Hackers are targeting US water systems. Here’s what that means.
Government officials are warning about a wave of cyberattacks on water utilities in the US.
At least seven states have reported incidents to the FBI since July 27. The agency hasn’t identified the attackers’ motivation or identity, calling them only “malicious cyber actors” and saying they were remotely accessing internet-facing computers used by water utilities. The hackers changed settings, IP addresses, and passwords, the FBI said. In some cases, the attacks weakened the plant operators’ ability to monitor and control their equipment.
Cybersecurity experts have voiced concerns for years about cyber vulnerabilities in water systems and other critical infrastructure, such as energy and healthcare, including the possibility of attacks by foreign adversaries. In April, the FBI and other federal agencies warned about ongoing Iran-affiliated cyber threats, including those targeting water systems.
What a hacker can actually do when they access a water system varies widely depending on the device they hack. There’s also a huge variety in how the roughly 148,000 public drinking water systems in the US operate, including the about 50,000 systems that supply drinking water to residents year-round.
“It really depends on the device and what that device is managing or controlling,” Kevin Morley, federal relations manager for the American Water Works Association, told Business Insider.
“It could be a pump, it could be a motor, and it could be something as simple as a tank-level log that just says the tank is full or not full.”
Some of the recent attacks have resulted in real-world impacts, such as loss of water pressure and flooding, according to the FBI, though the agency did not say where those incidents occurred.
City officials in Braham, Minnesota, said a cyberattack shut down the controls for its well and water treatment plant, temporarily causing the city to rely on its water tower stores. State officials said more than 30 community water systems in Minnesota were targeted last week, while officials in Michigan said nine water systems were targeted.
The hackers accessed devices with internet access
Joshua Corman, executive-in-residence for public safety and resilience at the Institute for Security and Technology, said that connecting the computers that control water equipment to the internet creates an additional avenue for attackers.
“With great connectivity comes great responsibility,” Corman said, riffing on a famous line popularized by the Spider-Man comics.
In a notice issued to water utilities last week, the FBI and the EPA said the recent attacks targeted devices connected to the internet. The agencies advised water utilities to disconnect certain computers — called Programmable Logic Controllers, or PLCs — from the public-facing internet and to strictly control their network access, among other measures.
Corman said PLCs can be programmed with “if this happens, then that happens” functions. A utility might set one to keep water pressure within a certain range, to alert workers if it gets too high or too low, or to shut off a pump before equipment is damaged. Corman said a hacker could, for instance, disable an alert that would notify an employee that part of the system needs attention.
Disruptions to water service can have far-reaching effects, including on businesses, hospitals, and fire response. “No water is no hospital in two to four hours,” said Corman, who runs an initiative called UnDisruptable27 focused in part on improving the resilience of water systems that support hospitals.
Improving cybersecurity at water utilities
Many cybersecurity experts agree that more could be done to shore up the cybersecurity of critical utilities.
Morley said that setting universal cybersecurity standards for water utilities in the US can be challenging because they vary widely in the populations they serve, the systems they use, and the extent of their existing cybersecurity measures. He said what’s right for one utility might not be right for another.
The American Water Works Association has advocated for developing nationwide minimum cybersecurity requirements for water utilities, shaped by water and cybersecurity professionals.
Improving protections for water systems is also a matter of national security, said Corman, who advised on cybersecurity efforts for Operation Warp Speed during the pandemic.
He added that water utilities should strengthen their resilience before a more serious attack forces them to do so.
“You want to dig a well before you’re thirsty.”