Breaking
Floor Plans

Hackers hit US water systems in rising attacks

Hackers hit US water systems in rising attacks - water systems hacked
Hackers hit US water systems in rising attacks

At least 12 states have faced cyberattacks on water and wastewater systems since late July, interrupting operations and prompting boil-water advisories in some areas.

The incidents, which did not include ransom demands, displayed an unusual level of coordination. Evidence suggests Iran may be responsible, though U.S. officials have not publicly confirmed the source.

How the attacks unfolded

The FBI reported that intruders accessed internet-connected operational technology devices like remote switches, valves, and pumps. They then changed IP addresses and passwords, locking out plant operators from monitoring and control systems.

Federal agencies advise removing programmable logic controllers from direct internet access, enforcing strong passwords, and limiting device communication to approved traffic only.

Cyberattacks on water systems are not new. In 2021, an unauthorized user increased sodium hydroxide levels at a Florida treatment plant to hazardous levels before an operator corrected it. Last November, an Iran-backed group disabled a water pressure regulator in Pennsylvania, though drinking water supplies remained unaffected.

Why water systems are vulnerable

Most U.S. water infrastructure prioritized reliability over security. Many plants, built in the 1940s and 1950s, relied on analog controls later connected to the internet for convenience. This transition introduced new security gaps.

Melvin Newman, CEO of Patabid and a former chief estimator, said these older systems were never built with security in mind. “They were extremely reliable, but security was not part of the design,” he explained. “Now, the air gap between SCADA and the internet can disappear by accident.”

Related: Modern Ontario Home Blends With Nature

SCADA systems manage industrial processes. Once isolated on private networks, many now link to corporate IT systems and the web, increasing their exposure to threats.

Human mistakes remain the largest risk. Poor passwords, misconfigured software, and phishing attacks create opportunities for intruders. Even isolated systems can be compromised, as seen with the 2010 Stuxnet virus, which spread through an infected USB drive.

Congress is reviewing the Water Resources Development Act of 2026, which would provide $25 million annually for water system cybersecurity. With about 23,000 wastewater treatment facilities nationwide, the funding would average roughly $1,087 per facility—insufficient even if directed toward high-density areas.

The challenge extends beyond funding. Many municipal plants operate with limited staff, and employees often lack cybersecurity training. Newman points to the U.S. Navy’s World War II damage control practices as a potential model—not for the technology, but for supporting a culture of readiness and quick action.

He noted the Navy’s ability to train personnel effectively. “Their methods created an unstoppable force,” he said. “We need to build that same mindset in municipal workers.”

Attacks continue without a clear resolution in sight.

Similar security concerns arise in other infrastructure projects, where older designs meet modern connectivity. A cabin remodel in Methow Valley preserved original structural elements while updating systems for better efficiency, showing how tradition and innovation can coexist.

cyberattacks fbi infrastructure iran security
Rachel Parker

Leave a Reply

Your email address will not be published. Required fields are marked *