How hackers are saving America’s water from cyberattacks

Rachel Feltman: For Scientific American’s Science Quickly, I’m Rachel Feltman.
Last month we talked briefly about how and why cyberattackers are targeting municipal water utilities throughout the United States. Today we’re taking a closer look at that story—why we’re so vulnerable to these attacks but also how volunteer hackers are working to protect our access to clean, safe water. Our guest today is Eric Geller, a senior reporter at Cybersecurity Dive, who focuses on federal cybersecurity policy and critical infrastructure protection.
On supporting science journalism
If you’re enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today.
Feltman: Thanks so much for coming on to chat with us today.
Eric Geller: Thanks for having me.
Feltman: So I wanna start with a very basic question. When we talk about cyberattacks, what is it we’re actually talking about? What’s under that umbrella?
Geller: Well, it’s a wide range of things. It can be everything from guessing somebody’s password or tricking them into handing it over and then just logging in like a real authorized user and messing with the computer system. Or it can be essentially fooling the computer system itself, taking advantage of a vulnerability in the software to get access to something that you shouldn’t be able to access. And then you can, sort of, layer on top of that the supply chain aspect, which is: all these companies are interrelated. So if you can get into one company, you might be able to then jump from there into another company’s systems, either by, again, pretending to be an employee of that first company or by taking advantage of actual connections between the computer systems and moving between them, like a burglar going from one room of a house to another. So there’s really a wide range of technical and social things that are involved here.
Feltman: So we recently talked on the show about water utilities, you know, being vulnerable to cyberattacks. Could you tell us a little bit more about why water is so vulnerable when it comes to cybersecurity?
Geller: We’re really talking about a combination of factors. First of all, many of these are very small. A lot of them are in rural areas. Even the ones that aren’t don’t have a lot of employees; they certainly don’t have a lot of people who are dedicated to security. They know water systems, they don’t necessarily know cyberdefense. There’s not a lot of money to upgrade the technology, and the technology is often old. Some of this equipment is running very early versions of Windows, and there’s not a lot you can do to harden that kind of technology. You can really just bolt security on top of it, and that’s not gonna be as effective as booting up a brand-new machine running the latest version of Windows. So we’re talking about old equipment.
We’re also talking about equipment that is not standard off-the-shelf commercial stuff like an iPhone or a version of Windows on your laptop. These are devices that have bespoke software on them. It’s not always easy for the employees at these water stations to understand the security implications, and they’re not easy to upgrade, and oftentimes they’re not designed with security in mind. So recently we saw a lot of attacks where once the hackers found a device that was accessible from the Internet, which is already something you’re not supposed to allow, they discovered that the login system used a default password, and that’s a second thing you’re not supposed to allow. So that’s a combination right there of two problems that really should not exist, but they do exist because a lot of these utilities are not ready to, sort of, be looking for those problems.
Feltman: So let’s talk about DEF CON Franklin. How did it start, and what’s the goal here?
Geller: Well, DEF CON Franklin grew out of the DEF CON Hacker Conference in 2024. It was sort of a spin-off effort that was designed to bring together people who are experts in cybersecurity and wanna improve and protect their communities with infrastructure operators that don’t have cybersecurity expertise and don’t have a lot of money.
So the system connects volunteers with infrastructure operators that want help making specific changes in their networks. The initiative that I wrote about recently for Cybersecurity Dive was focused on pairing up utilities with experts who could basically make a series of targeted improvements, whether that is helping them understand all the devices on their network—that sounds so simple, but oftentimes these utilities don’t know what they’re running—or whether it’s things like setting up multifactor authentication that you don’t just need a password to log in—these very basic things. DEF CON Franklin sort of connected experts with water systems that wanted this kind of help.
Feltman: I have friends who go to DEF CON, because I’m a nerd, but I think maybe some listeners—their idea of a hacker crystallized when Hackers came out, which unfortunately, I’m so sorry to say, was 30 years ago. Really shocking stuff. But can you tell us a little bit more about who people are who go to DEF CON, who self-identify as hackers these days? What kind of crowd are we talking about?
Geller: It’s a really interesting conference. I was just there at the beginning of August. Of course, it’s gotten a little more corporate over the years, but it does still try to maintain that independent streak, that sense of, you know, we’re the wild fringes of the community. Of course, in reality, a lot of these people are longtime professionals. They’re working in mid-level or senior-level roles inside companies. They are the security people for their companies. You also have a lot of enthusiasts, people who maybe don’t work in cybersecurity but really care a lot about it, want to understand the state of the technology.
Maybe they work at an accounting firm or they work at a hospital. One thing we’ve seen recently is a real significant expansion of the critical infrastructure community, so that’s power plants, water systems, hospitals. They are more and more realizing that they’re vulnerable to hackers and sending people to DEF CON. And so you see folks from hospital systems. You see folks from municipalities showing up to learn from the cybersecurity community about what they can do.
Feltman: Yeah. So in the piece you reported recently, what did you hear from folks about how this is going? You know, what kind of support people are getting?
Geller: Well, I talked to one woman who is the public works director in a very rural community—Wilder, Idaho—and she was telling me about how, you know, she understands that there is a threat out there, but until she started working with a volunteer from DEF CON Franklin, it’s sort of like the expression “you don’t know what you don’t know.” There was a whole world that she just didn’t understand the contours of, and as she started to learn more about it, that crystallized for her where the risks were in her own network, and she started to make these changes so that she was more secure. And then actually one thing I really appreciated hearing from her, and was a little bit surprising in a good way, was she would go out to these meetings with other public works people from the community, from other areas in Idaho, who were also struggling with cybersecurity, and she would tell them what she had learned and try to spread that knowledge so that other communities can start making those changes.
Some of this stuff is so basic that if we were to be told, “You need to go make this change,” we would probably say, “Oh, of course, I already do that. Obviously, I’m gonna use multifactor authentication,” right? But these are not standard Windows logins. These are very complicated systems. It’s not always easy to set up this kind of technology with them. But once you do set it up, she was saying there’s this peace of mind that the entire town has now because they know that, at the very least, they’ve made it a lot harder for people to break into their systems.
Feltman: What do you think that the future looks like here? Do you think this kind of, like, grassroots mitigation is our best way forward? Or are we maybe learning lessons from this that municipalities are gonna take on more broadly?
Geller: Well, one thing that the organizers of this initiative are very clear on is: this is not a substitute for dedicated government funding in the same way that the government gives out grants to harden sports stadiums and other facilities against terrorist attacks, in the same way that major transit systems like the New York City subway are focusing on preventing bombings. These organizations, from the smallest water utilities up to the largest hospital systems, need some sort of sustained focus on cybersecurity. And for most of them, they’re not gonna be able to come up with that money on their own. It’s gonna have to be federal funding. If you talk to folks in the community, that’s their hope for the future of this project, is that it’s not gonna be a volunteer initiative. It’s going to be federal government funding and perhaps some state government funding to give these organizations the support they need to make these changes. But in the meantime, yes, there’s a significant effort to set up what you could think of as cyber civil defense in the same way that, during the Cold War, there was this focus on people helping each other make their communities resilient against some sort of nuclear attack.
We’re seeing a similar concept at play here where universities creating clinics, philanthropists are donating money to organizations that are sending volunteers out into the community. Oftentimes these students going out to work with the local hospital, the local water system to help them make basic changes.
Feltman: And what about the people on the DEF CON Franklin side? What gets them excited about doing this work? You know, are they coming back to keep helping people repeatedly?
Geller: I talked to Jake Braun, who is a former White House and DHS official who runs DEF CON Franklin, and he was telling me that originally he didn’t expect volunteers to keep coming back after they had finished a particular stint working with a water utility. But he was saying it’s really inspiring that the volunteers want to keep getting sent out to other utilities to work on more projects. And part of that is a lot of these folks either grew up in rural areas or they live in rural areas, and they know firsthand that it is threadbare budgeting in these utilities. You know, they’re struggling sometimes just to be able to afford the treatment chemicals they need. So paying for some kind of expensive cybersecurity monitoring system, that’s out of the budget for sure. They’re not even thinking about that. And so when somebody shows up and says, “I can help you make basic changes, and I’m not gonna charge you any money,” once you get through the, sort of, “Who are you, how can I trust you?” which was a very real obstacle that this program had to overcome, for the utilities, it’s a godsend. And I think for the volunteers, knowing that they can make this kind of difference in their community, it’s a significant boost for them. And so that’s what Jake Braun from DEF CON Franklin was telling me, that he’s really been impressed by the commitment of the volunteers.
Feltman: Yeah. And how did they make those inroads? What did it take for them to get the trust of these utility companies?
Geller: Well, a big thing for Franklin was partnering with the association that represents rural water systems. That’s a group that has affiliates in every state. Those state affiliates talk very closely with the utilities themselves, so there’s a trust relationship there. The utilities trust this group, so when the group comes to them and says, “Would you be interested in being part of this program? We can vouch for the program itself.” They’re gonna vet the participants on their end—that’s a real signal to the utilities that this is not some fly-by-night initiative, but this is really something that’s been thought out and planned carefully. And I can imagine being a water system operator and not wanting to let somebody sit down at my keyboard and make changes on my network. I would be very worried about what I was getting myself into. But once you have that association coming to you and saying, “Trust us, we’ve done our due diligence,” that really opened a lot of doors, and from there it was a question of getting everybody to sit down and get on the same page, because the volunteers had these grand ideas about what they could accomplish. The utilities had, in some cases, unrealistic expectations about how secure they already were, and they were saying, “Come in here and do a test on us and you’ll see that we’re secure.” And the volunteers would say, “How about we make some basic changes first so that this test is a little bit more useful?” And so connecting the two sides in a way where they had the same expectations, that was a big part of the setup for the program.
Feltman: Well, I know it’s kind of an aside, but I really loved the story behind the name of the project. I would love if you could tell our listeners a little bit about that?
Geller: Sure. The name for the program comes from Benjamin Franklin, who created the first volunteer fire department in the U.S., and the idea behind that is it was a time when a lot of systems for what is the government gonna be doing, what do we owe each other as members of this new community, had not yet been created. The rules had not yet been written. And this was the first step toward a sense of civic participation in keeping our community safe, at least in the United States. And DEF CON Franklin, is trying to bring that same spirit forward of saying that while we obviously need government funding to do any kind of uniform improvements to cybersecurity across the country, we wanna live up to that same spirit of civic participation and civic engagement.
One thing I’ll add is that DEF CON Franklin did an interesting study where they talked to utilities about all these offers they were getting from big technology companies to say, you know, “We’ll gift you this product. You can have it for free, and it will help you with cybersecurity.” And what Franklin found is in most cases, these really small utilities can’t take advantage of those offerings because either they don’t have staff on hand to monitor whatever this product is and read and analyze the data that they’re getting, or the companies are saying, “You can have this expensive device.You gotta buy it from us, but then we’ll give you the licenses to use it.” So the devil is in the details there, and I think that’s really interesting because a lot of this conversation often comes down to “ Well, just have the big tech companies give away their products to the water utilities. That will solve the problem.” And the reality is it doesn’t solve the problem because these things are, as Jake Braun told me, free like a puppy, meaning, you know, they hand you the technology, but then there’s a lot of costs on the back end that you actually need to pay to make use of the technology.
Feltman: Yeah. They’re not cleaning up the pee for you, so.
Geller: Exactly.
Feltman: Well, thank you so much for coming on to talk us through this.
Geller: Thank you so much for having me. I enjoyed it.
Feltman: That’s all for today’s episode. We’ll be back on Friday to kick off the long weekend with a chat about a new piece of genre-bending fiction about online dating.
Science Quickly is produced by me, Rachel Feltman, along with Fonda Mwangi and Jeff DelViscio. This episode was edited by Alex Sugiura. Marielle Issa and Aaron Shattuck fact-check our show. Our theme music was composed by Dominic Smith. Subscribe to Scientific American for more up-to-date and in-depth science news.
For Scientific American, this is Rachel Feltman. See you next time!