Hacker News new | ask | show | jobs
by lysace 16 hours ago
The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations. While the FBI has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.

After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality. To reduce the risk of compromise, the FBI and EPA recommend removing PLCs from direct internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing an access control list (ACL) to allow only authorized communication between expected control system devices.

https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-...

1 comments

Did they literally just leave the water supply plant management software out available on the open internet? Hard to even call this a hack!
Does anyone recall the Colonial Pipeline outage? They had their IT and OT networks segregated but without billing capacity nothing else mattered. You didn’t expect them to let the petrol flow for free, didja? All that it takes is for a “jump box” that spans or bridges supposedly segregated networks to be p0wned to permit compromise of the soft and chewy center.
I mean

Some of these municipal water plants in the US are independently operated by municipalities of awfully few people and even fewer resources to spare, often serving relatively vast areas…

It’s probably not how you or I would set things up—especially after many years of warnings and slick best practices guides-but I can sympathize with “if it’s not broken…”-style maintenance, especially at the local level.

These things have lifespans measured in decades, and budgetary cycles to match… and for all of CISA’s good work (on limited budgets, and with power that’s more persuasive than fearsome) [0], it seems hard to get all 148,000 [1] system operators to afford to care, much less to afford to fix things—much less to check their work.

[0] https://www.cisa.gov/topics/industrial-control-systems , and https://www.gao.gov/assets/d24106576.pdf for an idea of the staffing they’re doing it with…

[1] https://www.epa.gov/dwreginfo/information-about-public-water...

Who connected the systems to the Internet in the first place?

Why?

Most likely to cut costs and have one person remote-admin all pumps, valves, etc. instead of a crew for each location.

Why didn't they have firewalls, admin accounts, access rights, you know, proper security? They were glad it barely worked at all.

Yes. The last federal administration attempted to use CISA to encourage better cyber outcomes for water supply systems, and the water industry and Republican states sued over it. There is no will to fix this, only to push the liability elsewhere.

https://news.ycombinator.com/item?id=39243560

https://web.archive.org/web/20240409155326/https://www.awwa....

(cybersecurity practitioner is a component of my professional persona)

When will the public figure out that many IT exploits are the result of malpractice by developers and network adminstrators, and the businesses employing them? We're building and operating bridges that we know will collapse. Our products are nearly indefensible, literally - they can't realistically be secured except at great expense. We talk about the imbalance between costs of attack and defense; we made that imbalance.

The big LLM security threat is arguably just a revelation of the sh-ty work our field has accepted. Maybe we need to become actual engineers and invest in building proper, reliable, safe systems (which includes not being a dangerous risk for fraud, surveillance, and addiction). The 'anything goes' extreme disruption of many current SV corporate leaders and their technology is, in a way, a culmination of what they've always done.

The good news is that LLMs used properly might make proper engineering less expensive. The LLMs will more likely be used to make sh-t cheaper, so we can make more of it. Unless of course we take action.