https://www.newsweek.com/us-water-systems-could-face-catastrophic-cyberattacks-what-could-happen-12295975 US Water Systems Could Face ‘Catastrophic’ Cyberattacks: What Could Happen
By Joe Edwards
Cyberattacks on U.S. water systems could go much further than temporarily blinding operators, proving catastrophic for public health and finances.
Experts say a serious undetected breach could disrupt pumps, valves, pressure levels and treatment systems, potentially leaving residents with unsafe water, broken pipes, boil-water notices or outages.
The warning comes after cyberattacks on water systems were reported in at least 12 states, including Michigan, Minnesota, Georgia, New Jersey and South Dakota, according to CBS News.
In Georgia, the Clayton County Water Authority said cyber activity caused a drop in water pressure and prompted a boil-water advisory, although service was restored within hours.
Some utilities lost remote-control capabilities and had to shift to manual operations, while officials have said drinking water has so far remained safe, it reported.
But experts told Newsweek that the consequences could be much more severe if an attack went undetected, lasted longer or reached more critical equipment.
Why Hackers Target Water
Water systems may be attractive targets because many use older equipment, have limited cybersecurity staffing and rely on internet-connected systems for remote monitoring. Dan Hartnett, interim CEO of the Association of Metropolitan Water Agencies, said attackers may not always be specifically looking for water utilities, but may instead scan for any vulnerable internet-connected device.
Still, Hartnett said water systems themselves could appeal to attackers because of their potential to disrupt public health and economic activity and undermine public confidence in the water supply.
Ahmad Taha, an associate professor in civil and environmental engineering at Vanderbilt University put the risk more starkly: “[The] impact of cyberattacks can be catastrophic, with very little effort."
The threat level prompted the FBI to issue a public service announcement on July 30, urging water companies to increase their security measures after receiving reports of incidents from the water and wastewater sector in at least seven states.
It said, "malicious cyber actors (MCAs) are conducting cyberattacks targeting Operational Technology (OT) devices," before naming specific technology systems that were at risk.
A Local Attack Could Cost Millions
The financial cost of an attack would depend on its scale, duration and location. Taha said a single pipe break that takes time to identify and months to fix could cost a city millions of dollars. William Akoto, an assistant professor of foreign policy and global security at American University in Washington, D.C., said even a localized incident could require overtime, cybersecurity specialists, equipment reprogramming or replacement, water-quality testing, public communications and extended manual staffing.
A regional incident, Akoto said, could reach millions once emergency water distribution, business interruption, infrastructure damage and recovery across multiple utilities are included.
What Residents Might Experience
For residents, the first signs of trouble could be low water pressure, interrupted service or a boil-water notice. Akoto said utilities would typically respond by isolating compromised equipment and switching to manual operations. If water pressure falls, untreated groundwater could potentially enter pipes, prompting officials to issue a precautionary boil-water notice and conduct testing before lifting it.
A prolonged incident could require bottled-water distribution, water tankers or priority deliveries to hospitals and other essential facilities, he said. But if operators contain the intrusion quickly and maintain manual control, "residents may experience little or no visible disruption."
Hartnett said a compromised system could leave operators unable to monitor pressure levels or chemical feeds. If undetected, that could lead to a loss of pressure that damages infrastructure or an incorrect application of treatment chemicals.
"Typically, before it gets to this point, an operator will identify a discrepancy in the system and be able to convert to manual mode to address the problem," Hartnett said.
How Hackers Could Disrupt Water Systems
Taha said there is no single type of cyberattack on a water system. Some attacks may lock operators out of command-and-control systems through stolen passwords, VPN access or phishing. Others, he said, could interfere with physical assets such as pumps, valves, chlorination stations and treatment facilities.
"When reaching access to assets (valves, pumps, etc.)," Taha said, cyberattacks "can lead to the wrong operational decisions in the water distribution network."
He gave the example of a compromised sensor measuring the volume or height of water in a large tank, which could cause the tank to overflow. An attack on pumping stations could weaken pressure across a city, potentially affecting households and fire hydrants. Another attack could increase pressure in underground pipes, causing breaks, leaks and service interruptions.
"Leaks are also extremely difficult to detect and isolate, as pipes are buried underground, so the problem becomes super hard to isolate and solve," Taha said.
Treatment systems are another concern. Taha said an attack on a chlorination station could result in either too little or too much chlorine entering the water network. "Both are dangerous for public health," he said.
Akoto said a successful attack could prevent operators from seeing or controlling equipment, or allow attackers to issue unauthorized commands.
Depending on the compromised controller, Akoto said, attackers could stop or start pumps, change valve positions, disrupt pressure, overflow tanks, interfere with treatment settings or falsify readings and alarms. But he added an important caveat: "Gaining access does not automatically give an attacker the knowledge or control needed to contaminate drinking water."