
In the teensy Midwestern town of Braham, homemade pie capital of Minnesota, something unusual in the municipality’s computer systems knocked the city’s entire water supply offline last week.
Within a few hours, dozens of other Minnesota cities discovered that their water and wastewater utilities, too, had been compromised, most likely as part of a massive Iranian cyberattack, the kind that US officials have been warning about since the war began.
At least a dozen states have been affected by the attack, which briefly led to a flurry of small-town service disruptions, boil-water notices, and local flooding. Water wells, dams, sewers, and pipelines are some of America’s oldest and creakiest pieces of infrastructure, built long before the internet existed, and certainly long before AI made hacking much easier. While you may assume most hackers are in it for the money or for data, some have targeted critical infrastructure like water systems or energy grids in ploys for control or disruption — or worse still, as acts of war.
And, as last week’s attacks show, the nation’s water system is woefully unprepared. But how worried should you be that the very infrastructure that keeps our water taps running is, apparently, hackable?
Quite worried, indeed.
When we say the water supply got hacked, what we really mean is that someone, somewhere has broken into the computer that controls a local water treatment plant or reservoir, and is now pulling the levers, like the one that decides how much of a corrosive chemical can safely go into cleaning the water that comes out of your tap.
These levers were once manual buttons and knobs operated in-person by real live humans, meaning that — barring a natural disaster, bomb, or break-in — protecting them was about as simple as building a fence and hiring guards. Increasingly, however, these levers have gone digital, meaning that they are now remotely operable from anywhere in the world.
Those upgrades have been convenient, allowing technicians to monitor and troubleshoot problems in real time. But, in the process, they have exposed at times centuries-old infrastructure to distinctly modern vulnerabilities. Most local water systems are operated by local authorities, don’t have a dedicated IT team, and lack the money or resources to thoroughly protect themselves without some extra help. Hackers know this, which is why they’ve increasingly targeted local agencies in such attacks.

“With great connectivity comes great responsibility,” said Joshua Corman, founder of I Am The Cavalry, a nonprofit focused on helping critical infrastructure withstand hackers. And yet, even when it comes to critical services like water, “our dependence on connected technology is growing faster than our ability to secure it.”
About 97 percent of water systems are small, run by local agencies that often barely lock the proverbial front door. America’s water system is like an expensive heirloom bicycle that’s been left on a busy street, protected by only the flimsiest of padlocks. And that very vulnerability has made tiny towns like Braham prime targets for faraway adversaries. Accessing the computers that operate most water systems — known as programmable logic controllers or PLCs — is often as simple as entering a username and password on a public-facing webpage. Sometimes, there is no real password at all, because PLCs were initially intended to be accessed only within locked, secure facilities, not on the open internet. If the US wants to avoid a far more severe version of what happened last week, then it will need to start taking the security of tiny water systems like Braham’s seriously.
“Any sociopath from anywhere in the world can see these things on the internet,” said Corman. And in the case of last week’s attacks, “these were devices with no password, no firewall or VPN shielding them — they just had to log in” as whoever the intended operator was, and just like that, they were inside a local water plant.
How did this happen at all?
When municipalities began hooking up their old water and wastewater systems to the internet — a trend that accelerated during the pandemic as water operators, like everyone else, adapted to remote work — cybersecurity was rarely front of mind, neither for individual utilities nor for regulators as a whole.

“We have more cybersecurity regulations for your credit card than we have for the nation’s water supply,” said Corman. Only recently have some municipalities begun to take steps to decrease the exposure of their water plants to hacks. In March, New York state, for example, launched a set of grants and basic cybersecurity regulations mandating security training for all water operators.
Basic cybersecurity hygiene isn’t always enough. More than half of all credit card holders have been hacked, even with the help of mandatory firewalls and data encryption. You can imagine how vulnerable our water must be without the assistance of such guardrails. In a worst-case scenario, a malicious actor could quite literally open the floodgates, as Russian hackers did to a Norwegian dam last year. They could poison the tap water, as a still unidentified hacker almost did in Florida in 2021, dialing up the levels of sodium hydroxide used at a water treatment plant by over 100 times its normal levels. In a severe scenario, they could indefinitely cut off access to all water entirely.
The good news is, none of this happened last week. Nobody died, nobody lost water for more than a few hours, no fire hydrants ran dry, and no hospitals were forced to cut off their dialysis machines (which can use more than a hundred gallons of water per treatment session). There’s no need to panic, and your drinking water is almost certainly still safe to drink, assuming it was safe before. Even the city of Braham, within a few hours, was able to bring its water tower back online, pumping groundwater back to its 1,800 residents.
How do we avoid cyber-armageddon?
If you’ve watched the Julia Roberts and Mahershala Ali-starring thriller Leave the World Behind, in which a cyberattack apocalyptically spoils a family vacation, then you might have some idea of where this story could go.
Cyberattacks on critical infrastructure can be extraordinarily dangerous, but thankfully, none have directly cost lives or severely disrupted services in this country so far. If the US wants to keep it that way, that will mean doing more to help small cities like Braham adapt and better monitor for potential threats. As it stands, of the roughly 151,000 water facilities in the US, only about 420 participate in voluntary information sharing on their own cybersecurity practices, says Corman, who has been leading his own project that recruits volunteers to give free cybersecurity support to water utilities in the nation’s roughly 6,000 hospital towns, where a disruption could be particularly deadly.
Cybersecurity experts like Corman believe that hackers from other nations like China have already quietly established cyber intrusions in countless local US utilities, water systems, and power grids, lying in wait to attack or act as leverage if a conflict arises.
Unfortunately, the Trump administration has hardly treated last week’s attacks as symptoms of a system in need of much broader strengthening, at least in its public statements. “I think Minnesota is behind it. You know who’s behind it? Minnesota,” the president baselessly claimed during a Cabinet meeting last Friday. “I think the governor is behind it. I don’t think there was an Iranian cyber attack.”

Just a few months ago, he proposed $707 million in cuts to the US Cybersecurity and Infrastructure Security Agency (CISA), the agency responsible for protecting the nation’s infrastructure from cyberattacks. He did so, at least in part, out of anger over the agency’s role in confirming the validity of the 2020 election results. If Iran is, indeed, responsible, for the recent water system intrusions, all of this means that Trump has effectively made us more vulnerable to the consequences of a conflict he initiated.
At the end of the day,“nation-state hackers do not respect the jurisdictional lines separating federal, state, and local responsibility,” Jen Easterly, who led CISA under the Biden administration, wrote in the New York Times this week. “They search for the most vulnerable way to disrupt American life, and too often they find it in small communities that lack the resources to defend themselves.” Easterly’s role has remained vacant for the past 18 months.
Kurt Gaudette, a senior vice president at the cybersecurity firm Dragos, told me that water systems have got to get into the habit of monitoring their networks for suspicious activity. Most power utilities have begun doing so in recent years, with some bipartisan backing from Congress.
In some cases, however, the most cost-effective and safest way to avoid a repeat of last week’s mess might be to unplug the most vital controls — like the one that decides the chemical levels in a water treatment plant — from the web entirely.
As Corman puts it, “if you can’t protect it, disconnect it.”
Source: Vox.

Leave a Reply