Content created by AI
The Department of Water and Sanitation (DWS) of South Africa has provided a reassuring update in the wake of a recent global cyberattack that left water facilities in the United States compromised. MyBroadband received confirmation that the DWS's systems remain untouched by the exploits that targeted Unitronics programmable logic controllers (PLCs), a type of industrial computer used for automating various processes.
The potential hazard surfaced when the Shadowserver Foundation included South Africa on a list of nations affected by the cyberattack. This information came to light following a warning issued by the Cybersecurity and Infrastructure Security Agency (CISA) of the United States, concerning the exploits by an alleged Iranian state-sponsored hacking group. The group, identified as CyberAv3ngers, reportedly have connections with the Islamic Revolutionary Guard Corps, labelled as a terrorist organization by the U.S. in 2019.
According to MyBroadband, the DWS, however, stands firm on the safety of its operations. A spokesperson for the department asserted, "The department has not received any notification of interruption of systems or compromise in water quality and wastewater management as a result of hacking." The statement does come with a cautious addendum that independent institutions in charge of certain infrastructures might not share the same level of security assurance.
Shadowserver had embarked on an internet-wide scan to identify vulnerable controllers post-CISA's advisory, which clarified that the security frailties within the PLCs were not confined to water and wastewater systems. Impact potential spanned a diverse range of sectors including energy, healthcare, and food and beverage manufacturing.
In their nefarious activities, CyberAv3ngers exploited weak security measures such as frail passwords. CISA pointed out that Unitronics PLCs notably came with a default password - "1111." This easily guessable default, if unchanged, offers little defense against unauthorized access. CISA urged institutions to rectify such vulnerabilities by avoiding connections of these PLCs to the open internet and stressed the importance of firewalls, VPNs, and IP address allowlists to regulate remote access.
Despite the alerts, at least 539 instances of Unitronics PLCs remained publicly exposed worldwide, Shadowserver's scan revealed. Though South Africa was mentioned among the exposed, it harbors less exposure compared to Australia, which topped the list, followed by Singapore, Switzerland, and the United States.
The extent of the exposure within South African infrastructure is not fully determined. With the DWS being clear on their systems' integrity, the status of other institutions using the mentioned PLCs remains uncertain. Randwater, another key institution, is yet to comment on this issue.
The incident serves as a stark reminder for continuous vigilance and assessment of security measures within critical infrastructure. It's a wake-up call to all sectors integrating such technology to prioritize cybersecurity to thwart such threats, mitigating the risk of substantial service interruptions and potential danger to the public.