Crime & Law
UChicago Cybersecurity Expert on Water System Hacks, Critical Infrastructure Concerns
What appeared to be innocent malfunctions in municipal water systems could actually be something more serious.
At the end of July, several water systems from Minnesota to Georgia suddenly went offline.
While officials restored them, cybersecurity experts now say the outages may have been caused by Iranian hackers, raising larger questions about the security of America’s critical resources.
Jacob Braun, executive director of the Cyber Policy Initiative at the University of Chicago and former acting principal cyber director under the Biden administration, joined “Chicago Tonight” to break down how hackers were able to access the country’s water infrastructure.
WTTW News: What happened when these cities first realized something was wrong with their water systems?
Jacob Braun: The cyber attack attacked a PLC (Programmable Logic Controller), which is a device that helps control the IT system and its commands to the physical system — so the actual pumps and so on that make the water utility work. As you suggested, the assumption is that the Iranians were behind the attack. And we think this attack is not really about a specific water utility. It’s really trying to send a message to the administration and the American people about where we’re vulnerable. I think that what they’re trying to do is really show the administration that they can shut off the water to our military assets. They can shut off the water to what may be the key economic driver in the country right now, which is our AI data centers. Finally, in a country that’s deeply divided over the war already, they’re showing they can undermine public trust in the government’s ability to perform the most basic lifegiving services like making sure the water turns on.
How did officials realize they were dealing with a cyberattack?
Braun: This particular device, this PLC device, is pretty ubiquitous throughout the water utilities in America. Once they saw this start popping up here and there — and now it looks like we’re up to over a dozen states — that doesn’t happen by just some random device randomly breaking. It happens because of a coordinated cyberattack.
How are hackers gaining access to our water systems?
Braun: Well, they worm their way through the internet. Unfortunately, most of the utilities that were successfully hit were the smaller utilities that don’t have budgets to hire big cyber companies or cyber professionals and make sure they have all the newest cyber defenses in place. So those were the low-hanging fruit that presumably the Iranian hackers were able to attack.
Are these attacks common? Have other countries experienced similar incidents?
Braun: There was a report today of a cyberattack against a U.K. water plant. The reason that I ended up getting involved in this issue when I was at the White House was when the Chinese were pre-positioning malware on our water utilities that support military assets around the country, presumably to let the U.S. military know that if there is a conflict, assuming over Taiwan, that they could shut off the water to a bunch of key military assets. Unfortunately, nearly all of the military assets in the country are supported by civilian water utilities.
Could there be similar implications or concerns for other utilities?
Braun: The Iranians have been quite active in hitting other critical infrastructure. For example, years ago when we launched a cyberattack against their nuclear program and it came to light, they did a massive attack against our banking system and shut off online banking for weeks and weeks. By the way, we were never able to stop it. They just kind of got bored with it after a few weeks and stopped doing it on their own. We also know they’ve been involved in our elections. Not, to our knowledge, with actual hacking per se, but with misinformation and disinformation, which is always coupled with different types of cyberattacks. And then of course we’ve seen the Russians and the Chinese act in similar ways.