More US water systems struck by hackers

Yuichiro Chino via Getty Images
The FBI said systems in at least seven states have been hit, following an Iran-linked group’s hack in Minnesota. Experts urged operators to beef up operational technology cybersecurity.
What started as a cyber attack on water systems in Minnesota has appeared to spread to a number of other states, as more and more such systems report being hacked in an effort that has been linked to Iran.
Michigan and Georgia were among the latest to say at least some of their water systems had been compromised, with the focus of the attacks appearing to be against programmable logic controllers, which command various pieces of water equipment. The Federal Bureau of Investigation and Environmental Protection Agency late last month issued a joint statement warning that water and wastewater utility companies in at least seven states had been hit.
Water system operators and observers have all warned for years about their cybersecurity vulnerabilities, especially in their operational technology that controls the physical world and monitors and manages their industrial activities. Tatyana Bolton, executive director of the Operational Technology Cybersecurity Coalition, said in a statement these attacks should be a “wake up call for OT security.”
Others agreed that, given how vulnerable OT is, these attacks highlight massive weaknesses in systems, and they warned of the major impact on everyday life if such systems are infiltrated.
“The willingness of malicious actors to interfere with systems that support the water we drink underscores how quickly a cyber incident can become a public safety issue,” Adam Ford, chief technology officer for state and local government and education at cybersecurity firm Zscaler, said in an email. “The challenge is especially acute in the water sector, where many operators depend on legacy operational technology systems and programmable logic controllers that were not designed with security in mind. Smaller and mid-sized utilities often lack the staff, funding, and modernization runway needed to rapidly strengthen their defenses.”
The attacks on various water systems represent an escalation by hacking groups tied to Iran, who had apparently already targeted the Los Angeles County Metropolitan Transportation Authority, as well as the South Florida Regional Transportation Authority. Experts had warned repeatedly that hacktivists linked to the Iranian government could attack critical infrastructure in the U.S. and elsewhere as retaliation for the ongoing conflict there.
And previous incidents, including a 2021 cyber incident at a water treatment plant in Oldsmar, Florida that was later blamed on employee error, highlighted how vulnerable critical infrastructure systems like water can be and that the worry about a large-scale hack taking down vital systems has existed for a long time.
“Adversaries in some way, shape or form have certainly been trying to attack us for years,” David Forbes, director of cyber physical defense at Booz Allen Hamilton, said in an interview. “And these attacks aren't isolated. We have to change our mindset and way of thinking, and we need to assume that our networks are being breached. It's not if you'll be attacked, it's when you'll be attacked, and it's what those attacks can do.”
Instead, Forbes urged water utilities to build their resilience with a three-pronged strategy focused on having visibility into networks and deploying advanced security controls like zero trust, which grants users and devices access only to parts of the network that are essential to their task and prevents outsiders from accessing anything. Then, Forbes said, there will “inevitably” be some OT network modernization that must take place.
It’s tricky, however, given that some of the technology that water systems rely on are decades old and were not designed with cybersecurity in mind, or even that they would be connected to any networks. Forbes estimated that just over half of legacy OT systems can't support modern security control requirements.
Also complicating matters is a lack of funding to support modernization and hardening cybersecurity postures. Among a list of demands for Congress, the Operational Technology Cybersecurity Coalition called for the State and Local Cybersecurity Grant Program to be reauthorized and funded, as that can help pay for necessary upgrades.
“All incidents are local,” Bolton said. “State and local governments and local critical infrastructure entities like Minnesota’s are the first line of defense against malicious cyber actors. And by not extending this grant program, Congress is leaving small towns to protect themselves from nation state actors like Iran.”
Many of the biggest cybersecurity vulnerabilities are human, too. Security company The Media Trust said in data and telemetry collected between Feb. 28 and Aug. 4 that phishing emails remain a preferred access method for hackers trying to infiltrate water systems.
“These campaigns illustrate that attackers often begin by targeting people — not infrastructure,” a company spokesperson said in an email. “Credential theft, phishing and social engineering remain some of the fastest ways to gain access to operational environments.”
Given that, Forbes said it’s important to go “back to the basics” and ensure OT networks have good cyber protocols and practices in place, an asset inventory to understand what needs protecting and an incident response plan. Information sharing about threats and best cybersecurity practices also must proceed, he said, as none of these issues are insurmountable.
“We need to do a better job sharing the technology and the cybersecurity advancements that we've made in OT cybersecurity,” Forbes said. “In the space that we operate in, both on the commercial and the federal side, we have made dramatic improvements in our ability to quickly, efficiently, cost-effectively deploy cybersecurity for OT and zero trust solutions for OT. We're doing this now… We need to move quickly to share this information and these procedures and these success stories with stakeholders, such as those facing these attacks.”




