An investigation is underway into a ransomware attack at the Cucamonga Valley Water District that paralyzed a computer system earlier this month, preventing customers from making phone payments.
The Aug. 15 cybersecurity incident was resolved Monday, enabling CVWD to accept payments by phone, district spokesperson Eric Grubb said in an email.
CVWD’s water distribution operations and customer database, which are on separate networks from the phone system, were not impacted. The district serves 190,000 customers within a 47-square-mile area, which includes approximately 49,000 water connections in Rancho Cucamonga, Upland, Fontana and Ontario.
The water district notified federal authorities that the ransomware attack caused a “network disruption,” but did not identify the hackers or disclose whether a ransom had been paid.
“Our team is working diligently to determine the scope of the event,” the water district said in a statement, adding that customers will be notified if it’s determined their personal information has been compromised.
The incident marks at least the second time Cucamonga Valley Water District systems involving customer payments have fallen prey to hackers.
In 2019, a server handling one-time credit card transactions for the utility was breached. Investigators did not immediately find conclusive evidence of data theft, but it was possible that some payment details may have been taken.
In March, the federal government warned state governors that foreign hackers are striking water systems throughout the United States.Specifically, hackers affiliated with the Iranian government Islamic Revolutionary Guard Corps carried out malicious cyberattacks against critical infrastructure operations, including drinking water systems, U.S. Environmental Protection Agency Administrator Michael S. Regan and National Security Advisor Jake Sullivan said in a letter.
IRGC hackers targeted and disabled a common type of operational technology used at water facilities that neglected to change a default manufacturer password.
Additionally, the People’s Republic of China state-sponsored cyber organization, Volt Typhoon, has compromised information technology systems used by multiple drinking water operations.
“Drinking water and wastewater systems are an attractive target for cyberattacks because they are a lifeline critical infrastructure sector but often lack the resources and technical capacity to adopt rigorous cybersecurity practices,” the letter states.
Elsewhere in the Inland Empire, San Bernardino County acknowledged in May that it, along with its insurer, paid a $1.1 million ransom to a hacker who uploaded malware to the Sheriff’s Department’s computer system.
The cyberattack did not compromise public safety, but required deputies to rely on other law enforcement agencies for criminal history checks.
PREVIOUS ARTICLE