Experts from the American cybersecurity firm Mandiant announced on Wednesday that a Russian hacking gang is suspected of carrying out a cyberattack in January that caused a reservoir at a water facility in Texas to overflow.

The city of Muleshoe in North Texas experienced a hacking incident that occurred simultaneously with similar incidents in at least two other cities in the same area, which implemented preventive defense measures after detecting suspicious online activity on their network systems, city officials told CNN. The FBI is investigating the incidents, one of the officials said.
Read also: Olympics in France: Preparing for cyberattacks
The attack is a rare instance where hackers have managed to gain access to sensitive industrial equipment, disrupting the daily operations of a water utility in the US. It follows a similar cyberattack last November on a water plant in Pennsylvania, for which US officials have blamed Iran.
The recent cyberattacks in Texas prompted a rare public call from U.S. National Security Advisor Jake Sullivan last month to state officials and water utilities to strengthen their cybersecurity. Sullivan said the cyberattacks are targeting water and wastewater systems “across the United States,” urging state governments and water utilities to step up defenses against the threat. The call came in a joint letter with the Environmental Protection Agency administrator to the officials.
US officials are concerned that many of the country's 150,000 public water systems are struggling to find the necessary funding and staff to address ongoing threats of hacking by criminals and government agencies.
The hacking incidents in Texas did not receive much attention when they first occurred, as there was uncertainty about who was behind the attacks. However, on Wednesday, Mandiant publicly revealed a link to a channel on Telegram, a popular social media platform, where hackers claimed responsibility for the attack in the Muleshoe area. This action has been linked to previous hacking activities by the GRU, a notorious unit of the Russian military intelligence service.
Mandiant analysts were unable to clearly determine whether the GRU was responsible for the cyberattack on the Muleshoe water facility, or whether this action can be attributed to other Russian-speaking hackers who may be using the same identity to carry out the attack.
The sequence of events did not affect the quality of drinking water in urban areas. However, a confirmation of the involvement of the GRU or one of its affiliates marks a significant escalation in the attack on critical US infrastructure by a Russian group that typically focuses on Ukraine.
In Muleshoe, a town of about 5,000 people, hackers managed to compromise a remote industrial software management system that allows operators to control a water tank, city manager Ramon Sanchez told CNN. The breach caused the tank to overflow for about 30 to 45 minutes before Muleshoe officials disconnected the affected industrial system and switched to manual operations, Sanchez said in an email. Officials have upgraded the compromised software system and taken further steps to strengthen the network's security, Sanchez said.
In October, the EPA was forced to rescind a major regulation related to the cybersecurity of public water utilities, following a legal challenge from Republican attorneys general.
See more: The Heritage Foundation: Think tank victim of cyberattack
Anne Neuberger, the White House Deputy National Security Advisor for Cyberspace and Emerging Technology , told CNN on Tuesday that “the EPA could have taken simple steps to prevent recent attacks on water systems.” She also added that “despite the challenges, we remain committed to ensuring the security of Americans’ water systems from cyberattacks by encouraging owners and operators to strengthen their digital security.”
Neuberger said the Biden-Harris administration recently recommended that state officials develop extensive security plans to defend their water systems against potential threats.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The hacking incident in Muleshoe has raised significant concerns in the local community. In Lockney, located about 75 miles east of Muleshoe, local officials discovered “suspicious activity” in the town’s SCADA system, a robust computer network used to monitor water infrastructure, Lockney’s manager Buster Poling told CNN.
And in the nearby city of Hale Center, hackers also tried unsuccessfully to break into the city's "firewall," causing the city to disable remote access to the SCADA system, City Manager Mike Cypert told CNN in an email.
Neither Cypert nor Poling identified the hackers responsible for the attempted cyberattacks. Poling said only that he believed they were coming from another country, but declined to provide further details.
Poling believes the hackers were trying to gain access to the city's water wells, but, he said, city officials were able to catch the threat early and prevent the hackers from having any impact.
"I've never experienced this before, but ... we know these threats are out there," Pauling told CNN by phone. The FBI was investigating the activity, he said.
The FBI declined to comment. CNN has reached out to the Russian embassy in Washington, D.C., for comment on the hacking incidents.
“Due to the ongoing investigation, EPA is unable to comment on this specific incident,” EPA spokesman Nick Conger said in a statement to CNN. “However, EPA is coordinating with the State of Texas to provide support as needed.”
In its report published Wednesday, Mandiant found multiple links between a GRU sabotage and espionage unit known as Sandworm and electronic infrastructure used by hackers using a persona called “CyberArmyofRussia_Reborn.” This includes a YouTube channel operated by the hacktivist persona that Mandiant believes was created by the GRU-backed unit.

Sandworm is particularly well-known for a series of disruptive cyberattacks that caused power outages in various regions of Ukraine during 2015 and 2016. This group has repeatedly targeted Ukrainian infrastructure with cyberattacks, continuing uninterruptedly during the current war.
Sandworm resorts to using online personalities to amplify and expand the impact of its attacks, according to Mandiant experts.
See also: Targus: Cyberattack disrupted business operations
On January 18, the day Sanchez, the Muleshoe city manager, told CNN that hackers had gained access to the city's industrial computer network, the group CyberArmyofRussia_Reborn posted a video on the Telegram social media channel purporting to show the manipulation of Muleshoe's water valves.
Source: wicz
