Why Hackers Keep Going After U.S. Water Supplies
A spate of new attacks believed to be linked to Iran has highlighted the water sector’s vulnerability.
Cyberattacks on U.S. water supplies have become a growing concern as at least seven states have experienced targeted breaches over the past two weeks, with some reports suggesting as many as a dozen states may be affected. The hackers specifically targeted programmable logic controllers that manage water flow and chemical composition, often locking out operators through modified passwords or disconnecting the components.
Although no major disruptions have occurred thus far, some boil water notices were issued to affected individuals.
Experts believe these attacks are likely linked to Iran, citing geopolitical motivations, capability, and a history of targeting the water sector. Past incidents involve Iran and Russia hacking into local water supplies in Florida and Texas, highlighting the vulnerability of these systems. With over 148,000 public water systems across the U.S., each with numerous infiltration points, the infrastructure is particularly weak.
Many water providers are decentralized and lack the resources to adequately secure technology, much of which is third-party and connected to the internet. This makes them easy targets, as seen in previous cases involving the Iranian hacking group "CyberAv3ngers" and components made by Rockwell Automation.
Written by urgent.news from Foreign Policy's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.