
I’ve spent years writing about the need to update default passwords on internet-connected devices, but the recent cyberattacks on our water systems show that the same preventable flaws continue to leave our most critical infrastructure vulnerable.
Starting on July 26, more than 30 water systems in Minnesota started experiencing symptoms of a coordinated cyberattack. A week and a half later, those attacks had spread to at least a dozen states, leading to widespread disruptions in service, boil-water notices, drops in pressure and flooding.
In a joint statement on July 30, the Federal Bureau of Investigation and Environmental Protection Agency described a situation that will sound familiar to anyone who’s followed cyberattack stories in recent years: Malicious actors gained access to internet-connected devices, changed the IP addresses and passwords and took control of their operations. Iranian hackers are likely behind the attacks, according to multiple news reports.
In most cases, facilities were able to restore services within hours by switching to manual operations. But experts say the attacks highlight alarming vulnerabilities in the security of our critical infrastructure.
“We’re in a lot worse shape than you would think,” says Maurice E. Dawson, a professor at the Illinois Institute of Technology who studies critical infrastructure cybersecurity.
The attacks shouldn’t have come as a surprise to anyone. As far back as 2023, the Cybersecurity and Infrastructure Security Agency issued an alert about threats targeting water systems by exploiting internet-connected devices with default passwords or no password at all.
In April this year, CISA put out another warning to water facilities about Iranian-affiliated actors potentially targeting US water and energy systems. The agency updated the advisory with additional guidance four days before the first attack in Minnesota was reported, listing the specific devices it had observed being targeted. Again, it urged operators to “ensure device passwords are changed from their default.”
How malicious actors access critical infrastructure
I’ve been writing about attacks on Wi-Fi routers for years, and it’s shocking how much CISA’s guidance to water systems mirrors what I tell internet users all the time: Change default credentials, use a VPN, keep devices updated with the latest security patches.
In the recent attacks on water systems, the open doors were industrial computers called programmable logic controllers, or PLCs. Like Wi-Fi routers, PLCs “serve as the central nervous system for complex industrial control systems,” according to Process Solutions, a company that manufactures the devices.
You’ll find them in virtually every industrial setting across the country, including food processing plants, water treatment facilities and electrical substations. Many of them have been in service for decades without security updates, making them inviting targets for attack.
Once found, the passwords were either too weak or too obvious. “It was very much a low-hanging fruit for an actor to go and attack these systems,” said Michael Garcia, policy director of the industry group Operational Technology Cybersecurity Coalition and former CISA associate chief.
On July 30, the research firm Censys identified 4,148 internet-exposed hosts made by Rockwell Automation, with 71% of them living in the US. Ron Fabela, an industrial control systems researcher, demonstrated how a typical attack might work in an interview with CSO Online. A malicious actor could scan Shodan, a search engine for internet-connected devices, looking for public IP addresses in a specific area. From there, they could identify which PLC model a water facility uses, pull up the manufacturer’s user manual and input the factory login credentials.

“These are PLCs that were connected to the internet that shouldn’t have been connected to the internet,” said Garcia. “And once they were found, they had either no passwords on them or weak passwords like ‘1234’ or ‘password.’”
From there, it would be as simple as entering the default credentials and changing them to lock out the utility operators from the system. That’s why CISA’s immediate advice to all operators was to disconnect PLCs from the internet and switch to manual operations.
Why infrastructure attacks are hard to prevent
There are around 156,000 public water systems in the US, and 97% of them serve 10,000 or fewer people. These systems generally operate on razor-thin budgets and minimal IT staffs.
“These are older operating systems that aren’t getting regular updates,” Dawson said. “It may be secure for the first month, but it gets weaker over time. Then, after many months, many years, that system is very vulnerable, and it’s expensive to repair.”
There has been some effort by the federal government to help critical infrastructure operators like water utilities modernize their cybersecurity practices.
In 2022, Congress appropriated $1 billion over four years for the State and Local Cybersecurity Grant Program, which aimed to help local communities prepare for “increasingly sophisticated and ever-changing cyber threats.” That money is now spent, and a reauthorization bill has been stuck in Congress.
“It comes down to cost,” said Garcia. “There are bills to reauthorize these programs, but for whatever reason, they’re being stalled.”
What you can do to stay safe
This wave of attacks had relatively limited impacts. Even in the areas that were most severely debilitated, most people never lost water. Still, now is a great time to make sure you’re following some best practices in case there’s a more severe attack in the future. Here’s what experts recommend:
- Stock up on water: The Federal Emergency Management Agency recommends storing at least 1 gallon of water per person per day for several days. The agency recommends buying commercially bottled water and storing it in a cool, dark place. If you prepare your own water containers, they should be cleaned with dishwashing soap before use, and water should be replaced every six months.
- Follow utility providers on social media: Most local governments and utilities post updates on social media when attacks like these occur. Platforms like Facebook, Instagram and X were the best places to get the latest information, such as boil-water notices issued in some areas. In some areas. You can also sign up for text alerts with the latest news.
- Make a plan for water treatment: If your local utility issues a boil-water notice or you’ve used all of your stored water, it may be necessary to treat suspicious water. FEMA recommends boiling water for at least 1 minute.
The bottom line
This wave of cyberattacks crossing a dozen states is one of the more alarming breaches in recent memory, but this type of infrastructure targeting is nothing new.
Suspected Iranian hackers targeted water systems in Arkansas City, Kansas, in 2024, and Minot, North Dakota, in March of this year. A 2021 ransomware attack on the Colonial Pipeline caused widespread fuel shortages on the East Coast. An Iranian attack in March on the medical equipment supplier Stryker caused a temporary companywide shutdown.
“This has been occurring for years,” Garcia said. “We’ve just been extremely fortunate that there hasn’t been a mass casualty event. But there is that potential.”
Source link