Ex-NSA Chief Warns Water System Controllers Should Not Be Connected to Internet After Suspected Iran Cyberattacks

0
2

Key Takeaways

  • At least 12 U.S. water systems have been compromised, most likely by Iranian threat actors targeting programmable logic controllers (PLCs).
  • Retired General and former NSA Chief Paul Nakasone urged higher cybersecurity standards, stressing that PLCs should never be directly connected to the internet.
  • The FBI is investigating the incidents as malicious cyber activity against operational‑technology devices, but has not officially attributed the attacks to Iran.
  • Private‑sector researchers and Nakasone express strong confidence that Iran‑linked groups are responsible, citing a history of similar intrusions.
  • The nation’s 50,000 water municipalities present a vast, under‑funded attack surface, often lacking dedicated IT or cybersecurity staff.
  • Effective defense requires broad partnerships—academic, industry, and hacker communities—exemplified by initiatives like DEF CON Franklin and Vanderbilt’s Project Chimera.
  • Nakasone advocates a collaborative, multi‑layered approach to raise resilience across critical water infrastructure.

Overview of Recent Water System Cyberattacks
In recent months, at least twelve distinct water and wastewater facilities across the United States have experienced cyber intrusions. The incidents primarily involved unauthorized access to programmable logic controllers (PLCs), the devices that regulate pump operations, monitor tank levels, and manage other essential process controls. Although the attacks did not cause widespread service outages, they demonstrated the ability of threat actors to manipulate critical operational technology (OT) components, raising alarms about the vulnerability of the nation’s water supply chain.

Statements from General Paul Nakasone at DEF CON
Retired General and former NSA Director Paul Nakasone addressed the issue during a press briefing at the DEF CON hacker conference. He emphasized that the current state of cybersecurity for water systems falls short of necessary standards and called for urgent improvements. Nakasone specifically warned that PLCs should never be exposed to the public internet, noting that such connections create unnecessary risk and simplify the task for adversaries seeking to disrupt essential services.

FBI Investigation Findings
The Federal Bureau of Investigation confirmed that it is actively investigating the attacks, classifying them as malicious cyber activity aimed at operational‑technology devices. The bureau’s inquiry focuses on the tactics, techniques, and procedures used to compromise PLCs and related infrastructure. While the FBI has gathered substantial evidence pointing to a sophisticated actor, it has refrained from issuing an official attribution, citing the need for a measured and evidence‑based approach before publicly naming a suspect.

Attribution to Iran‑Linked Actors
Despite the FBI’s cautious stance, several experts have voiced strong suspicions that Iranian cyber groups are behind the incidents. Cynthia Kaiser, senior vice president of the Halcyon Ransomware Research Center, told The Register at DEF CON that she would be “shocked if it’s not Iran,” adding that the evidence “almost certainly” points to Tehran‑aligned actors. General Nakasone echoed this view, noting that the observed actor possesses both the capability and intent consistent with previous Iranian campaigns targeting water facilities’ PLCs.

Historical Context of Iranian Cyber Operations
Iran has a documented history of conducting cyber operations against critical infrastructure, including earlier attempts to manipulate water‑treatment PLCs in the United States and abroad. These past campaigns often involved reconnaissance, credential harvesting, and the deployment of custom malware designed to interact with industrial control systems. Nakasone pointed out that the pattern of behavior seen in the recent attacks aligns with those historical precedents, reinforcing the assessment that Iran‑linked crews are likely responsible.

Lack of Official Attribution from Authorities
Although private analysts and senior military leaders express confidence in the Iranian connection, neither the FBI nor the Trump administration has formally blamed Iran for the attacks. Nakasone suggested that the federal government is taking a “measured approach” to attribution, prioritizing thorough analysis and coordination with international partners before making public declarations. This cautious stance reflects the broader challenges of attributing cyber operations in a landscape where false‑flag tactics and shared tools can obscure true origins.

Challenges Posed by the Water Sector’s Attack Surface
The United States hosts roughly 50,000 separate water municipalities, supplying about 90 % of the nation’s drinking water. Many of these entities are small, under‑funded operations with limited IT staff and, in numerous cases, no dedicated cybersecurity personnel. Consequently, the sector presents an expansive and uneven attack surface, where defenders must protect a myriad of disparate systems ranging from legacy SCADA installations to modern IoT‑enabled sensors. Nakasone highlighted that defending such a fragmented environment requires rethinking traditional security models and embracing more inclusive, collaborative strategies.

Partnership‑Centric Defense Strategies
To address these challenges, Nakasone advocated for a defense posture built on extensive partnerships. He pointed to DEF CON Franklin—a volunteer‑driven project launched two years ago at the annual hacker conference—as a model whereby skilled hackers donate their time and expertise to help secure water facilities. By bridging the gap between the hacker community and critical‑infrastructure operators, such initiatives can uncover vulnerabilities, develop mitigations, and foster a culture of shared responsibility.

Academic and Industry Collaboration: Project Chimera
In addition to grassroots efforts, Nakasone serves as the founding director of Vanderbilt University’s Institute of National Security and its Wicked Problems Lab, where he is helping to steer Project Chimera. This endeavor brings together academics, cybersecurity practitioners, and open‑source technologists to create a resilient cybersecurity platform tailored for critical infrastructure. By leveraging open‑source tools, the project aims to lower cost barriers, enhance transparency, and enable rapid adaptation to emerging threats against water systems and similar sectors.

Conclusion: Raising Standards and Embracing Collaboration
General Nakasone’s overarching message is clear: the nation must elevate its cybersecurity standards for water infrastructure, enforce strict network segmentation (especially keeping PLCs off the public internet), and cultivate a unified defense ecosystem that includes government, private industry, academia, and the hacker community. Only through such a coordinated, multi‑layered approach can the United States hope to safeguard its vital water resources against increasingly sophisticated and persistent cyber threats.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here