Please ensure Javascript is enabled for purposes of website accessibility
Breaches by Iran-Affiliated Hackers Spanned Multiple U.S. States, Federal Agencies Say
By admin
Published 10 months ago on
December 4, 2023

Share

Getting your Trinity Audio player ready...

HARRISBURG, Pa. — A small western Pennsylvania water authority was just one of multiple organizations breached in the United States by Iran-affiliated hackers who targeted a specific industrial control device because it is Israeli-made, U.S. and Israeli authorities say.

“The victims span multiple U.S. states,” the FBI, the Environmental Protection Agency, the Cybersecurity and Infrastructure Security Agency, known as CISA, as well as Israel’s National Cyber Directorate said in an advisory emailed to The Associated Press late Friday.

They did not say how many organizations were hacked or otherwise describe them.

Matthew Mottes, the chairman of the Municipal Water Authority of Aliquippa, which discovered it had been hacked on Nov. 25, said Thursday that federal officials had told him the same group also breached four other utilities and an aquarium.

Cybersecurity experts say that while there is no evidence of Iranian involvement in the Oct. 7 attack into Israel by Hamas that triggered the war in Gaza they expected state-backed Iranian hackers and pro-Palestinian hacktivists to step up cyberattacks on Israeli and its allies in its aftermath. And indeed that has happened.

The multiagency advisory explained what CISA had not when it confirmed the Pennsylvania hack on Wednesday — that other industries outside water and water-treatment facilities use the same equipment — Vision Series programmable logic controllers made by Unitronics — and were also potentially vulnerable.

Those industries include “energy, food and beverage manufacturing and healthcare,” the advisory says. The devices regulate processes including pressure, temperature and fluid flow.

The Aliquippa hack promoted workers to temporarily halt pumping in a remote station that regulates water pressure for two nearby towns, leading crews to switch to manual operation. The hackers left a digital calling card on the compromised device saying all Israeli-made equipment is “a legal target.”

The multiagency advisory said it was not known if the hackers had tried to penetrate deeper into breached networks. The access they did get enabled “more profound cyber physical effects on processes and equipment,” it said.

Hackers Affiliated With Revolutionary Guards

The advisory says the hackers, who call themselves “Cyber Av3ngers,” are affiliated with Iran’s Islamic Revolutionary Guards Corps, which the U.S. designated as a foreign terrorist organization in 2019. The group targeted the Unitronics devices at least since Nov. 22, it said.

An online search Saturday with the Shodan service identified more than 200 such internet-connected devices in the U.S. and more than 1,700 globally.

The advisory notes that Unitronics devices ship with a default password, a practice experts discourage as it makes them more vulnerable to hacking. Best practices call for devices to require a unique password to be created out of the box. It says the hackers likely accessed affected devices by “exploiting cybersecurity weaknesses, including poor password security and exposure to the internet.”

Experts say many water utilities have paid insufficient attention to cybersecurity.

In response to the Aliquippa hack, three Pennsylvania congressmen asked the U.S. Justice Department in a letter to investigate. Americans must know their drinking water and other basic infrastructure is safe from “nation-state adversaries and terrorist organizations,” U.S. Sens. John Fetterman and Bob Casey and U.S. Rep. Chris Deluzio said. Cyber Av3ngers claimed in an Oct. 30 social media post to have hacked 10 water treatment stations in Israel, though it is not clear if they shut down any equipment.

Since the beginning of the Israel-Hamas war, the group has expanded and accelerated targeting Israeli critical infrastructure, said Check Point’s Sergey Shykevich. Iran and Israel were engaged in low-level cyberconflict prior to the Oct. 7. Unitronics has not responded to the AP queries about the hacks.

The attack came less than a month after a federal appeals court decision prompted the EPA to rescind a rule that would have obliged U.S public water systems to include cybersecurity testing in their regular federally mandated audits. The rollback was triggered by a federal appeals court decision in a case brought by Missouri, Arkansas and Iowa, and joined by a water utility trade group.

The Biden administration has been trying to shore up cybersecurity of critical infrastructure — more than 80% of which is privately owned — and has imposed regulations on sectors including electric utilities, gas pipelines and nuclear facilities. But many experts complain that too many vital industries are permitted to self-regulate.

RELATED TOPICS:

DON'T MISS

Russia Urges Citizens to Leave Israel as Tensions with Hezbollah Escalate

DON'T MISS

Taxpayers in 24 States Will Be Able to File Their Returns Directly With the IRS in 2025

DON'T MISS

California Collects Millions in Stolen Wages, but Can’t Find Many Workers to Pay Them

DON'T MISS

Sweet Lola on the Mend, Ready for a Forever Home

DON'T MISS

Houthis Vow Retaliation Against US for Yemen Airstrikes

DON'T MISS

Chavez-Quintero Debate: How Would You Rate City-County Cooperation?

DON'T MISS

Biden Talks Election, Economy and Middle East in Surprise News Briefing

DON'T MISS

Big Money Rolling in from Commercial Builders for Local School Bond Measure Campaigns

DON'T MISS

Behind the Scenes at Fresno Chaffee Zoo’s Sea Lion Cove: A Flipper-tastic Adventure

DON'T MISS

Clovis Daytime Burglary: 2 Suspects Arrested, 1 at Large

UP NEXT

Houthis Vow Retaliation Against US for Yemen Airstrikes

UP NEXT

Israeli Airstrikes Rock Southern Suburbs of Beirut and Cut Off a Key Crossing Into Syria

UP NEXT

Relatives Say a Whole Family Was Killed in Israel’s Deadliest West Bank Strike Since Oct. 7

UP NEXT

Oil Price Jumps After Biden Says ‘Discussing’ Israeli Strike on Iranian Facilities

UP NEXT

Netanyahu Ramps Up Military Action as Public Support Surges

UP NEXT

Why the World’s Biggest Powers Can’t Stop a Middle East War

UP NEXT

Israel Extends Evacuation Warnings in Lebanon, Signaling a Wider Offensive

UP NEXT

Israel Reports 8 Combat Deaths as Troops Battle Hezbollah in Lebanon and Fears of a Wider War Mount

UP NEXT

Middle East Latest: Fears of Wider War in Middle East Grow as Israel and Iran Trade Threats

UP NEXT

Hurricane Helene’s Death Toll Passes 150 as Crews Search for Survivors

Sweet Lola on the Mend, Ready for a Forever Home

21 hours ago

Houthis Vow Retaliation Against US for Yemen Airstrikes

1 day ago

Chavez-Quintero Debate: How Would You Rate City-County Cooperation?

1 day ago

Biden Talks Election, Economy and Middle East in Surprise News Briefing

1 day ago

Big Money Rolling in from Commercial Builders for Local School Bond Measure Campaigns

1 day ago

Behind the Scenes at Fresno Chaffee Zoo’s Sea Lion Cove: A Flipper-tastic Adventure

1 day ago

Clovis Daytime Burglary: 2 Suspects Arrested, 1 at Large

2 days ago

Trump Stalled California Wildfire Aid? Ex-Aide Reveals Political Motive

2 days ago

Costa Bill Opens Grants for Heavy Manufacturers to Start Using Hydrogen

2 days ago

Watch: Fresno County Supervisor District 3 Debate

2 days ago

Russia Urges Citizens to Leave Israel as Tensions with Hezbollah Escalate

Russia has advised its citizens to leave Israel amid rising tensions with Hezbollah and Iran, reports Newsweek. Moscow’s ambassador to...

18 hours ago

18 hours ago

Russia Urges Citizens to Leave Israel as Tensions with Hezbollah Escalate

21 hours ago

Taxpayers in 24 States Will Be Able to File Their Returns Directly With the IRS in 2025

21 hours ago

California Collects Millions in Stolen Wages, but Can’t Find Many Workers to Pay Them

21 hours ago

Sweet Lola on the Mend, Ready for a Forever Home

1 day ago

Houthis Vow Retaliation Against US for Yemen Airstrikes

Challenger Luis Chavez and incumbent supervisor Sal Quintero debate in Fresno, Thursday, Oct. 3, 2024.
1 day ago

Chavez-Quintero Debate: How Would You Rate City-County Cooperation?

1 day ago

Biden Talks Election, Economy and Middle East in Surprise News Briefing

1 day ago

Big Money Rolling in from Commercial Builders for Local School Bond Measure Campaigns

MENU

CONNECT WITH US

Search

Send this to a friend