American Water says it was hit with cyberattack
Full article909 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
American Water Works Company said there does not appear to be any impact to water services.
A New Jersey-based company responsible for providing water to more than 14 million people was hit by a cyberattack which appears to only resulted in the loss of billing systems, according to a Securities and Exchange Commission filing Monday.
American Water Works Company, which first learned of the attack on Oct. 3, said there does not appear to be any impact to water or wastewater services. No ransomware gang has claimed responsibility for the attack on the company, which has operations in 14 states and serves at least 18 military installations.
There has been a steady increase in cyberattacks against water facilities in recent years, as both states and criminals exploit the sector, which experts deem vulnerable. The White House has spent many months warning about the vulnerabilities of the more than 170,000 water systems in the United States, including by sending a letter to governors in March.
At the same time, the Environmental Protection Agency has faced heavy criticism for the sector’s vulnerability, as the industry has faced a rash of hacks against water facilities. Meanwhile, the sector continues to be a largely voluntary operation when it comes to cybersecurity efforts, which critics say is dependent on Congress revamping EPA’s authorities. The Government Accountability Office has also noted as recently as August that the EPA has not identified or prioritized the greatest risks in the sector.
The EPA has announced plans to increase water security inspections in response to the increasing threats. Additionally, a recent reboot of a landmark critical infrastructure policy will require the government to provide yearly risk mitigation updates through a national plan on infrastructure risk.
While the American Water hack does not appear to impact vital services or operations, the company noted that it is “unable to predict the full impact of this incident” and disconnected some systems. The 8-K filing also notes that American Water does not expect the hack to have a “material effect on the company, or its financial condition or results of operations.”
The company took billing services offline and noted on its website that customers will not incur late charges and water services will not be shut off while they work to get back online.
The company said in a statement to CyberScoop that it had “contacted and [is] receiving assistance from law enforcement, and we are coordinating fully with them.”
In its 2023 annual report, American Water wrote that the company’s “capital investment totaled $2.7 billion, and we are well on track to deliver $3.1 billion in investments in 2024.”
The annual report also included a section on the company’s cybersecurity effort, highlighting a “defense-in-depth” strategy that uses the National Institute of Standards and Technology’s cybersecurity framework. The company “periodically reviews and modifies the implementation of its cybersecurity strategy based on threat trends, program maturity, the results of assessments, and the advice of third-party security consultants,” per the report.
More Scoops
In most cities, nobody owns the whole network
July’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions…
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/american-water-works-cyber-ransomware/