Posted on 08/05/2026 12:40:27 PM PDT by E. Pluribus Unum
Federal and state officials are racing to address an assault on the nation’s water supply that they believe is the work of Iranian hackers.
In 2023, the Environmental Protection Agency under the Biden administration proposed creating stronger cybersecurity guidelines to better safeguard the nation’s water supply from hackers.
The steps were modest, but necessary, officials said at the time: Many municipalities lacked even basic protections, and the computers that monitor and adjust water quality, including chemical-treatment levels, were easy-to-find targets for a would-be intruder.
The E.P.A. rescinded the order, however, after Republican-led states and industry groups sued to block its enforcement. They argued that the E.P.A. lacked authority for the move and that smaller, underfunded utilities would struggle to adopt the new standards.
The episode is just one of several in recent years in which efforts to bolster the cyberdefenses of America’s water systems were blocked despite repeated attacks that highlighted vulnerabilities. Just a little more than a month after the E.P.A. proposal was killed, a small town in western Pennsylvania disclosed that a hacking group tied to Iran’s Islamic Revolutionary Guards Corps briefly took control of equipment used to adjust water pressure.
Now federal and state officials are racing to address an alarming, widespread assault on the nation’s water supply that they believe is also probably the work of Iranian hackers.
Last week, at least seven states, including Minnesota and Michigan, reported incidents to the F.B.I., and in some cases the hacks — or the response to them — degraded water operations. The tally of states reporting possible attacks to the F.B.I. is now at least a dozen, according to people familiar with the investigation. The F.B.I. has not disclosed the states publicly,...
(Excerpt) Read more at nytimes.com ...
Dear FRiends,
We need your continuing support to keep FR funded. Your donations are our sole source of funding. No sugar daddies, no advertisers, no paid memberships, no commercial sales, no gimmicks, no tax subsidies. No spam, no pop-ups, no ad trackers.
If you enjoy using FR and agree it's a worthwhile endeavor, please consider making a contribution today:
Click here: to donate by Credit Card
Or here: to donate by PayPal
Or by mail to: Free Republic, LLC - PO Box 9771 - Fresno, CA 93794
Thank you very much and God bless you,
Jim
I watched an hour-long presentation on the collapse of empires. In their heyday their currency is strong, and they have massive public projects. As they age, they debase the currency. They can no longer afford to maintain the projects they already have. Also, they develop substantial complexity. Initially, adding complexity, like processes, procedures, and laws enhance the entire economy. But in an effort to maximize things, they go overboard with complexity. An example was the number of compliance requirements in 1950 for things like dams and powerplants. Compared with today, just the environmental regs can run into hundreds of thousands of pages, up about 1,000 percent. I’m afraid we’re on the wrong side of the decline curve.
Oh, did I mention 31 trillion in debt and a debased currency?
The age old question: Why are utility controls connected to public networks?
In 1995, I ran a small program on critical infrastructure security for electric utilities. THIRTY YEARS ago. A lot of our efforts were focused on keeping the power on with the upcoming Y2K, but much effort was focused on protecting SCADA systems and open modems at substations. I left the industry a few years later and I’m constantly reading and re-reading and re-re-reading the same old recycled stories about cyber threats to critical infrastructure.
A. As an inexpensive way to communicate telemetry.
Back in the day, there were expensive EDI systems, but when internet access began to proliferate, a lot of utility information switched to the internet as a cheap way to move the data.
I will defer to anyone with current expertise; mine is from the early 1990’s in the Electric, Gas, and Water Utility industry, where I conducted research while working my way through law school. But my sense of it from back then was that it was the embedded systems, typically in electric transmission networks, that were almost completely unsecure.
These are long-lived assets; they get installed, and they may spend 20-30 years out there before they get replaced. If they have a flaw or a vulnerability when they are installed, it’s there until someone climbs the pole and replaces the hardware, out in the middle of nowhere. In a transmission system, it’s a huge logistical and financial problem.
It’s truly crazy. They have spent BILLIONS and BILLIONS of dollars on the NSA but they can’t keep our infrastructure safe. The only thing they can seem to do is crack down on racism, anti-semitism and mis and disinformation online.
They have spent 20 Trillion dollars on defense in the past 30 years yet we can’t even beat the toughest 3rd world / weakest 1st world country (depending on how you rank it).
This is a disgrace.
Now, telemetry is one thing, control is another.
I do remote telemetry and control via Internet and Cellular all the time. None of my systems use web-based or publicly available protocols; and, none have been hacked. One technique that works well is a point-to-point callback to only predetermined IP or phone addresses. If I signal a site to connect, it originates a connection back to a prearranged address. It never processes an incoming connection or calls on an arbitrary connection.
If we had people like Throckmorton P. Gildersleeve as water utilities executives, things would be better.
Same.
Most of these SCADA systems were installed by integrators who were the low bidder and did what they were required to do by contract. I’d bet at least 8 out of 10 municipalities lack the knowledge of cybersecurity to write a proper spec and the people who sign their paychecks (i.e. city councils) don’t know the difference and won’t spend the money to hire experts that can inform them. Everyone wants these systems to be accessible from the internet because that allows them to save money vs. having to send someone out to remote sites with a laptop and serial cable.
The only surprising thing is that we’re not seeing more such attacks every day.
And STILL nothing is done about it.
I warned about this a decade ago.
A lot of this is about defensive measures, and they certainly are needed. With respect to Iran, I’d like to see US Cyber Command go on the offensive and melt them down.
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.