Workday HR and finance software, as Oracle and Microsoft make up the vendors losing out to the SaaS-only provider.…
45 minutes ago - October Prime Day is here and even if you're on a budget you can still get a great deal for under $10.
45 minutes ago - Shop the already live Amazon October Prime Day Deals, which include sales on Apple MacBooks and laptops from HP, Samsung and more.
45 minutes ago - This may be the last hurrah for high APYs as banks respond to the Fed's September rate cut.
45 minutes ago - The Torras Coolify Cyber portable cooler is now only $265 with this Amazon on-page coupon and discount for October Prime Day.