Cyberattacks on Water Utilities: A Preventable Threat
Last week, the FBI and EPA issued a joint alert that should concern anyone who drinks water in America. Since July 27, water and wastewater utilities in at least seven states have reported cyberattacks against internet-facing programmable logic controllers (PLCs), the small industrial computers that run pumps, valves, and treatment equipment.
Some of these attacks degraded operations, with utilities reporting pressure loss and flooding, several systems reverting to manual control, and one Minnesota community declaring a local state of emergency. The attackers didn’t use sophisticated methods, instead finding controllers exposed to the public internet, many of which were old and no longer receiving security patches.
A Familiar Pattern
This is not the first time the water sector has faced cyberattacks. In late 2023, attackers compromised controllers at water utilities across several states, including a widely reported incident in Aliquippa, Pennsylvania. The federal government issued guidance then, but the problem persists.
The difference between then and now is that attackers have grown in ambition, moving from defacing screens to disrupting operations across dozens of systems at once. They are exploiting the fact that third-party integrators often deploy the same vulnerable configuration across many small utilities.
Prevention is Possible
The uncomfortable truth is that these attacks were preventable. The reason they weren’t stopped is more structural than technical. The United States has roughly 50,000 community water systems, most of which are small, publicly funded, and run by operators whose primary job is keeping water safe and flowing. Cybersecurity ranks far below that, if it ranks at all.
The devices in question are often a decade or more old, and replacing them takes capital that these utilities don’t have. Rules governing water cybersecurity remain mostly voluntary, and attackers understand these economics perfectly.
Taking Action
Inaction is a choice. The defenses that work here cost little and require no exotic technology. The FBI and EPA guidance is sound, and every water and wastewater organization should act on it this week, not later.
- Get controllers off the public internet. No PLC should be reachable from the outside world.
- Remote access should go through a secure gateway that mediates, monitors, and logs every connection.
- Fix passwords. Default and shared credentials are still the most common way in. Strong, unique passwords are the cheapest security control available.
- Restrict communication between devices. Firewall rules and access control lists should allow only expected communication between known control system devices.
- Lock the logic. Keep physical and software key switches in the run position except during authorized updates.
- Practice running manually. The utilities that survived these attacks best were those that switched to manual operations quickly.
- Verify, don’t assume. Nearly every utility believes its PLCs aren’t internet-exposed, right up until an inventory proves otherwise.
Continuous monitoring of OT environments exists to turn signals into alerts within minutes instead of days. That difference is the difference between an incident report and a boil-water notice.
Water systems have the least margin for error and, too often, the fewest resources to defend themselves. The FBI and EPA have told us plainly what’s happening and what to do about it. The attackers are betting we won’t follow through. For the third time in three years, they’re testing that bet. Let’s finally prove them wrong.
Source: CyberScoop