Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

Littleton utility recounts China‑linked intrusion, FBI and CISA assist; fixes included MFA and network segmentation

Littleton Electric Light and Water Department · April 30, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Leaders of the Littleton Electric Light and Water Department described a prolonged intrusion tied to a China‑linked threat actor and summarized steps taken after detection — including CISA‑deployed network sensors, a Dec. 15 mitigation plan, a subsequent penetration test and a MassDEP grant to separate water and electric operational technology.

Littleton, Mass. — Officials from the Littleton Electric Light and Water Department told a briefing that their networks were infiltrated after a firmware vulnerability in perimeter firewalls was exploited, and that federal partners including the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) helped identify and cut off the intrusion.

Nick Lawler, general manager, and Dave Ketchin, assistant general manager, said the utility learned in mid‑January 2023 that a threat actor had gained access by leveraging a known firewall vulnerability and compromised VPN credentials. According to the presenters, Microsoft threat hunters later flagged suspicious traffic tied to a Littleton public IP and notified the FBI, which contacted the utility on Nov. 17, 2023.

The episode left Littleton treating the incident as part of a wider campaign. Ketchin said the intruder used "living off the land" techniques — legitimate administrative tools and credentials — to stay largely undetected while performing reconnaissance and intermittent file access over many months. "Our networks here were compromised by a China‑linked actor called Vault Typhoon," Ketchin said, adding that federal parties conveyed the attribution.

Why it mattered: Littleton combines electric and water operations under one municipal department and serves roughly 8,000 electric accounts, about 3,500 water accounts and around 100 wastewater connections. Presenters said that combined structure offers efficiencies but also expanded exposure when the perimeter was breached.

Immediate federal response and mitigation: After the FBI’s initial outreach, the utility agreed to partner with CISA. CISA installed network monitoring sensors that mirrored traffic for analysis and conducted follow‑up work on site. CISA personnel, working under confidentiality arrangements, provided a prioritized list of roughly 20 immediate technical fixes. On Dec. 15, the utility implemented measures that included password resets, tighter network segmentation and adding multifactor authentication (MFA) to VPN access.

Longer‑term checks and testing: The utility later arranged a CISA‑led penetration test that consisted of remote and on‑site phases. According to Ketchin, the test probed whether attackers could move into SCADA/OT systems; presenters said the intruder had not succeeded in gaining control of operational technology. CISA also provided ongoing monthly scans of public‑facing IPs to identify remaining vulnerabilities.

Vendor and workforce lessons: Littleton’s account highlighted problems with its previous managed service provider, Thrive Networks, where staff turnover and slower ticket handling contributed to architectural weaknesses. The utility transitioned to a smaller vendor, Evo Lab Solutions, and made operational changes including banning browser‑stored passwords and deploying a password manager (Keeper). Officials said roughly 10 employee browser credentials were exposed; they reported no customer data loss.

Funding and infrastructure work: Presenters said they obtained a drinking‑water cyber grant through the Massachusetts Department of Environmental Protection (MassDEP) to bolster OT assets on the water side. The grant is funding new switching and physical separation at sites where electric and water switching had been shared.

Costs and disclosure: Ketchin said the department did not pay ransom and that much of the federal assistance came at no cost; the direct non‑grant financial impact to the utility was described as limited because hardware replacement had already been budgeted.

Audience questions addressed training, authentication of FBI/CISA outreach and internal communications. Officials said they had previously run phishing and ransomware training, that MFA had previously been applied to OT networks but not uniformly to corporate systems, and that they are now running more frequent password rotation and incident‑response rehearsals.

The briefing concluded with presenters urging other small utilities to prepare for similar campaigns and to cultivate relationships with federal and regional partners; the session then moved to an extended Q&A.