CISA Outlines IT Precautions After Florida Water Facility Attack -- .com
Summary
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published advisory AA21-042A regarding the Feb. 5 electronic intrusion into a Florida water treatment facility by an unknown attacker. In a Feb. 9 RSA Conference interview, Bryson Bort, founder and CEO at Scythe, gave the opinion that the attack principally involved TeamViewer, although the use of outdated software in industrial control systems is prevalent. A Massachusetts advisory to public water suppliers provided the detail that "all computers shared the same password for remote access and appeared to be connected directly to the Internet without any type of firewall protection installed." SCADA systems are considered general targets these days, but Oldsmar may have been the first American water treatment plant attacked, or at least the first publicized, according to a blog post by Brian Kime, a senior analyst at the Forrester research and consulting firm. Kime added the important detail, sourced to the Wall Street Journal, that the plant had already upgraded to another remote desktop application, but hadnt removed the older TeamViewer software from its network.