Cybersecurity of US water supply systems will be ensured by hackers

2

The University of Chicago Harris School of Public Policy's DEF CON Franklin project recruited 450 hackers to ensure the cybersecurity of water infrastructure in the United States. This measure was a response to recent cyber attacks in which Iran is suspected.

For these purposes, DEF CON Franklin and the US National Rural Water Association (NRWA) will launch a Water Watch Center (WWC). Safety services will be provided directly to small water systems, each serving fewer than 10,000 people. All involved specialists will exchange information about threats through a special cooperation mechanism and transfer it to NRWA.

DEF CON Franklin brings together hackers and security experts to solve problems in the cyber environment. It consists of volunteer experts who will work with water and wastewater utilities in Arizona, Indiana, Oregon, Utah, Vermont, Washington and Wyoming.

The key problem remains the number of water supply organizations that need these specialists. There are about 150,000 such companies in the country, and their lack of security systems poses a significant threat to the United States, said Jake Brown, co-founder of DEF CON Franklin and former acting principal deputy director for national cybersecurity at the White House.

“Our amazing Franklin volunteers will support efforts to reduce costs for cash-strapped utilities. To further speed up the work, we have selected cyber providers that already support water utilities. These guys come to work already knowing the ins and outs of water cybersecurity,” Brown said.

He named the Chinese military and Iranian hackers as key adversaries posing a threat to US infrastructure. It is the latter who are suspected of the recent incident. On July 30, the Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA) issued a joint statement reporting cyberattacks on water supplies in at least seven states, but did not specify which states. After gaining remote access to devices connected to the Internet, the attackers changed IP addresses and passwords, which led to the loss of monitoring and management functions.

“The FBI and EPA recommend isolating devices from direct access to the Internet using secure gateways and firewalls, and establishing strong, unique passwords to allow only authorized communication between control system devices,” the publication clarifies.

Some utilities have lost critical control capabilities, forcing operators to go into manual mode. In other cases, hackers gained remote access to pumps, valves and water pressure control systems. On the same day, a warning from the Cybersecurity and Infrastructure Security Agency (CISA) appeared.

“Even water utilities with strong cybersecurity processes should review their external connections, as targets may include cellular modems installed by operators, suppliers, or system integrators that may not be documented or included in routine attack surface tests,” the agency said.

The next day, US President Donald Trump said that he had “heard about a cyber attack” in Minnesota, calling the actions of local authorities “completely incompetent” and expressed doubt about Tehran’s involvement in the incident. To this, the state governor, Democrat Tim Walz, who ran for vice president in the last presidential campaign, reproached the head of the White House for hiding information.

“Trump knows exactly who is responsible for this attack and knows that other states were also affected. This is what modern warfare looks like, and it once again underscores that there is no plan to win a war with Iran,” Walz said.

As it turned out later in the state, more than 30 municipal water systems were hacked. A few days later, on August 4, the media reported attacks in other states, the total number of which was reported to have grown to 12. CBS News mentions Michigan, Georgia, New Jersey and South Dakota among them.

Read also:  “They were condemned”: Rubio criticized Balogun’s red card in the USA-Bosnia and Herzegovina match

Iranian officials did not comment on the incident. Suspicions of hacking were expressed against the hacker group CyberAv3ngers, allegedly associated with the Islamic Revolutionary Guard Corps (IRGC). However, the group denies any involvement.

“Any reports of our cyberattacks on US water infrastructure are absolutely false propaganda. But we are ready and stronger than ever – our capabilities will surprise everyone. The time has not come yet,” CyberAv3ngers emphasized.

Earlier, RTVI talked about how a Belarusian was sentenced in the United States to 16 years for extortion via the Internet, and artificial intelligence models Claude and GPT hacked the infrastructure of four organizations in the United States with an interval of less than 10 days, getting out of control at the time of testing.

LEAVE A REPLY

Please enter your comment!
Please enter your name here