Water systems are ripe for cyberattacks, experts warn after suspected Iranian hacks – The Oakland Press | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


By Ellen Nakashima, Amy B WangTHE WASHINGTON POST

In late 2022, Microsoft detected the hack of a water system in Guam that U.S. intelligence agencies in the following months determined was orchestrated by China. The idea wasn’t new. The spy agencies had long watched as Iran targeted Israeli water systems.

“That another nation state was doing it to us – that was unsettling,” recalled one former U.S. official, who, like several others interviewed for this story, spoke on the condition of anonymity because of the matter’s sensitivity.

Senior U.S. officials were concerned that such intrusions could affect military bases on Guam, but also civilian water supplies, many of which were poorly protected against hacks.

The Biden administration, alarmed by the spring 2021 ransomware attack on Colonial Pipeline, had already moved to regulate pipelines and then railroads.

Now they wanted to move on water.

In March 2023, the Environmental Protection Agency issued a memo to require that states work with local officials to spot weaknesses in water systems that hackers could exploit, and then develop plans to remediate them. Municipalities could apply for federal grants to help defray costs.

But attorneys general in three Republican-led states – Arkansas, Iowa and Missouri – sued, arguing that the memo exceeded the EPA’s authority, failed to provide for public comment and was a financial burden on small towns. The federal appeals court for that region, seen as among the most conservative, halted the rule change. The EPA withdrew it.

Late last month, a water utility in the western part of Arkansas, one of the states that sued, was hit with a cyberattack, part of a spate of intrusions into municipal water systems that U.S. spy agencies believe is the work of Iranian regime hackers. The campaign comes as a U.S.-launched war with Iran moves into its sixth month, with Tehran showing no sign of backing down.

Had the EPA rule been in place, some experts say, the Arkansas utility or others like it might have been spared.

“Shooting it down set us back,” said Gus Serino, president of I&C Secure Inc., a cybersecurity consultant on control systems, and a former engineer at the Massachusetts Water Resources Authority. “The level of effort and expense to fix these systems is not that much. It wouldn’t remove all the risk, but would certainly remove most of the low-hanging fruit.”

The number of states affected has expanded to at least a dozen, say officials familiar with the matter, with at least 30 systems affected in Minnesota alone.

Iran’s targeting of water systems, a trend that federal authorities first warned of months ago, and a history of failed efforts to boost water utility cybersecurity has lit a fire under some members of Congress.

Sen. Adam Schiff (D-California), the top Democrat on the water panel of the Environmental and Public Works Committee, unveiled a bill Monday explicitly authorizing the EPA to regulate water sector cybersecurity. The measure would enshrine in law what the agency tried to do by executive action three years ago: require water utilities to conduct cybersecurity assessments and require corrective actions when significant vulnerabilities are identified.

Days before Iran began its recent campaign of hacks into water utilities, the Senate EPW committee unanimously passed a bipartisan measure that would help rural water systems mitigate cybersecurity risk.

Industry representatives are now saying that voluntary efforts are not enough.

The largest group representing water utilities is urging passage of a bill, sponsored by Rep. Rick Crawford (R-Arkansas), that would establish an independent nongovernmental body to develop minimum cybersecurity requirements for the water sector overseen by the EPA.

“We need minimum requirements,” said Kevin Morley, federal relations manager at the American Water Works Association (AWWA). “It’s time to step up the game.”

The flurry of activity comes as the administration has slashed cyber specialists at the Department of Homeland Security and has not sought to renew funding for cybersecurity grants to states.

President Donald Trump has blamed the states for the hacks, criticizing Minnesota Gov. Tim Walz (D) for a rash of attacks there, adding that he didn’t think Iran was the culprit.



Click Here For The Original Source.

——————————————————–

..........

.

.