Ex-NSA Chief Declares Water Controllers Have No Place on the Internet as Iranian Attacks Hit a Dozen States

Retired Gen. Paul Nakasone didn’t mince words at DEF CON this week. “We have to have higher standards,” the former NSA director said. “These PLCs should not be connected to the internet.”

His blunt assessment came as federal agencies confirm cyberattacks on water and wastewater systems have now reached at least a dozen states. The incidents, widely suspected to be the work of Iranian-linked actors, have forced utilities to issue boil-water notices, lose remote monitoring capabilities, and shift to fully manual operations. And the pace is accelerating.

According to The Record, utilities in states including Minnesota, Michigan, New Jersey, South Dakota and Georgia have reported intrusions since late July. In Minnesota alone, more than 30 municipal systems were hit in a single wave. Some facilities saw operators locked out after attackers changed IP addresses and passwords on programmable logic controllers. Others dealt with pressure drops, flooding risks and the potential for untreated groundwater to enter distribution pipes.

But here’s the uncomfortable truth. Many of these controllers were sitting exposed online, often protected by nothing more than factory-default passwords. Attackers didn’t need sophisticated malware. They didn’t need zero-days. They simply reached in and rewired the systems that pump, treat and distribute drinking water for millions of Americans.

Nakasone, now leading Vanderbilt University’s Institute of National Security, laid out the scale of the problem. “We’ve got 50,000 different water municipalities in the United States. Ninety percent of our water comes from these 50,000.” Defending that sprawling, often underfunded collection of local utilities demands a different mindset, he argued. “We have to think differently about how we defend it. You defend with a series of partners, in a much more involved approach than we have right now.”

Federal warnings had been sounding for months. In April, the Cybersecurity and Infrastructure Security Agency, FBI, NSA, EPA and other agencies issued a joint advisory detailing how Iranian-affiliated actors were exploiting internet-facing PLCs across critical infrastructure. The document, CISA advisory AA26-097A, highlighted targeting of Rockwell Automation Allen-Bradley controllers as well as devices from Schneider Electric and Siemens. Actors used foreign IP addresses on common industrial ports to pull project files, alter logic, and manipulate human-machine interfaces.

A follow-up alert in late July sharpened the focus on water systems. CISA Acting Director Nick Andersen stated the agency was “currently observing a significant increase in cyber threat actors targeting programmable logic controllers at water utilities.” He urged owners to “remove publicly exposed PLCs and other operational technology from the internet as soon as possible.”

The New York Times first reported U.S. investigators viewed the Minnesota attacks as likely Iranian handiwork. Three state officials, speaking anonymously, pointed to the specific tradecraft and the absence of any ransom demand. No water supply was rendered unsafe, local officials stressed, yet the operational headaches were real. One city’s well and treatment plant went temporarily offline. Others resorted to manual overrides.

These tactics echo earlier Iranian campaigns. In 2023, the group known as CyberAv3ngers — tied by the U.S. government to Iran’s Islamic Revolutionary Guard Corps — targeted Unitronics PLCs at water facilities, including one near Pittsburgh. Defacements and disruptions followed. The pattern has only grown more aggressive amid heightened U.S.-Iran tensions.

Cynthia Kaiser, senior vice president at the Halcyon Ransomware Research Center, was equally direct at DEF CON. “I’d be shocked if it’s not Iran. It’s almost certain it’s Iran.” Nakasone agreed the actors possess both capability and intent. “They certainly have the capability. There’s an intent … we’re in conflict with Iran.”

The attacks reveal more than just technical vulnerabilities. They expose a structural weakness in how the United States secures its most basic infrastructure. Water utilities often operate with limited budgets, small or nonexistent dedicated cybersecurity teams, and aging equipment that was never designed with internet connectivity in mind. Remote access features added for convenience during the pandemic were rarely removed. Segmentation between corporate networks and operational technology remained an afterthought in too many places.

Jake Braun, a former Chicago mayor’s office cybersecurity official, captured the strategic stakes. “They can shut off the water for our military, they can shut off the water for our economy, in particular our AI dominance, and they can undermine trust in our government to provide the most basic life-giving services. That’s really what’s at the core of this. I don’t think it has anything to do with any particular physical objective they were hoping to achieve with hacking these water systems.”

So what does effective defense actually look like? Nakasone and federal agencies agree on core steps. Pull PLCs off the public internet. Deploy firewalls and secure gateways. Use unique, strong credentials. Enable multi-factor authentication where possible. Monitor for anomalous changes to control logic. Validate project files before loading them. Keep mode switches in the “run” position rather than remote programming mode.

Yet implementation lags. Shodan scans still reveal thousands of industrial control devices reachable from anywhere. Many run outdated firmware with known vulnerabilities. Even when patches exist, applying them to live systems that cannot tolerate downtime presents its own risks.

The FBI has been unusually vocal. In a public service announcement, the bureau described how malicious actors gained remote access to internet-facing Rockwell MicroLogix 1100 and 1400 series controllers. After altering configurations, they left operators blind. Some facilities reported sustained manual operations for days. Boil-water notices followed in at least one Georgia county before testing cleared the supply.

This isn’t theoretical. It’s happening now. And the campaign shows no signs of slowing. As more states come forward with previously unreported incidents, the true scope may grow further. WaterISAC and other sector-specific information sharing organizations have pushed updated threat intelligence to members, but adoption varies widely between large metropolitan utilities and small rural systems.

Nakasone’s call for higher standards and deeper partnerships feels both obvious and overdue. The DEF CON Franklin project, which enlists volunteer hackers to help secure water facilities, represents one model of that collaboration. Yet scaling such efforts across 50,000 disparate entities requires sustained federal funding, clearer regulatory expectations, and perhaps liability protections that encourage information sharing without fear of lawsuits.

Meanwhile, the geopolitical backdrop adds urgency. Direct U.S. military action against Iranian targets has resumed in the Middle East. Tehran has shown willingness to respond in cyberspace. Disrupting American water systems offers a low-cost, deniable way to impose costs and sow doubt without crossing into kinetic retaliation that risks wider war.

Industry insiders have warned for years that operational technology security cannot remain an afterthought. The current wave of attacks proves the point with painful clarity. Controllers that manage chemical dosing, pump speeds, tank levels and valve positions were never meant to face the open internet. Exposing them created an attack surface that adversaries are now happily exploiting.

Removing that exposure won’t solve every problem. Determined nation-state actors can still find ways in through supply chain compromises, insider threats or phishing campaigns aimed at engineers. But it would close the widest, most embarrassing door currently standing open. As Nakasone put it, we have to do better. The water we drink depends on it.


Discover more from Web and IT News

Subscribe to get the latest posts sent to your email.

1 thought on “Ex-NSA Chief Declares Water Controllers Have No Place on the Internet as Iranian Attacks Hit a Dozen States”

  1. Pingback: Ex-NSA Chief Declares Water Controllers Have No Place On The Internet As Iranian Attacks Hit A Dozen States - AWNews

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top

Discover more from Web and IT News

Subscribe now to keep reading and get access to the full archive.

Continue reading