AUTO-UPDATED

Weak Passwords Just Exposed Our Water Supply to Iranian Hackers

Coordinated cyberattacks targeting programmable logic controllers have disrupted water systems across at least a dozen U.S. states, exposing critical vulnerabilities in aging infrastructure and weak security protocols.

Key Points

  • Attacks began on July 26, affecting over 30 water systems in Minnesota before spreading to at least 12 states.
  • Malicious actors, likely linked to Iran, gained control by exploiting internet-connected devices using default or weak passwords.
  • The breaches targeted programmable logic controllers (PLCs), which serve as the central nervous system for industrial control systems.
  • The Cybersecurity and Infrastructure Security Agency (CISA) had previously issued multiple warnings regarding these specific vulnerabilities.
  • Many public water systems struggle to implement security updates due to limited IT staffing and constrained municipal budgets.

Why it Matters

These incidents highlight the severe risks posed by connecting legacy industrial equipment to the public internet without adequate authentication. The inability to secure this critical infrastructure threatens public health and underscores the urgent need for federal funding and modernized cybersecurity standards.
CNET Published by Joe Supan
Read original