Dozens of water treatment plants in the U.S. have come under cyberattack since President Donald Trump started a war with Israel against Iran in February. Cyberattacks on critical infrastructure are now a regular part of the modern world, but it raises the question: why is that infrastructure hooked up to the internet in the first place?
The problem lies with programmable logic controllers (PLCs), which control various functions at water treatment plants. The Cybersecurity and Infrastructure Security Agency (CISA) has issued alerts about PLCs, including one in July noting that “threat actors” were changing passwords to lock out the proper operators of the facilities and disconnecting PLCs by changing their IP addresses.
The threat actors are believed to be hackers affiliated with the government of Iran, believed to be motivated by the fact that the U.S. and Israel started a war with that country on Feb. 28, bombing infrastructure and assassinating top leadership. The first CISA warning of that kind was issued in April, when Iran was specifically mentioned.
PLCs are vital instruments, and having them hooked up to the internet allows for remote monitoring. They’re made by a variety of companies, including Rockwell Automation/Allen-Bradley, Schneider Electric, and Siemens. Tampering with them in even the most relatively minor way can lead to a loss of water pressure, which could allow untreated groundwater to seep into pipes, according to CISA.
PLCs are a vulnerability that can lead to potentially disastrous consequences. In Georgia, Clayton County Water Authority and Columbus Water Works have experienced recent cyberattacks in the past month, according to the FBI and EPA, which triggered water pressure disruptions. Iran is suspected to be behind the attacks.
Aside from altering the quality of the water supply or turning it off completely, Betsy Soehren Jones, Executive Director of the Critical Infrastructure Security Consortium, tells Gizmodo that you also have to think about the downstream effects.
“What if that water facility is feeding a nuclear power plant, you know, is it going to affect the cooling towers?” said Jones. “It’s not just the portability, drinkability, of course, and human lives, but then also what does that water serve?”
When there’s a disruption, there’s a necessity to revert to more manual ways of operating. And Jones says that we need drills similar to those we already have for other emergencies, such as wildfires, earthquakes, and hurricanes. That requires moving to paper and pencil sometimes, forcing the workforce to learn how things may have functioned 10 or 15 years ago.
“We just need to teach this generation how to get back to paper very, very quickly. It’s gonna happen. This is not gonna stop,” said Jones. She says the issue is much larger than simply whether devices are connected to the internet.
“It’s not the fact that they’re connected to the internet that is always the issue. It’s more about when the information comes back into the company. How is that company and that utility protecting the information as it’s moving from that field device, into the water company, going into another IT system, et cetera,” she said.
Jones pointed to states like Maryland, Virginia, and California as places where utilities are actually doing well. And it’s not a coincidence that these are states with a strong Department of Defense presence.
“You see more cyber regulations in states that have a high DOD facility in them because they want to make sure that the water doesn’t get pulled,” adding that it’s important, “because it’s a matter of national defense.”
Jones emphasized that state actors targeting critical infrastructure aren’t typically focusing on the utility for the utility’s sake. They’re trying to hit defense facilities or critical manufacturers or a factory that they care about, perhaps making components for a war: “It’s usually not the utility they’re after; it’s usually the downstream piece that they’re after.”
Jones gave the example of a cyberattack against critical infrastructure in Orlando, Florida.
“Start thinking about that domino effect of how critical was that particular facility, and what does [role] it play in that community?” said Jones. “The water company for Orlando is owned by the city of Orlando. They have 7 million people that come in and out of that city every year. That’s going to be a pretty impactful issue if something happened there,” said Jones.
Back in 2021, long before the start of the Iran War, unknown hackers tried to poison the Florida water supply by increasing the amount of sodium hydroxide, also known as lye, in the water of Pinellas County, according to CISA. The issue was quickly identified, but in a heightened threat environment like an ongoing war with Iran, all it takes is one success to cause panic and real issues downstream.
States where hackers have gone after water systems include New Jersey, South Dakota, and Michigan. In Minnesota, the state saw at least three dozen known attacks on municipal water systems during the summer, likely tied to Iran, according to the New York Times. Incredibly, President Trump didn’t blame Iran for the attacks on Minnesota. He said in July that Minnesota actually attacked itself, a ludicrous claim with no basis in fact.
“It’s not if, it’s when,” said Jones. “It’s going to happen because we’re never going to outspend China. We’re never going to outspend Russia or any of the other adversaries. We just need to assume they’re already here and start to make plans for how do you recover faster when it does happen.”
It’s not just the water supply that needs to be protected. PLCs are also used by the energy sector. Prolonged power outages would be a serious problem that comes with its own challenges. And Jones noted that everyone needs to be learning from each other as the threats become more acute: “What we should be doing is learning from each other across the country to say, this happened in this water company, this one happened at this gas company, this happened at the electric company.”