Iran Behind US Water Hacks? 30 Systems Hit, FBI Warns Of Attacks Across 7 States

iran behind us water hacks? 30 systems hit, fbi warns of attacks across 7 states

Washington: A string of cyberattacks targeting water and wastewater systems across the United States has raised fresh concerns over the vulnerability of critical public infrastructure, with officials investigating whether the incidents are linked to Iranian hackers or another actor attempting to mimic their tactics.

In late July, Minnesota reported that at least 30 municipal water systems had been hit in what authorities described as a “coordinated cyberattack.” Days later, the Federal Bureau of Investigation (FBI) warned that malicious cyber actors had breached water and wastewater systems in at least seven states, causing operational disruptions and exposing vulnerabilities in essential public services.

Since then, states including Georgia, New Jersey and South Dakota have reported similar incidents. It remains unclear whether those attacks are among the seven states referenced by the FBI.

While the Donald Trump administration initially pointed to hackers allegedly aligned with Iran, the US government has not formally attributed the attacks to any specific actor.

How America’s Water System Works

The scale of the US water infrastructure makes it a particularly attractive target for cybercriminals.

According to federal government data, the country has around 152,000 public drinking water systems and more than 16,000 wastewater treatment facilities. Most communities source their water from lakes, reservoirs, rivers or underground aquifers.

Electric pumps transport the water to treatment plants, where it is filtered and disinfected. The treated water is then moved into storage tanks before being distributed through networks of pipes to homes, businesses, parks, schools and other public facilities.

Because these systems can stretch across several square miles, they rely on a complex network of pumps, sensors, computers and industrial control systems to keep water flowing and maintain treatment standards.

The Digital Weak Point: Internet-Connected Controllers

According to a CNN report, hackers have been targeting internet-facing programmable logic controllers (PLCs) — devices that control and monitor industrial equipment at water facilities and other critical infrastructure sites.

PLCs can regulate crucial functions such as water pressure and chemical dosing, while dashboards allow municipal workers to monitor and operate these systems.

Depending on the facility, workers may access the controllers through wired networks, radio or cellular connections, or the internet.

William Akoto, Assistant Professor of Global Security at American University’s School of International Service, explained in an article for The Conversation that attackers can begin by scanning internet addresses for exposed controllers, dashboards and remote-access services operated by outside vendors.

Once a vulnerable system is identified, hackers may attempt to gain entry using default or stolen passwords, exploit unpatched software vulnerabilities or take advantage of incorrectly configured remote-access services.

After gaining access, attackers can potentially change passwords, issue commands or attempt to modify the software controlling the equipment.

Is Iran Behind the US Water Hacks?

US officials are investigating whether Iranian hackers could be behind some of the attacks, CBS News reported, while stressing that the assessment could change as investigators gather more technical evidence.

Iran has previously been accused of carrying out cyberattacks against Israeli infrastructure, adding to concerns that Iranian-linked groups could be testing similar tactics against US targets.

However, Trump has publicly questioned the Iran theory.

At a cabinet meeting last week, he appeared to dismiss claims that Iran was responsible for the Minnesota attack and instead criticised local authorities.

“They like to say, ‘Oh, it’s Iran.’ Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota,” Trump said.

Investigators are also examining whether another threat actor deliberately copied techniques associated with Iranian hackers in an attempt to mislead authorities about the source of the attacks.

No Evidence Yet of Contaminated Drinking Water

Despite the disruptions, there has so far been no reported evidence that the attacks contaminated a water supply or made drinking water unsafe.

However, some incidents have forced utilities to switch to manual operations, while precautionary boil-water advisories have been issued in certain cases.

Experts say the danger extends beyond the physical water supply.

The attacks could undermine public confidence in the ability of local and federal authorities to protect basic services, particularly at a time of deep political divisions in the US.

“They’re attacking our trust in our government to be able to deliver basic services,” Jake Braun, a former acting White House Deputy National Cyber Director, told the BBC.

How Can US Water Utilities Protect Themselves?

Cybersecurity experts say one of the most immediate steps water utilities can take is to prevent industrial controllers and human-machine interfaces from being directly exposed to the internet.

Following the Minnesota incidents, the Cybersecurity and Infrastructure Security Agency (CISA) urged water utilities to place such equipment behind properly configured firewalls and other security measures.

When remote access is essential, utilities should use secure gateways or VPNs, implement multi-factor authentication and restrict users to only the access they need.

Experts also recommend changing default passwords, disabling unnecessary remote-access services and installing vendor-approved security updates on connected equipment.

Another key measure is to separate operational technology networks from business systems such as email. This can make it harder for an attacker who compromises one network to move laterally into systems controlling physical infrastructure.

Utilities should also maintain backups of controller programmes, monitor and log remote-access activity, and regularly practise restoring systems and operating critical functions manually.

As water infrastructure becomes increasingly connected, the recent attacks highlight a growing challenge for the US: protecting not just the physical pipes and treatment plants that deliver water, but also the digital systems that keep them running.

source

Leave a Reply