What You Need to Know
• U.S. public water systems in at least a dozen states have been targeted by cyberattacks linked to Iranian hackers.
• The Cybersecurity & Infrastructure Security Agency reported that many water systems use vulnerable internet-connected programmable logic controllers.
• The Clayton County Water Authority in Georgia reported a cyberattack on July 27, affecting 300,000 customers.
U.S. government officials have raised alarms about a series of cyberattacks on public water systems across at least a dozen states, which are believed to be linked to Iranian-backed hackers. Although these attacks have not compromised drinking water, utilities have swiftly regained control of their systems. Cybersecurity experts emphasize that these incidents reveal significant vulnerabilities in many public water systems, which rely on poorly secured, internet-connected industrial computers known as programmable logic controllers (PLCs). These PLCs, which manage critical functions like water pressure and chemical treatments, often lack adequate security measures, making them susceptible to hacking.
Why It Matters
The recent wave of cyberattacks on U.S. water systems highlights the critical security vulnerabilities within essential infrastructure. Many public water utilities do not have federal regulations mandating the reporting of such incidents, leading to potential underreporting of attacks. The reliance on internet-connected programmable logic controllers without proper security measures poses a significant risk to public safety and operational integrity. Historical precedents indicate that compromised water systems can have severe consequences, emphasizing the need for improved cybersecurity protocols in this sector.
Read the Full Story →