States, feds scramble to prevent more water cyberattacks

Vithun Khamsong via Getty Images
In the weeks after nine states were hit, lawmakers at the federal and state levels have proposed new funding to harden infrastructure, but experts warned they remain vulnerable.
Water operators are still reeling from Iran-linked cyberattacks on water systems in at least seven states, and governments are already trying to help avoid a repeat.
Hackers linked to the Iranian regime were blamed for compromising operational technology in water and wastewater utilities in Michigan, Georgia and other states, prompting the Cybersecurity and Infrastructure Security Agency to urge utilities to take their exposed systems down in the immediate aftermath.
Since then, governments at all levels have been searching for ways to provide more cybersecurity support to stretched critical infrastructure systems, including financially, as their ability to pay for tech upgrades is limited.
U.S. Sens. Adam Schiff, D-Calif., and Amy Klobuchar, D-Minn., unveiled legislation earlier this month that would provide greater funding for local utilities and protect water and wastewater utilities from cyberattacks, as well as strengthen oversight by the Environmental Protection Agency.
The bill would authorize an additional $300 million each year for the Drinking Water and Clean Water State Revolving Funds to be dedicated to cybersecurity improvements and require large drinking water and wastewater systems to assess cybersecurity risks as part of their existing risk and resilience planning. It also would extend federal cyber incident reporting requirements to state- and locally owned water and wastewater systems that were previously exempt, among other requirements.
Smaller water systems and those with fewer resources would get greater flexibility and receive priority for federal funding, the pair said.
“The recent cyberattacks on Minnesota have highlighted the urgent need to improve the security of our water systems and critical infrastructure,” Klobuchar said in a statement. “Our legislation will direct the EPA to assess water infrastructure cybersecurity and identify vulnerabilities, and help municipal water systems defend against cyber threats. Protecting our critical infrastructure and the safety of Minnesotans is a top priority.”
Smaller utilities also received help earlier this month with the Water Watch Center, a joint effort between the National Rural Water Association and DEF CON Franklin, a project of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy. The center will provide direct cyber mitigation support to utilities that serve less than 10,000 people, which is most of the community water systems in the U.S.
Outside experts said those governmental efforts should go even further, however.
James Turgal, a former agent at the Federal Bureau of Investigation and current vice president of global cyber risk and board relations at cybersecurity company Optiv, said that if such attacks are left unaddressed, they could expand into the healthcare, transportation, and energy sectors, where he warned “the operational, economic, and public safety consequences would be far more severe.”
"The recent Iranian-linked cyber intrusions targeting U.S. water treatment facilities should be a turning point for critical infrastructure security,” Turgal said in an email. “Congress should establish mandatory baseline cybersecurity requirements for the water sector and create either an independent non-governmental oversight authority or strengthen EPA oversight to ensure consistent operational technology and programmable logic controller security standards across the nation's water utilities.”
Meanwhile, Tatyana Bolton, executive director of the Operational Technology Cyber Coalition, said last month the attacks should serve as a “wake up call” and called on Congress to, among other things, reauthorize and fund the State and Local Cybersecurity Grant Program.
Beyond that, Mike Searight, a former chief information officer of Waco, Texas who is now a senior advisor for software company Elisity, called on critical infrastructure operators and governments to have better asset management, including making sure OT is not connected to the internet. He also pointed to new initiatives like the state-level Texas Cyber Command as a better way to respond, especially in areas with fewer resources.
“I think that the states need to lean in on this as well, to support these smaller cities so they have a number to call and they have people to call when they have issues like this,” he said. “I think that's a critical piece that's missing here.”
Other threats are already on the horizon. A joint bulletin from the FBI, National Security Agency, CISA and other federal agencies warned of an active cyber threat to certain PLCs, where bad actors use exploitation scripts generated by artificial intelligence that are disguised as legitimate monitoring tools. Among the most targeted sectors are water and wastewater, energy and critical manufacturing.
“Using AI gave attackers faster discovery and exploitation of the attack surface,” Dan Moore, senior director for customer identity and access management strategy at software company FusionAuth, said in an email. “The suggested defenses are what we’ve heard over and over again: apply patches, don’t put systems on the internet, use strong access controls, monitor important systems, and don’t leave authentication in the default state. Hackers don’t need AI to discover new vulnerabilities. All they need to do is exploit weaknesses that we know we should have patched long ago.”




