فتحت السلطات الأمريكية تحقيقًا في اختراق إلكتروني استهدف شركة صغيرة متخصصة في تكنولوجيا مرافق المياه بولاية كانساس، في حادثة تسلط الضوء مجددًا على المخاطر السيبرانية التي تواجه البنية التحتية الحيوية في الولايات المتحدة.
وأكدت شركة Micro-Comm، ومكتب التحقيقات الفيدرالي «FBI»، تعرّض الشركة للهجوم، في واقعة لم يسبق الإعلان عنها.
وأعلنت مجموعة قرصنة تطلق على نفسها اسم Barracuda مسؤوليتها عن الاختراق، وهي مجموعة حديثة نسبيًا تقول إن دوافعها مالية ولا تعمل لحساب أي حكومة.
ونشرت المجموعة، في السادس من أغسطس، ما قالت إن نحو 850 ألف ملف مسروق من الشركة، بإجمالي يقارب 644 غيغابايت من البيانات.
شركة تزوّد مرافق الصرف الصحي بأنظمة تحكم
وتنتج Micro-Comm وحدات تحكم منطقية قابلة للبرمجة (PLC)، وهي أجهزة حاسوبية تستخدم للتحكم في المعدات والعمليات داخل شبكات البنية التحتية الحيوية، بما في ذلك مرافق معالجة مياه الصرف الصحي.
ويثير الاختراق مخاوف بشأن مدى قدرة أنظمة المياه المحلية والشركات التي توفر لها التكنولوجيا على مواجهة الهجمات الإلكترونية المتزايدة، خصوصًا مع اعتماد العديد من هذه المنشآت على أنظمة تحكم صناعية متصلة بالشبكات الرقمية.
ووقع اختراق الشركة في وقت شهدت فيه الولايات المتحدة موجة من الهجمات الإلكترونية استهدفت وحدات تحكم صناعية في ولاية مينيسوتا، وما لا يقل عن 6 ولايات أخرى خلال أواخر يوليو.
ويعتقد خبراء في الأمن السيبراني أن تلك الهجمات كانت جزءًا من حملة إلكترونية طويلة الأمد مرتبطة بإيران.
تحذيرات أمريكية من استهداف أنظمة التحكم
وكان مكتب التحقيقات الفيدرالي ووكالة الأمن السيبراني وأمن البنية التحتية الأمريكية CISA قد حذرا في 30 يوليو من استهداف قراصنة لوحدات تحكم صناعية تنتجها شركات عالمية، بينها Rockwell Automation الأمريكية، وSchneider Electric الفرنسية، وSiemens الألمانية.
وقالت CISA في 19 أغسطس إن قراصنة يستخدمون تقنيات الذكاء الاصطناعي لتسهيل هجماتهم على معدات Siemens، فيما أكدت الشركة تعاونها مع الوكالة، مشيرة إلى أن منتجاتها آمنة، لكن السلطات لم تربط اختراق Micro-Comm بشكل مباشر بتلك الحملة.
الشركة: الهجوم لم يستهدف أنظمة المياه
وقال جيم كوت، أحد مالكي Micro-Comm، إن الشركة اكتشفت الاختراق في 31 يوليو، وإن مكتب التحقيقات الفيدرالي أبلغها بأن الهجوم يبدو انتهازيًا ولم يستهدف الشركة تحديدًا.
وأوضح كوت أن الملفات التي نشرها القراصنة لا تتضمن معلومات حساسة، مثل كلمات مرور المستخدمين وبيانات الدخول، التي يحتفظ بها العملاء، كما أنها لا تحتوي على بيانات مرتبطة بقدرة Micro-Comm على الوصول عن بُعد إلى أجهزتها.
وفي رسالة إلى عملائها بتاريخ 8 أغسطس، قالت الشركة إنها تعرضت لهجوم محدود ببرمجيات خبيثة، وإن أي معلومات حساسة ضمن الملفات المسروقة كانت مشفرة.
وأكدت الشركة أن الاختراق «لا علاقة له بأي شكل» بالهجمات الإلكترونية على أنظمة المياه التي كانت تتصدر الأخبار في ذلك الوقت، كما أوصت عملاءها بتغيير كلمات المرور كإجراء احترازي.
بيانات مسرّبة قد تشكّل خطرًا مستقبليًا
وبحسب شركة مراقبة الإنترنت Censys، فإن نحو 200 نظام من أنظمة SCADAview CSX التابعة لـMicro-Comm والمستخدمة في ولايات أمريكية مختلفة يمكن الوصول إليها عبر الإنترنت.
كما أظهرت قائمة بالملفات التي جمعها باحثون في منصة eCrime.ch إشارات إلى عملاء حكوميين محددين، بينهم جهات محلية ومنشأة تابعة للجيش الأمريكي، إضافة إلى أسماء موظفين ومعلومات فنية عن المنتجات، بما في ذلك مخططات.
وقال توم هيغل، الباحث البارز في مجال التهديدات لدى شركة الأمن السيبراني SentinelOne، إن نشر هذه الملفات لا يعني أن أي نظام مياه تعرض للاختراق التشغيلي أو فقد السيطرة عليه.
لكنه حذّر من أن المعلومات المسربة يمكن أن تمنح المهاجمين معرفة مفيدة على المدى الطويل، ما قد يساعدهم في فهم الأنظمة المستهدفة وتحديد نقاط ضعف محتملة في المستقبل.
تحقيق فيدرالي في الهجوم
وقال ديكسون لاند، المتحدث باسم مكتب الـFBI في مدينة كانساس سيتي، إن المكتب على اتصال بشركة Micro-Comm بشأن الاختراق، ويعمل على التنسيق مع أجهزة إنفاذ قانون أخرى، وأحالت CISA الاستفسارات المتعلقة بالحادثة إلى الشركة.
ويأتي التحقيق في وقت تتزايد فيه التحذيرات الأمريكية من استهداف البنية التحتية الحيوية، ولا سيما أنظمة المياه والصرف الصحي التي تعتمد بدرجة متزايدة على أجهزة التحكم الصناعي والشبكات المتصلة بالإنترنت.
The U.S. authorities have opened an investigation into a cyber breach that targeted a small company specializing in water facility technology in Kansas, in an incident that highlights once again the cybersecurity risks facing critical infrastructure in the United States.
Micro-Comm and the FBI confirmed that the company was attacked in an incident that had not been previously disclosed.
A hacking group calling itself Barracuda claimed responsibility for the breach, a relatively new group that says its motives are financial and that it does not operate on behalf of any government.
The group published, on August 6, what it claimed were about 850,000 stolen files from the company, totaling nearly 644 gigabytes of data.
A Company Providing Wastewater Facilities with Control Systems
Micro-Comm produces programmable logic controllers (PLCs), which are computer devices used to control equipment and processes within critical infrastructure networks, including wastewater treatment facilities.
The breach raises concerns about the ability of local water systems and the companies that provide them with technology to withstand increasing cyberattacks, especially as many of these facilities rely on industrial control systems connected to digital networks.
The company's breach occurred at a time when the United States was experiencing a wave of cyberattacks targeting industrial control systems in Minnesota and at least six other states in late July.
Cybersecurity experts believe that these attacks were part of a long-term cyber campaign linked to Iran.
U.S. Warnings About Targeting Control Systems
The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) warned on July 30 about hackers targeting industrial control units produced by global companies, including U.S. firm Rockwell Automation, French company Schneider Electric, and German company Siemens.
CISA stated on August 19 that hackers are using artificial intelligence techniques to facilitate their attacks on Siemens equipment, while the company confirmed its cooperation with the agency, noting that its products are secure, but authorities did not directly link the Micro-Comm breach to that campaign.
The Company: The Attack Did Not Target Water Systems
Jim Kott, one of the owners of Micro-Comm, stated that the company discovered the breach on July 31, and the FBI informed them that the attack appeared to be opportunistic and did not specifically target the company.
Kott clarified that the files published by the hackers do not include sensitive information, such as user passwords and login data held by customers, nor do they contain data related to Micro-Comm's ability to remotely access its devices.
In a message to its customers dated August 8, the company stated that it had experienced a limited attack involving malware, and that any sensitive information within the stolen files was encrypted.
The company confirmed that the breach is "not related in any way" to the cyberattacks on water systems that were making headlines at the time, and it advised its customers to change their passwords as a precautionary measure.
Leaked Data That May Pose Future Risks
According to internet monitoring company Censys, about 200 SCADAview CSX systems belonging to Micro-Comm and used in various U.S. states can be accessed online.
A list of files collected by researchers on the eCrime.ch platform showed references to specific government clients, including local entities and a facility belonging to the U.S. Army, as well as employee names and technical information about products, including schematics.
Tom Hegel, a senior threat researcher at cybersecurity firm SentinelOne, stated that the publication of these files does not mean that any water system was compromised operationally or lost control.
However, he warned that the leaked information could provide attackers with useful long-term knowledge, which may help them understand the targeted systems and identify potential vulnerabilities in the future.
Federal Investigation into the Attack
Dixon Land, a spokesperson for the FBI in Kansas City, stated that the bureau is in contact with Micro-Comm regarding the breach and is coordinating with other law enforcement agencies, while CISA referred inquiries related to the incident to the company.
The investigation comes at a time when U.S. warnings about targeting critical infrastructure are increasing, particularly water and wastewater systems that are increasingly reliant on industrial control devices and internet-connected networks.