ノーマルビュー

Hackers Targeted Municipal Water Systems In 7 States This Week, FBI Says

著者: BeauHD
2026年8月1日 05:10

🤖 AI Summary

米国の7州で公衆水源システムへのサイバー攻撃が報告され、FBIと環境保護庁は全国の水道事業者に警告を発しました。これらの攻撃により、いくつかの地域での沸騰注意通知や手動運転が発生しているとのことです。

ミネソタ州では30以上の公衆水源施設が標的となり、イランによる介入と見られる特徴を持つ攻撃が行われたことが判明しています。しかし、ミネソタ州の情報技術サービス庁は、被害によって水源が汚染されたという報告はない旨述べています。

FBIと環境保護庁は、制御システムを使用する公衆水源事業者に対するマルチキャストな攻撃を警告し、ネットワークへの直接的アクセスからプログラマブル論理コントローラ(PLC)を取り除き、セキュアなゲートウェイやファイアウォールの後ろに配置することを含むいくつかの対策を提案しています。また、強力なパスワードを使用し、認証された制御システムデバイス間の通信を限定するなど、他の予防措置も推奨されています。
An anonymous reader quotes a report from NBC News: Cyberattacks targeting municipal water systems have been reported in at least seven states this week, prompting the FBI and the Environmental Protection Agency to warn utilities nationwide that hackers are trying to disrupt critical water infrastructure. In a public service announcement Thursday, the agencies said water and wastewater utilities have reported incidents to the FBI, with some malicious activity degrading water operations. The announcement does not name the states. The warning comes after hackers targeted more than 30 municipal water facilities in Minnesota in an attack that had hallmarks of Iranian meddling, according to a law enforcement official. It is still under investigation. A spokesperson for Minnesota's information technology services agency said Thursday there was no indication the breaches contaminated any municipal water supplies. The federal Cybersecurity and Infrastructure Security Agency said in a separate alert that some larger attacks on water infrastructure had "resulted in boil water notices and sustained manual operations," though it did not say where. [...] The federal advisory said the malicious cyber actors, or MCAs, targeted specific brands of control systems used by municipal water utilities, though the FBI and the EPA urged operators of all systems to take precautions. [...] The agencies said the hackers remotely accessed internet-facing devices, changed IP addresses and passwords, and caused utilities to lose monitoring and control capabilities. The federal advisory calls on system operators to remove programmable logical controllers, or PLCs, from direct internet exposure by putting them behind secure gateways and firewalls; use strong passwords; and limit communications between authorized control system devices through access control lists.

Read more of this story at Slashdot.

❌