2 Municipal Water Facilities Report Falling To Hackers In Separate Breaches
Full article405 words · extracted from arstechnica.com · click to collapse
A second hack hitting the North Texas Municipal Water District came to light on Monday after a ransomware group tracked as DAIXIN added the district, abbreviated as NTMWD, to its leak site. The post said the group has stolen sensitive data contained in 33,844 files. A text file that accompanied the post showed what appeared to be an extensive file directory tree of the network belonging to the NTMWD.
A partial screenshot of a text file left on the DAIXIN website listing some of the files stolen.
A partial screenshot of a text file left on the DAIXIN website listing some of the files stolen.
“The North Texas Municipal Water District (NTMWD) recently detected a cybersecurity incident affecting our business computer network,” an official wrote in an email. “Most of our business network has been restored. Our core water, wastewater, and solid waste services to our Member Cities and Customers have not been impacted by this incident, and we continue to provide those services as usual.” The official went on to say that phone systems remained offline. The district has engaged third-party forensic investigators to probe the extent of the breach.
While the network intrusion didn’t come to light until Monday, NTMWD first notified residents of a phone outage on November 12. The official didn’t say when the breach occurred. NTMWD serves 2.2 million people across 2,200 square miles.
DAIXIN was first spotted in June 2022. The group, which has been actively tracked by both CISA and the Water Information Sharing and Analysis Center, has successfully targeted a wide range of industries including health care, aerospace, automotive, and packaged foods.
Less is known about Cyber Aveng3rs, the group claiming responsibility for the hack on the Municipal Water Authority of Aliquippa. It may be the same group known as Cyber Av3ngers or connected to Cyber Av3ngers, which has ties to a group Microsoft has linked to the Iranian-government-backed Moses group.
It’s tempting to think that the hacks of two different water facilities coming to light within a few days signals an escalation. It’s easier to bear in mind that water facilities are notoriously underfunded and employ IT staff who receive little training and resources and are underpaid. Either way, the attacks should serve as a wake up call to political leaders at every level of government that critical infrastructure is vulnerable to hacking and will remain that way until they make the necessary investments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/11/2-municipal-water-facilities-report-falling-to-hackers-in-separate-breaches/