Please ensure Javascript is enabled for purposes of website accessibility
States and Congress Wrestle With Cybersecurity After Iran Attacks Small Town Water Utilities
gvw_ap_news
By Associated Press
Published 1 year ago on
January 2, 2024

Share

Getting your Trinity Audio player ready...

HARRISBURG, Pa. — The tiny Aliquippa water authority in western Pennsylvania was perhaps the least-suspecting victim of an international cyberattack.

It had never had outside help in protecting its systems from a cyberattack, either at its existing plant that dates to the 1930s or the new $18.5 million one it is building.

Then it — along with several other water utilities — was struck by what federal authorities say are Iranian-backed hackers targeting a piece of equipment specifically because it was Israeli-made.

The Impact of the Cyberattack

“If you told me to list 10 things that would go wrong with our water authority, this would not be on the list,” said Matthew Mottes, the chairman of the authority that handles water and wastewater for about 22,000 people in the woodsy exurbs around a one-time steel town outside Pittsburgh.

The hacking of the Municipal Water Authority of Aliquippa is prompting new warnings from U.S. security officials at a time when states and the federal government are wrestling with how to harden water utilities against cyberattacks.

The danger, officials say, is hackers gaining control of automated equipment to shut down pumps that supply drinking water or contaminate drinking water by reprogramming automated chemical treatments. Besides Iran, other potentially hostile geopolitical rivals, including China, are viewed by U.S. officials as a threat.

State Responses to Cybersecurity Threats

A number of states have sought to step up scrutiny, although water authority advocates say the money and the expertise are what is really lacking for a sector of more than 50,000 water utilities, most of which are local authorities that, like Aliquippa’s, serve corners of the country where residents are of modest means and cybersecurity professionals are scarce.

Besides, utilities say, it’s difficult to invest in cybersecurity when upkeep of pipes and other water infrastructure is already underfunded, and some cybersecurity measures have been pushed by private water companies, sparking pushback from public authorities that it is being used as a back door to privatization.

Efforts took on new urgency in 2021 when the federal government’s leading cybersecurity agency reported five attacks on water authorities over two years, four of them ransomware and a fifth by a former employee.

At the Aliquippa authority, Iranian hackers shut down a remotely controlled device that monitors and regulates water pressure at a pumping station. Customers weren’t affected because crews alerted by an alarm quickly switched to manual operation — but not every water authority has a built-in manual backup system.

Legislative Actions and Controversies

With inaction in Congress, a handful of states passed legislation to step up scrutiny of cybersecurity, including New Jersey and Tennessee. Before 2021, Indiana and Missouri had passed similar laws. A 2021 California law commissioned state security agencies to develop outreach and funding plans to improve cybersecurity in the agriculture and water sectors.

Legislation died in several states, including Pennsylvania and Maryland, where public water authorities fought bills backed by private water companies.

Private water companies say the bills would force their public counterparts to abide by the stricter regulatory standards that private companies face from utility commissions and, as a result, boost public confidence in the safety of tap water.

“It’s protecting the nation’s tap water,” said Jennifer Kocher, a spokesperson for the National Association of Water Companies. “It is the most economical choice for most families, but it also has a lack of confidence from a lot of people who think they can drink it and every time there’s one of these issues it undercuts the confidence in water and it undercuts people’s willingness and trust in drinking it.”

Opponents said the legislation is designed to foist burdensome costs onto public authorities and encourage their boards and ratepayers to sell out to private companies that can persuade state utility commissions to raise rates to cover the costs.

“This is a privatization bill,” Justin Fiore of the Maryland Municipal League told Maryland lawmakers during a hearing last spring. “They’re seeking to take public water companies, privatize them by expanding the burden, cutting out public funding.”

The Struggle for Cybersecurity Funding

For many authorities, the demands of cybersecurity tend to fade into the background of more pressing needs for residents wary of rate increases: aging pipes and increasing costs to comply with clean water regulations.

One critic, Pennsylvania state Sen. Katie Muth, a Democrat from suburban Philadelphia’s Montgomery County, criticized a GOP-penned bill for lacking funding.

“People are drinking water that is below standards, but selling out to corporations who are going to raise rates on families across our state who cannot afford it is not a solution,” Muth told colleagues during floor debate on a 2022 bill.

Pennsylvania state Rep. Rob Matzie, a Democrat whose district includes the Aliquippa water authority, is working on legislation to create a funding stream to help water and electric utilities pay for cybersecurity upgrades after he looked for an existing funding source and found none.

“The Aliquippa water and sewer authority? They don’t have the money,” Matzie said in an interview.

Attempts at Federal Regulation

In March, the U.S. Environmental Protection Agency proposed a new rule to require states to audit the cybersecurity of water systems.

It was short-lived.

Three states — Arkansas, Missouri and Iowa — sued, accusing the agency of overstepping its authority and a federal appeals court promptly suspended the rule. The EPA withdrew the rule in October, although a deputy national security adviser, Anne Neuberger, told The Associated Press that it could have “identified vulnerabilities that were targeted in recent weeks.”

Two groups that represent public water authorities, the American Water Works Association and the National Rural Water Association, opposed the EPA rule and now are backing bills in Congress to address the issue in different ways.

One bill would roll out a tiered approach to regulation: more requirements for bigger or more complex water utilities. The other is an amendment to Farm Bill legislation to send federal employees called “circuit riders” into the field to help smaller and rural water systems detect cybersecurity weaknesses and address them.

The Future of Cybersecurity in Water Utilities

If Congress does nothing, 6-year-old Safe Drinking Water Act standards will still be in place — a largely voluntary regime that both the EPA and cybersecurity analysts say has yielded minimal progress.

Meanwhile, states are in the midst of applying for grants from a $1 billion federal cybersecurity program, money from the 2021 federal infrastructure law.

But water utilities will have to compete for the money with other utilities, hospitals, police departments, courts, schools, local governments and others.

Robert M. Lee, CEO of Dragos Inc., which specializes in cybersecurity for industrial-control systems, said the Aliquippa water authority’s story — that it had no cybersecurity help — is common.

“That story is tens of thousands of utilities across the country,” Lee said.

Because of that, Dragos has begun offering free access to its online support and software that helps detect vulnerabilities and threats for water and electric utilities that draw under $100 million in revenue.

After Russia attacked Ukraine in 2022, Dragos tested the idea by rolling out software, hardware and installation at a cost of a couple million bucks for 30 utilities.

“It was amazing, the feedback,” Lee said. “You wonder, ‘Hey I think I can move the needle in this way’ … and those 30 were like, ‘Holy crap, no one’s ever paid attention to us. No one’s ever tried to get us help.'”

 

RELATED TOPICS:

DON'T MISS

Senate Confirms Gabbard as Trump’s Director of National Intelligence

DON'T MISS

President Trump and Putin Have Agreed to Start Negotiations to End the Ukraine War

DON'T MISS

Google Calendar Users No Longer See Default Entries for Events Like Pride, Black History Month

DON'T MISS

Apple Changes Gulf of Mexico to Gulf of America on Maps

DON'T MISS

Kevin Durant Becomes 8th in NBA History to Score 30,000 Points

DON'T MISS

Too Few Tents Entering Gaza Threatens the Truce. Here’s What’s Happening

DON'T MISS

California’s FAIR Plan Needs $1B for Wildfire Claims, Costs Passed to Policyholders

DON'T MISS

Valley Crime Stoppers’ Most Wanted Person of the Day: Erik Michael Alexander Gropp

DON'T MISS

Baseball Is Back as Pitchers and Catchers Start Spring Training

DON'T MISS

Could Obesity Drugs Help With Alcohol Cravings? New Study Suggests Potentia

UP NEXT

President Trump and Putin Have Agreed to Start Negotiations to End the Ukraine War

UP NEXT

Google Calendar Users No Longer See Default Entries for Events Like Pride, Black History Month

UP NEXT

Apple Changes Gulf of Mexico to Gulf of America on Maps

UP NEXT

Kevin Durant Becomes 8th in NBA History to Score 30,000 Points

UP NEXT

Too Few Tents Entering Gaza Threatens the Truce. Here’s What’s Happening

UP NEXT

California’s FAIR Plan Needs $1B for Wildfire Claims, Costs Passed to Policyholders

UP NEXT

Valley Crime Stoppers’ Most Wanted Person of the Day: Erik Michael Alexander Gropp

UP NEXT

Baseball Is Back as Pitchers and Catchers Start Spring Training

UP NEXT

Could Obesity Drugs Help With Alcohol Cravings? New Study Suggests Potentia

UP NEXT

Monty the Giant Schnauzer Wins Westminster Dog Show

Apple Changes Gulf of Mexico to Gulf of America on Maps

2 hours ago

Kevin Durant Becomes 8th in NBA History to Score 30,000 Points

2 hours ago

Too Few Tents Entering Gaza Threatens the Truce. Here’s What’s Happening

2 hours ago

California’s FAIR Plan Needs $1B for Wildfire Claims, Costs Passed to Policyholders

2 hours ago

Valley Crime Stoppers’ Most Wanted Person of the Day: Erik Michael Alexander Gropp

2 hours ago

Baseball Is Back as Pitchers and Catchers Start Spring Training

2 hours ago

Could Obesity Drugs Help With Alcohol Cravings? New Study Suggests Potentia

2 hours ago

Monty the Giant Schnauzer Wins Westminster Dog Show

2 hours ago

US Defense Chief Hegseth Calls NATO Membership for Ukraine Unrealistic

2 hours ago

Visalia Man Arrested for Beating Dog, Confronting Officers

2 hours ago

Senate Confirms Gabbard as Trump’s Director of National Intelligence

WASHINGTON — The Senate on Wednesday confirmed Tulsi Gabbard as President Donald Trump’s director of national intelligence after Repub...

1 hour ago

Tulsi Gabbard, President Donald Trump's choice to be the Director of National Intelligence, arrives to appear before the Senate Intelligence Committee for her confirmation hearing on Capitol Hill Thursday, Jan. 30, 2025, in Washington. (AP/John McDonnell)
1 hour ago

Senate Confirms Gabbard as Trump’s Director of National Intelligence

President Donald Trump arrives to greet Marc Fogel at the White House, Tuesday, Feb. 11, 2025, in Washington. (AP/Alex Brandon)
2 hours ago

President Trump and Putin Have Agreed to Start Negotiations to End the Ukraine War

2 hours ago

Google Calendar Users No Longer See Default Entries for Events Like Pride, Black History Month

A screenshot of Apple Maps showing that they changed the Gulf of Mexico to the Gulf of America. (Screenshot)
2 hours ago

Apple Changes Gulf of Mexico to Gulf of America on Maps

Kevin Durant 30,000 NBA Points
2 hours ago

Kevin Durant Becomes 8th in NBA History to Score 30,000 Points

Palestinians stand next to tents surrounded by buildings that were destroyed by the Israeli air and ground offensive in Jabaliya, Gaza Strip, Tuesday, Feb. 11, 2025. (AP/Jehad Alshrafi)
2 hours ago

Too Few Tents Entering Gaza Threatens the Truce. Here’s What’s Happening

Residences destroyed by the Eaton Fire line a neighborhood in Altadena, Calif., on Tuesday, Jan. 21, 2025. (AP File)
2 hours ago

California’s FAIR Plan Needs $1B for Wildfire Claims, Costs Passed to Policyholders

Erik Michael Alexander Gropp
2 hours ago

Valley Crime Stoppers’ Most Wanted Person of the Day: Erik Michael Alexander Gropp

Help continue the work that gets you the news that matters most.

Search

Send this to a friend