The joint statement reads, “The Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Energy are aware of threat actors gaining access to a variety of internet-connected uninterruptible power supply (UPS) devices, often through unchanged default usernames and passwords…Organizations can mitigate attacks against their UPS devices, which provide emergency power in a variety of applications when normal power sources are lost, by removing management interfaces from the internet.”
Not long after the advisory was issued, it was reported that the FBI had issued separate warnings to five American energy companies regarding Russian parties scanning their networks. This news is especially starke following announcements that the February 24th cyberattack on Viasat, a U.S satellite communications provider responsible for network services throughout Central and Eastern Europe, was the result of wiper malware with noted similarities to previous Russian hacks – on the very same day the Russian invasion began.
To protect internet-connect UPS devices, the CSA is recommending two key measures:
These are incredibly tumultuous times.
Our team is ready and able to help in any way we can, just as we always have been.
We’re only one email away.
Subscribe to our newsletter and get the latest cybersecurity insights, updates, and event invitations delivered straight to your inbox. Join our community and empower your security journey with RISCPoint's expert knowledge.
Join our newsletter for updates. Terms.