Tue, Aug 4

NEWS: Here’s what the cyber threats to US water systems mean for power pros.

  • What happened: Over 12 states have reported potential cyberattacks on water and wastewater utilities, ABC News reported. So far, Michigan, South Dakota, and Minnesota have publicly confirmed incidents (and Wisconsin has raised alarms). But no communities have seen major disruptions.

  • More details: Hackers are remotely tampering with programmable logic controllers (PLCs), the FBI noted…the same tech that 50-80% of US grid control endpoints depend on. In April, federal officials warned of this specific threat to US water and energy systems.

  • Who’s responsible? The FBI hasn’t named any names…but federal agencies recently warned that Iranian hackers had their eyes on US water systems. Previously, Iran-affiliated hackers have allegedly targeted PLCs used in US and Israeli water systems.

  • What it means for electric utilities: As we add more internet-accessible tech to the grid, from PLCs to inverters, the risk (and stakes) of cyber attacks will continue to grow. “A coordinated and simultaneous attack against them could have a pretty significant effect on [power] supply,” Energy Central member Richard "Dick" Brooks, a software engineer and cybersecurity expert, told us.   

  • Brooks’s advice for power pros: 1) Follow zero-trust cybersecurity principles (get more info from CISA here) and 2) ensure you’re getting early warnings of vulnerabilities from equipment producers. “With AI, it’s very easy for these exploits to be exercised within minutes,” Brooks said. “It’s vitally important that these critical infrastructure operators get early-warning notices, so they can take mitigating action to prevent a disaster.”

1
1 reply