Why hackers targeting America’s water systems have the upper hand | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


A coordinated cyber operation affected more than 30 community water systems in Minnesota. Image: Tony Webster from Minneapolis, Minnesota, United States, CC BY 2.0 , via Wikimedia Commons

At the end of July, Minnesota detected hackers that had targeted around 36 municipal water systems in the state. Since then, at least 11 other states, including Michigan, Georgia, New Jersey, and South Dakota have discovered similar breaches, which the US government reportedly blames on the Iranian government.

News of these intrusions—especially from a cyber-capable adversary with whom the United States is at war—rightfully produces concern about the security of American critical infrastructure systems. But the cybersecurity of these systems has long been a nightmare, plaguing the many dedicated practitioners and policymakers who created the important, albeit limited, progress seen to date.

Protecting US critical infrastructure from cyberattacks requires confronting a fundamental mismatch between the threat and the government’s ability to respond. The systems at risk are sprawling, diverse, and include both private- and government-owned facilities that make up the nation’s critical infrastructure, while many of their operators lack the expertise or resources to defend themselves against sophisticated state adversaries—made worse by a failure to create strong cybersecurity regulations. At the same time, the federal government has weakened its own capacity to support those defenses. And getting stuck in endless debates about what to do carries risks of its own: The failure to clearly and swiftly respond to nation-state intrusions that are or could become disruptive can signal to adversaries that such operations are low-cost, encouraging them to become more frequent or aggressive. What’s needed to combat them is a more assertive and comprehensive approach.

Details are sparse about the suspected Iranian operations. Minnesota’s advisory stated that a coordinated cyber operation on July 26 and 27 targeted more than 30 community water systems’ operational technology—the equipment that touches the physical world, such as water treatment devices, contrasted with purely digital information technology. The state noted that the investigation and coordination with federal authorities were ongoing.

None of states has given indications that the water supplies were made unsafe for drinking, except in Georgia, where an Atlanta-area water authority said the breach caused a pressure drop (which could cause back pressure and allow contaminants to get into the system), and the agency issued a boil water advisory to the roughly 300,000 customers in its service area. Hackers in other cases interfered with operators’ remote-control functions and accessed pumps, valves, and water pressure systems.

Iran has targeted US critical infrastructure systems in the past. One of the most well-known incidents unfolded in 2013 when Iranian state hackers broke into the control system of a small dam near Rye, New York, as uncovered by The Wall Street Journal two years later. However, there were no indications that the hackers created any physical effects with said access. And the Iranian government, as is typically the case in these scenarios, did not comment (let alone confirm that it was involved).

Other nation-states, for their part, have engaged in similar activity in the United States and in the infrastructure of key allies and partners. These include Russian security service hackers breaking into critical infrastructure targets in Ukraine and Poland and Chinese state hackers extensively “prepositioning” malware, or putting disruptive code in place now in US energy grids and other infrastructure with the potential to activate it later in a conflict scenario. Needless to say, the national security risks are substantial and safeguarding these systems is thus essential.

Protecting US critical infrastructure from nation-state hackers, however, is much harder than it sounds—and it already sounds hard. The Department of Homeland Security has designated 16 official critical infrastructure sectors in the United States, from communications and critical manufacturing to emergency services and energy systems. All these sectors are critical, and any threats to them can lead to potential loss of life, serious economic disruption, and limited access to critical services like hospitals, logistics systems that transport food or prescriptions, and even water treatment.

But the critical infrastructure components in question are also diffuse. Systems in these 16 sectors are spread throughout the country, in different state and county jurisdictions, and are owned in substantial part by private companies that have varying (usually weaker) regulatory requirements compared to government-owned systems.

These systems are also diverse in nature. The information technology and especially operational technology systems deployed in a water treatment plant, an electrical grid substation, a gas pipeline, and a hospital often look very different from one another and are technically varied. Yet, conversations about protecting critical infrastructure as a whole can often lump them together and obscure all the differences in play. And they are hard to adequately secure without regulation: Experts have called for years for better cybersecurity for critical infrastructure, yet a political unwillingness to impose stronger security requirements on industry has let the wholly insufficient, each-do-as-they-please approach persist.

The second major challenge facing policymakers and the people managing these critical systems is that the foreign adversaries targeting their infrastructure are sophisticated, well-resourced, and persistent. Hackers in China and elsewhere are constantly trying to break into American systems. They can draw on large pools of technical expertise to do so, often in ways that far exceed what the United States and its allies and partners could or would leverage. Russia, for example, heavily capitalizes on cybercriminals to further state aims. Adversaries can also utilize their considerable intelligence apparatuses to inform their operations. In total, local infrastructure operators may be thrown up against the might of a hacker cell in China’s People’s Liberation Army, Russia’s military intelligence agency, or Iran’s Ministry of Intelligence and Security that is going to spend hours a day, every day of the week, for months working to get into a system.

Compounding the problem is that not every critical infrastructure operator is coming from the same defensive position. There are plenty of operators who are sophisticated and can tap into the expertise of information sharing and analysis centers, or ISACs, for threat intelligence-sharing; cybersecurity clinics that aim to bolster public-interest cybersecurity capacity; and the many technologies and years of human experience in industry, including from cyber professionals who leave government. Many others, however, simply do not have the knowledge, resources, talent, and other capabilities necessary to adequately defend their networks. The gutting of the Cybersecurity and Infrastructure Security Agency, known as CISA, which started in 2025, and its prior support of state cyber capacity has significantly exacerbated the problem amid the Iran war, Russia’s war on Ukraine, and other global conflicts and flashpoints. Building that back up, and quickly, in concert with the private sector is urgently needed.

At the strategic level, policymakers must weigh if, and how, to respond to these Iranian and other nation-state hacks of US critical infrastructure. If the hack leads to loss of life or other clear outcomes, that may create a more obvious path to a response—even though the incident is more catastrophic. If a suspected Iranian hack disrupts water treatment but doesn’t contaminate the water, or if a Chinese hack inserts malware for use later, it is easier for policymakers to get stuck in debates.

A substantial body of theoretical academic literature on cyber in the context of security, conflict, and war has posited that doing more in response to these operations could escalate into kinetic scenarios. For example, an extreme of these arguments goes, could a cyber tit-for-tat spiral into nuclear war? There are many scenarios that defense and security planners should game out and prepare for no matter how unlikely they sound. But that does not mean those mental exercises should guide policymaking. In the case of the suspected Iranian hacks and other state-initiated attacks, policymakers should consider that doing nothing only tells the adversary that they can keep attacking without consequence.

Stopping all cyberattacks is impossible, and policymakers face complex challenges in better shielding US water, energy, and other systems from intrusions. Business as usual is not going to solve the problem. At a moment when deregulation of many industries is politically in vogue, policymakers should consider that a more assertive posture—strengthening cybersecurity regulations, building the defensive capacity of infrastructure owners and operators, and demonstrating to adversaries that certain actions carry consequences—might be the best path forward.



Click Here For The Original Source.

——————————————————–

..........

.

.