Weak Passwords Just Exposed Our Water Supply to Iranian Hackers
Our critical utility infrastructure can make the same classic mistakes as we do with our everyday connected devices.
A cyberattack targeting water systems across the United States has been traced back to Iranian hackers, according to recent reports. Starting on July 26, the attacks affected more than 30 water systems in Minnesota before spreading to at least a dozen other states. Symptoms included disruptions in service, boil-water notices, drops in pressure, and flooding.
The Federal Bureau of Investigation and Environmental Protection Agency attributed the attacks to malicious actors who gained access to internet-connected devices, changed their IP addresses and passwords, and took control of their operations. A large portion of the affected facilities were able to restore services within hours by switching to manual operations.
However, cybersecurity experts warn that these attacks highlight alarming vulnerabilities in the security of critical infrastructure. Default passwords and lack of password protection on internet-connected devices have been identified as major contributing factors. Experts have been warning about such threats since at least 2023, urging facilities to change default credentials and implement stronger security measures.
The attacks exploited industrial computers called programmable logic controllers (PLCs), which are often left in service for decades without security updates. Once discovered, the weak or default passwords made them easy targets for hackers. CISA had previously issued warnings about potential Iranian-affiliated actors targeting US water and energy systems, including specific devices that were under attack.
The high number of internet-exposed hosts identified by Censys, with 71% located in the US, further emphasizes the urgency of addressing these vulnerabilities. Despite the severity of the attacks, most people continued to have access to their water supply. However, the incident serves as a reminder of the need for robust cybersecurity practices, particularly for critical infrastructure operating on limited budgets and with minimal IT staff.
Experts recommend disconnecting PLCs from the internet and switching to manual operations as immediate steps to mitigate the risk of future attacks.
Written by urgent.news from CNET's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.