Cyberattack Disrupts Water Supply in Small Midwest Town
In the teensy Midwestern town of Braham, homemade pie capital of Minnesota, something unusual in the municipality’s computer systems knocked the city’s entire water supply offline last week. Within a few hours, dozens of other Minnesota cities discovered that their water and wastewater utilities, too, had been compromised, most likely as part of a massive Iranian cyberattack, the kind that US officials have been warning about since the war began.
At least a dozen states have been affected by the attack, which briefly led to a flurry of small-town service disruptions, boil-water notices, and local flooding. Water wells, dams, sewers, and pipelines are some of America’s oldest and creakiest pieces of infrastructure, built long before the internet existed, and certainly long before AI made hacking much easier. While you may assume most hackers are in it for the money or for data, some have targeted critical infrastructure like water systems or energy grids in ploys for control or disruption — or worse still, as acts of war.
As last week’s attacks show, the nation’s water system is woefully unprepared. But how worried should you be that the very infrastructure that keeps our water taps running is, apparently, hackable?
The Mechanics of a Cyberattack on Water Supply
When we say the water supply got hacked, what we really mean is that someone, somewhere has broken into the computer that controls a local water treatment plant or reservoir, and is now pulling the levers, like the one that decides how much of a corrosive chemical can safely go into cleaning the water that comes out of your tap.
These levers were once manual buttons and knobs operated in-person by real live humans, meaning that — barring a natural disaster, bomb, or break-in — protecting them was about as simple as building a fence and hiring guards. Increasingly, however, these levers have gone digital, allowing technicians to monitor and troubleshoot problems in real-time. But this convenience exposes long-standing infrastructure to modern vulnerabilities. Most local water systems are operated by local authorities that often lack a dedicated IT team, resources, or money to thoroughly protect themselves.
“With great connectivity comes great responsibility,” said Joshua Corman, founder of I Am The Cavalry, a nonprofit focused on helping critical infrastructure withstand hackers. Yet, even when it comes to critical services like water, he warns that “our dependence on connected technology is growing faster than our ability to secure it.”
Approximately 97 percent of water systems in the United States are small, run by local agencies that barely secure their infrastructures. As Joshua Corman aptly states, America’s water systems resemble an expensive heirloom bicycle left on a busy street, protected by a flimsy padlock. Cyber attackers are acutely aware of this vulnerability, often exploiting it to target local agencies.
The mechanics of this kind of cyberattack are alarming. Many times, hackers can access the computers operating local water systems—known as programmable logic controllers (PLCs)—simply by logging in via public-facing web pages. In fact, some systems even lack basic password protections, making unauthorized access relatively easy.
Understanding the attack’s cause sheds light on its potential consequences. When municipalities began connecting their old water and wastewater systems to the internet, security considerations were often an afterthought, especially as remote work became prevalent during the pandemic. “We have more cybersecurity regulations for your credit card than we have for the nation’s water supply,” Corman remarked.
Basic cybersecurity hygiene may not be enough. More than half of all credit card holders have been hacked even with mandatory firewalls and encryption. In contrast, the risks for water utilities could lead to catastrophic outcomes, such as unauthorized chemical usage or the complete cutting off of water supply.
Fortunately, last week’s attacks did not result in any fatalities, nor serious disruptions to essential services. Braham successfully restored its water supply within hours, providing reassurance to its 1,800 residents.
Addressing Vulnerabilities to Avoid Future Cyber-Attacks
The events underline that small cities like Braham need to enhance their cybersecurity frameworks to prevent future incidents. “Cyberattacks can be extraordinarily dangerous, but thankfully, none have directly cost lives in this country so far,” according to cybersecurity expert Kurt Gaudette. Enhancements in monitoring network activities are crucial, similar to the practices already adopted by many power utilities.
In some situations, disconnecting critical controls from the internet entirely may be the most effective approach. In Corman’s words, “if you can’t protect it, disconnect it.”
As the landscape of cybersecurity risk evolves, maintaining a proactive stance is essential for our water supply systems. The recent events serve as a wake-up call, highlighting the need for more robust infrastructure to safeguard our communities. For a deeper look into this pressing issue, you can find more information here.
Image Credit: www.vox.com







