Iranian hackers attacked our water systems. Here are 5 things our leaders need to do now

Over 30 Minnesota water systems were targeted in a coordinated cyberattack exploiting default passwords and internet-connected operational technology.

As tensions continue to rise between the United States and Iran, Iranian-affiliated hackers have reportedly reached into the heartland of America and targeted the systems that control a basic necessity of life: water.

More than 30 community water systems in Minnesota were targeted in a coordinated cyberattack in late July, with similar activity being identified in a handful of other states.

This should concern every American. But the most alarming part isn’t simply who may have been behind the attack. Instead, it’s how little sophistication may have been needed to pull it off in the first place.

INVESTIGATORS BELIEVE IRANIAN HACKERS ARE LIKELY BEHIND CYBERATTACK ON MINNESOTA WATER SYSTEMS: REPORT

Early indications suggest this was not some unstoppable cyberweapon that no municipality could have anticipated. Instead, the attackers appear to have targeted operational technology that is connected to the internet and exploited the kinds of fundamental security weaknesses experts have been warning about for years.

And while Iranian-affiliated hackers may have carried out this particular attack – certainly representing an escalation in the ongoing U.S.-Iran conflict – the attack on Minnesota did not expose a vulnerability unknown to our nation’s leaders.

Instead, it’s further underscored the real-world consequences of weaknesses the federal government has been documenting for years.

For instance, in 2024, the Environmental Protection Agency’s Office of Inspector General examined 1,062 drinking-water systems serving more than 193 million citizens. It found critical or high-risk cybersecurity vulnerabilities at 97 systems serving approximately 26.6 million Americans. Another 211 systems serving more than 82.7 million people had portals that were visible from outside their networks.

OUR ENEMIES FOUND A WEAKNESS IN ESSENTIAL TECHNOLOGY. WE MUST FIX IT … FAST

Put plainly, systems serving tens of millions of Americans could be discovered from the public internet. Exploiting these access points, as the inspector general warned, presented an opportunity for hackers to disrupt services and lead to potential physical damage to water infrastructure.

That is what raises the stakes far beyond the data breach Americans have become all too accustomed to reading about.

Of course, these breaches, whether involving a retailer or a credit bureau, can expose personal information and certainly inflict serious harm. That risk should not be minimized.

An attack on a water system, however, crosses a far more dangerous threshold – from compromising data to disrupting an essential service on which human life depends. Pumps can stop operating. Water supplies can be interrupted. An entire community’s health and safety can be placed at risk.

DSA CANDIDATE PUSHES FEDERAL AI DATA CENTER MORATORIUM WITH MICHIGAN EARLY VOTING UNDERWAY

The scope of this challenge extends far beyond Minnesota. According to the Government Accountability Office, nearly 170,000 water and wastewater systems make up America’s water sector. Many rely on aging equipment, face workforce shortages, and operate with little capacity for dedicated cybersecurity personnel.

Artificial intelligence (AI) is further complicating matters.

This technology has helped malicious actors identify vulnerable systems, create convincing phishing messages and modify malicious software faster than ever before. There is no public evidence that AI played a role in Minnesota, but it is making cyberattacks cheaper, faster and easier to execute at scale – and it’s a threat we must not ignore.

The fortunate reality, however, is that regardless of how powerful AI might be, AI does not remain the underlying weakness. It simply enables attackers to exploit said weaknesses more efficiently.

THE BIGGEST THREAT IN AMERICA'S RACE WITH CHINA ISN'T BEIJING, TECH EXECUTIVE WARNS

So where do we go from here?

The answer isn’t found in futuristic solutions while continuing to ignore the fundamentals. Instead, protecting critical infrastructure – such as water plants – must begin with five essential actions.

First, utilities must know what is connected to their networks. Every water system needs an accurate inventory of its equipment, software origins, remote-access points and third-party vendors. An organization cannot protect technology it does not know it has.

Second, every point of access must be secured. Default passwords must be eliminated, multi-factor authentication should be required, and critical controls should never be exposed directly to the internet.

TRUMP THREATENS 'MAJOR MILITARY PUNISHMENT' FOR IRAN OVER FUTURE HOUTHI ATTACKS

Third, operational equipment must be separated from routine business systems. A computer used for email, internet browsing or administrative work must not provide a pathway to the pumps and other machinery necessary to control a community’s water supply.

Fourth, software must be updated routinely and promptly. Attackers often search for known vulnerabilities whose fixes have been available for months or even years. A security update that exists but was never installed offers no protection.

Lastly, critical infrastructure must control what software is permitted to run by deploying application allowlisting, also known as whitelisting, across its systems.

Most traditional cybersecurity tools are designed to identify and block programs believed to be malicious. But AI now allows attackers to create and modify malware at an extraordinary speed, producing new variations that may not resemble previously identified threats. This makes a traditional, detection-only strategy increasingly difficult to sustain.

Application allowlisting, however, reverses this model. Instead of trying to identify every possible threat, it permits only previously approved software to operate. Everything else is prevented from running by default until a system administrator can review for safety. This prevents unknown, potentially malicious software from executing inside systems Americans rely on for necessities such as water and electricity.

Taken together, these five measures would make America’s water systems – and all critical infrastructure – substantially harder to compromise. They would also move these systems away from reacting to attacks after the damage begins and toward preventing the damage in the first place.

The latest attacks in Minnesota must mark a turning point in how our nation protects its critical infrastructure. Meeting this moment will require more than acknowledging the risk; it will require action, accountability, and urgency.

Every utility operator, municipal leader and government agency responsible for these systems should immediately assess whether these five standards are being met, assign clear responsibility for correcting every deficiency and establish firm deadlines for shoring up any vulnerabilities. And where local communities lack the necessary expertise or resources, state and federal partners must help close the gap.

The danger presented by cyberattacks is no longer distant, nor is it theoretical.

America’s adversaries are actively searching for known vulnerabilities. And any action, or inaction, which allows those weaknesses to remain unresolved is a choice that only invites a more serious attack – one with potentially deadly consequences.

America was fortunate – this time. Minnesota’s water system continued serving residents despite the attack.

CLICK HERE FOR MORE FOX NEWS OPINION

But that outcome should create urgency, not complacency.

Good fortune cannot be America’s cybersecurity strategy, and leaders must take action today by closing the known security gaps before the next cyberattack puts American lives in danger.

CLICK HERE TO READ MORE FROM ROB CHENG

The post Iranian hackers attacked our water systems. Here are 5 things our leaders need to do now appeared first on FOX News