Rockwell Automation/Allen-Bradley MicroLogix PLCs Attack
What is the Attack? Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with successful compromises resulting in operational disruptions. Attackers have gained access to exposed PLCs and manipulated their operation, demonstrating the potential for Internet-accessible OT systems to be directly abused to disrupt physical processes. The activity…
|
What is the Attack? |
Cyber threat actors are targeting Internet-facing programmable logic controllers (PLCs) used by water and wastewater organizations, with successful compromises resulting in operational disruptions. Attackers have gained access to exposed PLCs and manipulated their operation, demonstrating the potential for Internet-accessible OT systems to be directly abused to disrupt physical processes. The activity does not involve a specific CVE. Instead, attackers are taking advantage of Internet-exposed PLCs, weak or default credentials, and inadequate access controls to obtain unauthorized access to OT environments. Once access to an exposed PLC is obtained, attackers may manipulate configurations, operating parameters, or connected industrial processes. Such access can interfere with normal operations and potentially affect the availability and reliability of water and wastewater services. |
|
What is the recommended Mitigation? |
• Remove PLCs from direct Internet exposure and place them behind secure gateways, firewalls, or VPNs. The FBI specifically recommends removing PLCs from direct Internet exposure, using strong unique passwords, and implementing ACLs to restrict communications |
|
What FortiGuard Coverage is available? |
• FortiGuard Operational Technology Security Service: Provides specialized protection for OT/ICS environments, helping identify and protect against threats targeting industrial control systems, including PLCs and other critical OT assets. |
