Treaty and Talks
Relationships

Cyberattacks on U.S. Water Supplies Highlight Vulnerability

A recent spate of cyberattacks on U.S. water supplies has highlighted the sector's vulnerability, with at least seven states affected and potentially as many as a dozen.

A recent spate of cyberattacks on U.S. water supplies has highlighted the sector's vulnerability, with at least seven states...

The U.S. water sector is facing a growing threat from cyberattacks, with at least seven states targeted over the past two weeks. The attacks, which are believed to be linked to Iran, have highlighted the sector's vulnerability and raised concerns about the potential for disruption to water supplies.

The hackers targeted programmable logic controllers, which allow utility providers to manage the flow and chemical composition of water supplies. In many cases, they modified passwords to lock out operators and disconnected the controllers. While there are no indications that the attacks have caused major disruption or lasting damage to water supplies, they were serious enough in some cases to have resulted in boil water notices to affected people.

The implications of the attacks are more severe, however. Programmable logic controllers help operators regulate the flow, distribution, and chemical composition of the water supply. There have been a few close calls in the past, including a 2021 incident in Florida where a hacker attempted to increase chemical levels at a plant before being discovered in time, and a 2024 incident in Texas where an attack caused a tank to overflow.

While the U.S. government has yet to officially attribute the latest attacks to a particular adversary or group, several reports and multiple former officials indicate that they are very likely linked to Iran. "I'm incredibly confident that these attacks are Iran," said Cynthia Kaiser, a former deputy assistant director of the FBI's cyber division. "The geopolitical motivation, capability, the recent history of targeting that sector... all of that points to Iran, and there's not a plausible alternative."

The water sector is particularly vulnerable to cyberattacks due to the sheer number of possible infiltration points. According to the EPA, there are more than 148,000 public water systems across the United States, serving homes, schools, hospitals, and other sections of the economy. "It has an incredible attack surface - there's so many places," said retired Gen. Paul Nakasone, who served as director of the National Security Agency and head of U.S. Cyber Command. "When an adversary looks at it, it's like: 'Oh, my goodness, this is low-hanging fruit for us.'"

The water infrastructure in the United States is also far more decentralized than other sectors, with more than 52,000 different local water providers across the country. Many of these providers are small and lack the resources to implement robust cybersecurity measures. "The water municipalities generally just don't have the resources," said Rob Joyce, a former NSA cybersecurity director. "Most of them are small, they're very decentralized, they're often running technology installed by a third party, and they don't understand the cyber implications of the technology they're running."

The recent attacks have reignited conversations about the need for explicit cybersecurity authority in the water sector. In 2023, the EPA put forward a memorandum seeking to mandate cybersecurity evaluations as part of regular audits of water systems, but it withdrew that memorandum after multiple states filed lawsuits alleging that the required cybersecurity improvements would be too costly for water utilities to bear.

The scale and scope of the latest attacks has sparked widespread alarm and prompted a raft of moves to help shield U.S. water infrastructure from future attacks. This month, New York announced more than $9 million in cybersecurity grants to help safeguard more than 150 water systems across the state. And just this week, Democratic Sens. Adam Schiff and Amy Klobuchar introduced legislation, called the Water Shield Cyber Act, aimed at fortifying cybersecurity protections for water infrastructure across the United States.

The attacks have also cast a fresh spotlight on previously proposed legislation that would authorize an independent organization to spearhead the development of cybersecurity requirements in the sector. Private sector volunteers are also jumping into the fray, with the launch of a new initiative called the Water Watch Center, which will bring together cybersecurity companies and volunteer hackers to work with the National Rural Water Association to help defend smaller water utilities against foreign adversarial cyberattacks.

The attacks are coming at a time when water resources are increasingly weaponized in global conflict, with profound implications for governments around the world. The recent attacks on U.S. water supplies serve as a stark reminder of the need for robust cybersecurity measures to protect this critical infrastructure.

## A Decentralized and Vulnerable Sector

The water sector is particularly vulnerable to cyberattacks due to its decentralized nature. There are more than 52,000 different local water providers across the country, many of which are small and lack the resources to implement robust cybersecurity measures.

## The Need for Explicit Cybersecurity Authority

The recent attacks have reignited conversations about the need for explicit cybersecurity authority in the water sector. In 2023, the EPA put forward a memorandum seeking to mandate cybersecurity evaluations as part of regular audits of water systems, but it withdrew that memorandum after multiple states filed lawsuits alleging that the required cybersecurity improvements would be too costly for water utilities to bear.

## A Call to Action

The scale and scope of the latest attacks has sparked widespread alarm and prompted a raft of moves to help shield U.S. water infrastructure from future attacks. This month, New York announced more than $9 million in cybersecurity grants to help safeguard more than 150 water systems across the state. And just this week, Democratic Sens. Adam Schiff and Amy Klobuchar introduced legislation, called the Water Shield Cyber Act, aimed at fortifying cybersecurity protections for water infrastructure across the United States.

## Conclusion

The recent attacks on U.S. water supplies serve as a stark reminder of the need for robust cybersecurity measures to protect this critical infrastructure. The water sector is particularly vulnerable to cyberattacks due to its decentralized nature and lack of resources. The need for explicit cybersecurity authority in the water sector is clear, and it is imperative that policymakers take action to protect this critical infrastructure.

Topics

Related coverage

More from Relationships