US water and wastewater (WWS) facilities have been hit by multiple ransomware attacks over the past two years, US government agencies said in a joint advisory on Thursday.
See also: Yanluowang Ransomware: Used in attacks against businesses

See also: VirusTotal: What did the analysis of 80 million ransomware samples show?
The advisory also reports ongoing malicious activity targeting WWS facilities that could lead to ransomware attacks that impact their ability to provide drinking water and effectively manage their wastewater.
Since they belong to the 16 critical infrastructure sectors of the US, their breach through spearphishing and outdated software exploitation attacks will directly impact national security, economic security, and public health or safety.
Multiple ransomware strains were used in the incidents disclosed in this advisory to encrypt water treatment plant systems, including Ghost, ZuCaNo, and Makop ransomware:
- In August 2021, malicious attackers used Ghost variant ransomware against a California-based WWS facility. The ransomware variant had been on the system for about a month and was discovered when three supervisory control and data acquisition (SCADA) servers displayed a ransomware message.
- In July 2021, hackers used remote access to inject ZuCaNo ransomware into the SCADA computer of a Maine-based WWS facility. The treatment system was run manually until the SCADA computer was restored.
- In March 2021, cybercriminals used an unknown ransomware variant against a Nevada-based WWS facility. The ransomware affected the victim’s SCADA system and backup systems. The SCADA system provides visibility and monitoring but is not a full-fledged industrial control system (ICS).
- In September 2020, staff at a New Jersey-based WWS facility discovered that possible Makop ransomware had compromised files on their system.
Attackers have also infiltrated WWS plant networks in an attempt to poison drinking water, as happened in March 2019 when a former employee of the Kansas-based WWS facility failed in his attempt to use credentials for malicious purposes after resigning.
While not included in the advisory, an unknown threat actor also gained access to the water treatment system for Oldsmar, Florida, in February 2021 and attempted to poison the city's drinking water by increasing the levels of chemicals used to clean wastewater to dangerous levels.
See also: Global ransomware meetings: Russia and China left out
Other breaches of water treatment facilities have occurred over the past two decades, including a wastewater treatment plant in South Houston in 2011, a water company with out-of-date software and hardware in 2016, the Southern California water district in August 2020, and a water system in Pennsylvania in May 2021.
Here you can find the full list of mitigation measures proposed by the four federal agencies.
Information source: bleepingcomputer.com
