America's water systems are getting hacked amid security gaps, experts say
Summarized and contextualized by DistantNews.
At a glance
- Cyberattacks targeting U.S. public water systems are increasing, exposing security vulnerabilities in industrial control systems.
- Hackers are exploiting internet-connected devices called programmable logic controllers (PLCs), often lacking passwords or firewalls.
- While current attacks have not affected drinking water quality, experts warn these systems are "low-hanging fruit" for malicious actors, potentially linked to Iran-backed groups.
U.S. public water systems are facing a growing wave of cyberattacks, highlighting significant security gaps that experts warn could have severe consequences. Hackers are increasingly targeting these critical infrastructure components, exploiting vulnerabilities in industrial computer systems that control water pressure and treatment processes.
The bottom line is there's no one guarding these systems.
These systems often rely on programmable logic controllers (PLCs), which are industrial computers that manage essential functions. Many PLCs are connected to the internet, and security experts note that they frequently lack adequate protection, such as strong passwords or firewalls. The Cybersecurity & Infrastructure Security Agency (CISA) has issued warnings about these weaknesses, emphasizing that some systems are directly exposed online with minimal security measures.
These systems were directly on the internet with no firewalls or VPNs or anything, with no passwords set in most cases.
Officials suspect that Iran-backed hackers may be behind some of these attacks, though they stress that so far, no attacks have impacted the safety of drinking water. Utilities have generally been able to regain control of their systems quickly. However, cybersecurity experts like Joshua Corman of the Institute for Security and Technology describe these systems as "low-hanging fruit" for malicious actors due to their poor security configurations.
Water systems are being targeted specifically because they offer "low-hanging fruit" for malicious actors.
The full scale of the problem remains unclear, as federal regulations do not mandate reporting for all water system hacks. Michael Garcia, policy director of the Operational Technology Cybersecurity Coalition, stated that disclosure has largely been voluntary, leaving a gap in understanding the widespread impact. Reported incidents have occurred in at least a dozen states, including Georgia, Michigan, Minnesota, New Jersey, and South Dakota, affecting numerous community water systems and even wastewater treatment plants.
There's nothing that requires [utilities] to say, 'Here's all the information that we have. Here's how it happened.'
Originally published by CBS News. Summarized and contextualized by our editorial team with added local perspective. Read our editorial standards.