Forget poisoned water, a cyberattack’s real threat to SA is empty reservoirs
Expert says attacks on South African organisations are financially motivated and not aimed at targets of national significance.
A recent cybersecurity incident at Rand Water has raised concerns about the potential threat cyberattacks pose to South Africa's water supply infrastructure. The attack targeted Rand Water's payments and GIS systems, but experts say the real danger is not contaminated water, but rather the loss of pressure and control across the utility's gravity-fed network that serves over 11 million people in Gauteng.
Anna Collard, SVP and Content Strategist, and CISO Advisor at KnowBe4, explained that while physically poisoning the water by manipulating chemical dosing is difficult to achieve, attackers can lock operators out of control systems, disable alarms, or shut down pumping stations. This could lead to reservoirs being drained in hours rather than days, leaving higher-lying areas without water first.
Bongani Majola, head of DFIR at ScaryByte, warned that attackers with write-access to programmable logic controllers could interfere with dosing or induce dangerous pressure surges, potentially causing irreversible damage within minutes. The restoration of such a compromised system could take weeks, leaving communities without potable water in the meantime.
Rand Water's own statement reassured the public that their treatment processes and quality control systems had continued to operate normally. However, experts emphasize the importance of transparency, noting that Rand Water's disclosure was adequate in addressing the safety of the water supply, but lacked detail on the extent and duration of the disruption and whether any personal or vendor data was involved.
Collard pointed out that while most cyberattacks on South African organizations are financially motivated, state-owned entities are disproportionately targeted due to their large, ageing, and technically complex systems. She cautioned against assuming South Africa is under state attack, emphasizing that financially motivated criminals are more likely to exploit vulnerabilities.
Majola outlined a two-phase approach to attacks on state-owned entities: initial automated scans for unpatched systems followed by targeted operations once a breach is confirmed. He noted that state-owned utilities have become primary extortion targets due to their critical services once a breach is confirmed.
Experts agree that the separation of IT and OT networks in water utilities has generally functioned as intended, preventing contamination of the water supply. However, the increasing use of IoT sensors and remote monitoring in "smart utilities" raises new concerns that need to be addressed.
Written by urgent.news from The Citizen's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.