According to sources quoted by the media, at least 12 states in the United States have recently faced cyber attacks on their water supply systems. Although no major damage has been reported, the source of the attacks has not been officially confirmed. Experts are calling for the elimination of related vulnerabilities.
Recently, water supply systems in at least 12 states including Michigan, Minnesota, Georgia, New Jersey, and South Dakota have been targeted by hackers, as reported by CBS News.
In Clayton County, Georgia, the water pressure in the system of the Clayton County Water Authority, which serves about 300,000 users in the Atlanta area, dropped due to a cyber attack on July 27. The authority issued a notice advising residents to boil water before consumption. Water services were restored to normal after a few hours.
In Rapid City, South Dakota, a sewage treatment plant also fell victim to a “cyber attack” at the end of July. Local officials had to isolate the treatment system from the internet as a precaution.
A water supply system serving over 30 communities in Minnesota was similarly affected by the cyber attacks.
The FBI, EPA, and CISA jointly issued a warning on July 30, stating that hackers had remotely attacked the online infrastructure of water and sewage treatment systems in at least seven states, leading to the loss of monitoring and control functions in these systems.
Officials mentioned that some water facilities that were targeted had to switch to manual operations after losing remote control capabilities to prevent accidents. Hackers had even gained remote access to water pumps, valves, and pressure systems of these systems.
However, the drinking water safety in states has not been compromised so far. The officials are now questioning why the hackers did not cause more significant damage to water supply systems during the summer heat, such as manipulating equipment controlling chemical dosages that could endanger water quality.
Marty Edwards, the former director of the DHS’s cybersecurity response division, told CBS that this wave of cyber intrusions reflects the consequences of years of insufficient budget allocations and growing apathy towards risks in the United States.
The CISA pointed out that outdated equipment in US water supply systems is also a vulnerability. These attacks often target programmable logic controllers (PLCs) that lack protection and regulate water pressure and chemical dosages.
Joshua Corman from the Institute for Security and Technology commented that many of these systems are directly exposed online without firewalls, VPN protection, or even passwords.
Michael Garcia, the policy director of the Operational Technology Cybersecurity Coalition, mentioned that since the federal government does not mandate local businesses to report hacker attacks, the actual scope of impact may exceed the current known numbers.
Both Garcia and Corman recommend that individuals should store some drinking water at home in case of natural disasters like hurricanes or cyber attacks on water supply systems.
Experts generally agree that enhancing monitoring is a good starting point, but without substantial investments and modernization of water supply systems, the outdated infrastructure will continue to face the risk of cyber attacks.
