Hackers just broke into America’s tap water
In the teensy Midwestern town of Braham, homemade pie capital of Minnesota, something unusual in the municipality’s computer systems knocked the city’s entire water supply offline last week. Within a few hours, dozens of other Minnesota cities discovered that their water and wastewater utilities, too, had been compromised, most likely as part of a massive […]
Last week, hackers infiltrated the computer systems controlling the water supply in the small town of Braham, Minnesota, leading to a brief disruption in service. This incident is believed to be part of a larger Iranian cyberattack that affected dozens of other Minnesota cities and at least a dozen states across the country. The attack highlights the outdated and vulnerable nature of America's aging water infrastructure, which has been increasingly connected to the internet and exposed to modern hacking vulnerabilities.
Critical infrastructure like water systems and energy grids are prime targets for hackers, not just for financial gain or data theft, but also for control, disruption, or even as acts of war. The nation's water system, built before the internet era and before AI made hacking easier, lacks the necessary security measures to protect against such threats. While some may assume hackers are primarily motivated by money or data, they are increasingly exploiting critical infrastructure for control and disruption purposes.
Water systems, often operated by local authorities without dedicated IT teams or sufficient resources, are particularly vulnerable. Many of these systems rely on programmable logic controllers (PLCs) that can be remotely accessed, sometimes without passwords or firewalls, making them easy targets for hackers. In the Braham incident, hackers gained control over levers that regulate the amount of corrosive chemicals in the water treatment process, showcasing the potential for serious damage if left unchecked.
The lack of proper cybersecurity measures in small water systems has made them easy targets for faraway adversaries. Municipalities have largely overlooked cybersecurity concerns until recently, with only a few states implementing basic regulations and training programs to address these vulnerabilities. The fact that most water systems are small and operate under limited resources makes them particularly susceptible to hacking attempts.
While the recent Braham attack did not result in widespread damage or loss of life, it underscores the urgent need for improved cybersecurity in America's water infrastructure. A worst-case scenario could involve open floodgates, water poisoning, or complete water cutoffs, potentially endangering public health and safety. The good news is that, in the case of the Braham incident, the impact was limited, and services were quickly restored.
However, the incident serves as a stark reminder that water systems are not as secure as one might assume. The nation must prioritize the protection of its water infrastructure, which is crucial for public safety and health. Basic cybersecurity hygiene is not enough; comprehensive security measures, including firewalls, encryption, and password protection, are essential to safeguard critical infrastructure from potential threats.
Written by urgent.news from Vox's reporting — not their text. Machine-written; read the original for the full account.



