Ex-NSA Chief Urges Air-Gapping of US Water Systems After Multi-State Cyberattacks
Following suspected Iranian-backed attacks across 12 states, security experts warn that critical water controllers must be disconnected from the public internet.
Cyberattacks targeting water infrastructure across at least 12 US states have prompted an urgent warning from a former NSA chief regarding the vulnerability of critical utility controllers. The incidents highlight a systemic security failure in how the US manages its water distribution and treatment systems.
Federal investigators suspect the attacks are linked to hackers backed by Iran, noting that the tactics closely resemble a 2023 campaign conducted by CyberAv3ngers, a group tied to Iran's Islamic Revolutionary Guard Corps (IRGC). The attackers specifically targeted water-system controllers exposed to the public internet. In many cases, these systems remained vulnerable due to the use of weak or default passwords, allowing remote actors to gain unauthorized access with minimal effort.
The Legacy Connectivity Gap
These attacks occur amid heightened geopolitical tensions involving the US, Israel, and Iran. This is not the first time Iranian-linked groups have targeted Industrial Control Systems (ICS) and Programmable Logic Controllers (PLCs). Historically, these campaigns have been used to demonstrate technical capability and create disruption within critical infrastructure.
The current wave of attacks underscores a persistent issue: many legacy industrial systems were originally designed for isolated operation and were never intended to be connected to the global web. However, they were integrated for convenience or remote management without adequate security layers, leaving them open to exploitation by state-sponsored actors.
The Case for Air-Gapping
Because water infrastructure is a critical vulnerability, the ability for remote actors to manipulate treatment processes or distribution schedules could lead to severe public health crises or permanent physical damage to equipment. In response, a former NSA chief has warned that water system controllers simply do not belong on the internet.
This approach, known as "air-gapping," involves physically isolating a secure network from any external connection to the public internet. By removing the primary attack vector used by remote hackers, agencies can ensure that the controllers managing chemical levels and water flow are unreachable from outside the facility.
Strengthening National Defenses
Water agencies have been advised to immediately disconnect operating programs from the internet and implement more rigorous security protocols to prevent further intrusions. As federal investigators continue to trace the origin of these breaches, the focus has shifted toward a fundamental redesign of utility security.
The industry must now determine how to balance the need for modern monitoring with the absolute necessity of isolating the controllers that keep drinking water safe. Without a shift toward physical isolation, the risk of a catastrophic failure in the nation's water supply remains an open door for foreign adversaries.