C
月内に
CISAは、水・廃水システム(WWS)の運用技術(OT)を標的としたサイバー攻撃の増加について警告を発しました
📌 一言でいうと
CISAは、水・廃水システム(WWS)の運用技術(OT)を標的としたサイバー攻撃の増加について警告を発しました。攻撃者はインターネットに公開されているPLC(プログラマブルロジックコントローラ)を標的にし、パスワード変更による操作権限の奪取やIPアドレス変更による切断を行っています。これにより、ミネソタ州の複数の水道事業所で自動制御が停止し、「煮沸勧告」が出されるなどの実害が発生しています。
🔍該当判定
- 自社で水道・排水処理などの水インフラ設備を運営・管理している
- PLC(プログラマブルロジックコントローラ)などの産業用制御装置を利用している
- PLCやOT(制御系)設備を、外部からアクセス可能な状態でインターネットに直接接続している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
1. インターネットに直接公開されているPLCおよびOT機器を直ちにネットワークから分離または遮断すること。2. 外部からアクセス可能な管理インターフェースの有無を確認し、VPN等の安全な経路に限定すること。3. 強固なパスワードポリシーを適用し、不審な設定変更がないか監視を強化すること。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】水・廃水セクターにおけるPLC標的攻撃への対応について
お疲れさまです。CISAより発表されたOT機器(PLC)を標的とした攻撃に関する情報共有です。
■ 概要
インターネットに公開されているPLC(プログラマブルロジックコントローラ)を標的とした攻撃が急増しています。攻撃者はパスワードを書き換えて管理者をロックアウトし、IPアドレスを変更して通信を遮断させることで、制御不能に陥らせます。既に米国ミネソタ州の水道事業所で実害が報告されています。
■ 影響範囲
- インターネットに直接公開されているPLCおよびOT機器
- 水・廃水インフラ等の産業制御システム
■ 対応手順
1. 資産棚卸を行い、インターネットから直接アクセス可能なPLC/OT機器を特定する。
2. 特定した機器を直ちにインターネットから切り離し、VPNや踏み台サーバー経由のアクセスに制限する。
3. デフォルトパスワードの変更および、特権アカウントの認証強化を実施する。
■ 参考情報
- CISA Alert (July 30)
対応優先度: 高
対応期限: 至急
お疲れさまです。CISAより発表されたOT機器(PLC)を標的とした攻撃に関する情報共有です。
■ 概要
インターネットに公開されているPLC(プログラマブルロジックコントローラ)を標的とした攻撃が急増しています。攻撃者はパスワードを書き換えて管理者をロックアウトし、IPアドレスを変更して通信を遮断させることで、制御不能に陥らせます。既に米国ミネソタ州の水道事業所で実害が報告されています。
■ 影響範囲
- インターネットに直接公開されているPLCおよびOT機器
- 水・廃水インフラ等の産業制御システム
■ 対応手順
1. 資産棚卸を行い、インターネットから直接アクセス可能なPLC/OT機器を特定する。
2. 特定した機器を直ちにインターネットから切り離し、VPNや踏み台サーバー経由のアクセスに制限する。
3. デフォルトパスワードの変更および、特権アカウントの認証強化を実施する。
■ 参考情報
- CISA Alert (July 30)
対応優先度: 高
対応期限: 至急
Subject: [Security Alert] Protection of PLCs in Water/Wastewater Sector
Dear Team,
We are sharing a critical alert from CISA regarding coordinated attacks targeting Programmable Logic Controllers (PLCs) within the water and wastewater sector.
■ Overview
There is a significant increase in threat actors targeting publicly exposed PLCs. Attackers are modifying passwords to lock out legitimate operators and changing IP addresses to disconnect devices from the network, leading to operational disruptions and manual override requirements.
■ Scope
- Publicly exposed PLCs and OT devices
- Industrial Control Systems (ICS) in critical infrastructure
■ Action Items
1. Conduct an asset discovery to identify any PLCs or OT devices directly exposed to the public internet.
2. Immediately remove these devices from the public internet and restrict access via secure tunnels (e.g., VPN).
3. Audit and strengthen authentication mechanisms for all controller management interfaces.
■ Reference
- CISA Alert (July 30)
Priority: High
Deadline: Immediate
Dear Team,
We are sharing a critical alert from CISA regarding coordinated attacks targeting Programmable Logic Controllers (PLCs) within the water and wastewater sector.
■ Overview
There is a significant increase in threat actors targeting publicly exposed PLCs. Attackers are modifying passwords to lock out legitimate operators and changing IP addresses to disconnect devices from the network, leading to operational disruptions and manual override requirements.
■ Scope
- Publicly exposed PLCs and OT devices
- Industrial Control Systems (ICS) in critical infrastructure
■ Action Items
1. Conduct an asset discovery to identify any PLCs or OT devices directly exposed to the public internet.
2. Immediately remove these devices from the public internet and restrict access via secure tunnels (e.g., VPN).
3. Audit and strengthen authentication mechanisms for all controller management interfaces.
■ Reference
- CISA Alert (July 30)
Priority: High
Deadline: Immediate