Video summary
Cyber attacks targeting U.S. water and wastewater utilities have been reported across at least seven states, including Minnesota, South Dakota, Michigan, Georgia, New Jersey, and Alabama, with some reports suggesting the scope may extend to a dozen locations. Although these incidents exploited vulnerabilities in industrial control systems connected to the internet—often due to poor security practices like default passwords and exposed IP addresses at smaller municipalities—they did not result in widespread contamination or an immediate threat to drinking water quality. Instead, the attacks caused operational disruptions that forced some facilities to issue boil-water notices and revert to manual operations, leading to significant financial losses for the affected utilities.
Experts attribute these incidents with a high likelihood of 90% to 95% to Iran, basing this conclusion on behavioral signatures, a history of targeting water infrastructure since 2013, and specific technical tactics linked to Iranian groups such as the IRGC's "Cyber Avengers." The nature of these attacks is characterized as opportunistic disruptions aimed at information warfare rather than long-term pre-positioning, seeking primarily psychological impact and power projection instead of causing physical harm. Consequently, experts advise against framing the events as a form of cyber escalation or accepting narratives that suggest Iran is targeting individual household taps, emphasizing that the primary goal was disruption rather than contamination.
In response to these threats, specialists recommend strengthening defensive cybersecurity regulations and increasing funding for water utilities while reviewing existing security tools. They also suggest that private employment of offensive cyber capabilities might be necessary to deter adversaries effectively. The discussion highlights the importance of understanding these nuances amidst alarmist headlines regarding potential U.S. diplomatic openings and quieter government responses, helping to clarify what truly matters in the current geopolitical landscape without succumbing to fear-mongering.
The episode concludes by acknowledging the value of this nuanced conversation for providing clarity during times of heightened public concern. Hosts announced that links to analysis pieces from all three guests will be included in the show notes and encouraged audience participation through a survey for feedback on future content. The segment ended with thanks to the guests, a call to subscribe to "State of Play," and information directing listeners to www.csis.org/geopolitics for further analysis, produced by Sarah Baker.
Read the full video transcript
Possible cyber attacks targeting water
and wastewater utilities have now been
reported across 12 US states.
Although there has been no widespread
contamination or an immediate threat to
public drinking water, it seems like a
serious and coordinated attack. So why
is US critical infrastructure seemingly
so vulnerable? What can be done to
respond to it? And I'll be right in
thinking this was probably Iran.
[music]
Okay. So today we are bringing together
three experts from right across the SIS
actually from all four departments
between the four of us. Now um we have
Caitlyn Welsh back on the show. Thanks
so much for joining Caitlyn. Um, as
you'll remember, Caitlyn is the director
of our food and water security program
in the global development department.
And I'm very excited to welcome as well
Lauren Williams, who is the deputy
director and senior fellow in the
strategic technologies program that's in
our economic security and technology
department. And then calling in, we also
have Dr. Nikkita Sha who is a senior
fellow with the intelligence national
security and technology program in our
defense and security department. It's a
bit of a mouthful um but um so excited
to have you all and just explain kind of
the provenence of this. Firstly, thank
you to Nina Priya in our external
relations department whose whose idea I
think was to was to make this happen.
But this came, am I right in saying from
a a briefing that you did to some um to
to the Hill um and then you kind of all
got talking more about how you were
tackling this. You've all written about
it um and and wanted to continue the
discussion. So I'm excited to to do it
in this format. Thank you for coming on
State of Play to do it. I think um we
will learn a lot because um I will say
although I am quite focused on Iran, I
have not been as focused on this. So I
want to start by asking you what
actually happened. So I think I said I I
I think the numbers are 12 reported
attacks now or across at least sorry
attacks across 12 different states. But
Caitlyn, can I start with you? What what
has just happened?
>> Yeah, thank you. Thanks Will. Great to
be back. The number that you gave 12 is
something that we're seeing in the
press. But I will note that the only
official number that we've got from the
US government is at least seven. And
that comes from an FBI press release
that was uh that was released on July
30th. And the FBI said that since July
27th, at least a dozen sorry, at least
seven states were subject to these
attacks to water utilities. Um, again,
the states were not listed, but we have
tracked reports of attacks in six
states. So, between late July and then
as of actually just 3 days ago, August
10th, we've tracked reports of attacks
in Minnesota, South Dakota, Michigan,
Georgia, New Jersey, and Alabama.
Coinciding with this FBI press release,
I will also say that SISA, the Cyber
Security and Infrastructure Security
Agency, has issued a few warnings since
the war in Iran started. A couple of
those were at the end of July and they
also talked about a significant increase
in cyber threat actors targeting
essentially water infrastructure. So
that's as of the end of July. I will
also say that um those notices were
reiterating a notice that was first
posted by SISA on April 7th and that
talked about um authorizing a agencies
identifying um again attacks to water
infrastructure hitting multiple cyber
attacks hitting multiple sectors. That
press release did not identify how many
states, whether one or multiple. So, at
the end of the day, we really don't know
how many states. We know at least seven
from the FBI. In the press, we're seeing
around a dozen.
>> I'll stop there.
>> Okay. And what actually happened? I
mean, when we say cyber attack, it
sounds quite scary, but as I said, as
far as I know, there haven't been, you
know, really widespread like people's
water didn't just turn off. Um, it's not
been poisoned.
Maybe I I don't want to downplay it, but
like how how how serious is what
actually happened?
>> Lauren, I'll jump in and then I think we
all uh can add add uh dimensions to
this. So, so let me take it to the um
kind of the the cyber attack kind of the
tactics uh level and then talk get to
your your real question which is about
the the actual impact which you know the
important thing as you said will and as
um you noted as well Caitlyn is that
drinking water is is safe. We haven't
heard of any reports across all of those
states and all of the the smaller
municipalities that were impacted and
I'll get out what we mean by impacted
that um there has been any contamination
of the water system. So that is a
resilience story, a good story for the
United States. But um you know when you
look at this from a a cyber security
perspective, it's also a story again of
how vulnerable our critical systems such
as water are. So the the quick and dirty
essentially is that cyber threat actors
were able to get into these water
systems from a wide range of states in
the United States across the country due
to the fact that critical industrial
control systems these programmable logic
controllers we've been hearing this term
um for the last several weeks are
connected to the internet in a lot of
places across the United States which
means that our critical water surfaces
have internet connective connection
points which attackers were able to
exploit and there are a lot of reasons
for that which I'm sure we'll dig into
quite a bit here which is that you know
these municipalities are generally very
small there might just be a few people
who are working at them and they need to
be monitored kind of 24 hours a day
which requires you to be able to have um
you know remote access and uh in many of
these cases uh there were kind of simple
cyber security basics that weren't being
followed default passwords were used.
Um, IP addresses were exposed on the
internet that attackers were able to
exploit and to get into these systems
and to cause
>> physical impacts to cause changes in
pressure to cause discernable anomalies
in these systems. But again,
fortunately, we didn't see actual water
quality impacted.
>> Okay,
>> thanks Lauren. in terms of impacts and I
um appreciate Lauren's explanation of
exactly the nature of these attacks but
um in the words of US government itself
um they describe the impacts in terms of
boil water notices and sustained manual
operations i.e disconnection from
internet internet and operation of
utilities that way and also operational
disruption and financial loss. So those
are the way that the
>> impacts have been described by at least
by CISA um those impacts
affecting communities around the country
um as well as multiple sectors. So we
shouldn't think about it just in terms
of impacts on households but also many
all of the sectors that rely on water
for a variety of reasons.
>> Interesting. Okay. So um can you can we
talk a little bit more about kind of why
this is so vulnerable like the
vulnerabilities? I mean, we talk about
critical infrastructure and I think
maybe a lot of our listeners would
assume with all the capabilities of the
US government that that there would be a
lot of resources put into protecting
them. Um, I think Lauren, you started to
get at this by saying, you know, lots of
these are very small there. You know,
they they don't have very many staff.
They were using password one 123 uh as
the password or something like that. Um,
but but kind of what h how do you think
about the vulnerabilities of critical
infrastructure? Yeah, I'll I'll give a
really quick answer and then I'll
welcome Lauren and Nikita to join to
jump in. But I think that water
utilities lie at this dangerous
intersection between being fundamentally
necessary and fundamentally vulnerable.
And in terms of being fundamentally
necessary, it's actually um challenging
to even describe the importance of water
to everything that we do because we rely
on it for everything. Everything from
all household uses, consumption and
sanitation and etc.
health purposes, industrial purposes,
military purposes, and the list goes on
and on. So, fundamental to everything.
And then fundamentally vulnerable
because there are um the network of
water [snorts] utilities around the
country is so diffuse. There are about o
over 150,000 water utilities around the
country. Um many of them very small,
small in staff, small in budget with
very basic cyber security uh uh elements
in place. And I'll let Lauren and Nita
build on that.
>> Yeah. No, it's exact it's exactly right.
And this is gets at one of the the
topics that the three of us were like we
really want to get into this you know
what is the importance of water and the
water utilities being targeted including
in the context of this conflict which
Nikita um will will dive into a and what
is the broader conversation around
critical infrastructure cyber security
because I think it's it's a combination
of all of those things water is
important in this case it has to do with
the the threat actor and its interests
and capabilities but also at the same
time and I'll I'll stick to this point
and then Nikita and can add on our
critical infrastructure broadly and
we're and that includes water, it
includes energy utilities, it includes
our transportation and there are 16
sectors and CISA um you know manages
this the security of all of these. They
are uniquely vulnerable in the United
States and that's for all the reasons
that that Caitlyn already laid out which
is because we have such a dispersed
system of owners and operators um
utilities included. So, we've got
privately managed and owned utilities in
the United States. Water, for example,
is um kind of operated by localities or
or private operators. And then we've got
kind of the state level, which may or
may not, you know, be very connected um
from a cyber security perspective. We
already talked about how these utilities
might just not have experts um who are
steeped in or even thinking about cyber
security because they're trying to just
keep the water um uh kind of the
day-to-day operations of of water um
going strong. And then there's the
connection between uh the federal
government level where you just kind of
lose connectivity at each each step that
you move up the chain. Um, and all of
that is to say that we have a very
fragmented and kind of deregulated way
of approaching cyber security in the
United States. We look at it from a
sector by sector level. So water cyber
security requirements are different from
energy are different from space which I
worked on in government. Um, and it just
adds to the challenges and it it means
and we also have not historically funded
cyber security um, adequately in the
United States as well. And it really
comes to a head in situations like this.
And I'll um I'll just add on really
briefly um just building on what Caitlyn
and Lauren have said, you know, you've
got these these very fragile but very
critical um ecosystems that we've been
talking about. Um and so that makes them
lowhanging fruit for adversaries in in a
conflict to target because it ultimately
gives them symbolic value. They're
showing that they can reach into the US
homelands. They can tinker around with
things and they can have a a pretty
important symbolic effect which is very
much what they're after.
>> So Nikita, let's talk about that then.
Let's talk about who did this. So, um I
you know the reports are saying it's
sort of assumed to be Iran, but I don't
think the US government has assigned a
culpability explicitly to to Iran. So,
what can you tell us about how we know
about who did this?
>> Yeah, it's it's a really important
question and you know, as you said,
there's been no official attribution or
or kind of recognition from the US
government that this is Iran. Um from my
perspective it's it's something like 90
95% likely to be Iran because of um the
way that the attacks were conducted from
a technical perspective. Um so so in
cyerspace we tend to think about
different actors having their own
behavioral signatures almost you know
they have certain things about the way
that they conduct attacks their intent
their capability and if you look across
those all signs effectively point to
Iran. Um I'll pick out three things. So,
one is Iranian cyber actors. Um, whether
it's the Ministry of Intelligence and
Security or the Iran, uh, the Islamic
Revolutionary Guard Corps, they have a
history of targeting the water sector
across the United States and Israel. Um,
that goes right back to 2013 when, um,
Iranian actors attacked a dam in New
York State. Um, it also, uh, goes to
attempts in Israel, um, I believe in
2020 where they tried to poison, um, an
Israeli water supply. Um and then it
goes through to um you know likely to to
the events that we're seeing now, but
also an April 2026 advisory that that
CISA put out earlier this year um where
it pointed to again Iranian cyber
attacks on the water and energy sectors.
So there's a real continuity there in
terms of how Iran um targets the water
sectors across you know two adversarial
countries. Um the other thing I'll
mention is the technical component in
question. So if you look at the way that
the attackers got in and the particular
type of industrial control uh technology
that they were targeting, they're called
programmable logic controllers, which is
a a kind of technical way of saying
these are the heavy industrial machines
that enable you to control industrial
systems basically and monitor what's
going on, etc.
um c certain Iranian cyber actors and um
the IRGC in particular uh this is a
group called cyber avengers um that's
linked to the IRGC it's highly likely to
be them because they have a target uh a
history of targeting PLC's in particular
um they've done it before in Israel um
again this is linked to the CIS advisory
in in April this year it's highly likely
to be that particular actor so there is
always a chance it might not be um but
you know from my perspective all signs
pointing towards Iran.
>> No.
>> And I'd just like to underscore
something that Nikita said. Um at the
highest levels of the US government,
there's been reluctance to attribute
these attacks to Iran. I will say though
that in public issuances from July 22nd
and from April 6th, they have named
Iran affiliated threat actors targeting
critical infrastructure including water
infrastructure. So parts of the US
government have named Iran.
>> Yeah. And I'll jump I was going to jump
in here kind of with the somewhat of a
question. So hopefully not going in a
different direction that you were
looking to go will because I think for
all of us we've had a lot of
conversations in the last couple of
weeks with different stakeholder groups
about different elements of this uh
crisis and one of or these attacks and
one of the questions that's come up and
my conversations has been you know is it
important or is it not to to tie these
attacks to Iranian threat actors and as
as Nikita argued and I completely agree
to map their past you t tactics and
techniques to the current um attacks
that we're seeing across the country.
Kind of why is that important or is it
not important? I think it is, but uh
kind of curious from Caitlyn and and
Nikita's perspectives and Caitlyn, I
know you're looking at this in a global
context, in the context of the war.
>> Yeah. Yeah, that's a really good
question, Lauren. Um I I think in the
context of the Iran war and its fallout,
I think it is important to name Iran if
indeed it is Iran. um happy to talk
about how targeting water infrastructure
sits in the context of the war generally
speaking. Um I think though that any any
attacks by malicious actors to water
infrastructure in the US would have a
number of impacts. Um and I'll say
really quickly we've been focusing on
the physical impacts, what they are and
what they are not of these ongoing
attacks. Um, beyond these physical
impacts though, there are psychological
impacts that are real and these attacks
certainly have captured public attention
and policymakers attention. And then
there's also the threat of uh potential
future attacks. Um, and whether or not
the attacks were effective today um is a
different question from whether or not
they may be um effective in the future.
So in this case that malicious actors
might be laying the tracks for future
attacks. Um so all all those things
would be in place no matter who the
actor is. Um in in terms of Iran though
assuming it is Iran uh that's
responsible for the these most recent
attacks. It is interesting to look at it
again in the context of the in the
broader context of the ongoing war with
Iran. I'll pause there though will I
don't know if we want to go to Nikita
first and then I'm happy to talk about
that context.
>> Yeah sure. No let's let's turn to Nikita
and then but I I'm I'm really interested
in that broader context piece. But
Nikita,
>> it's a really good question and and so
what I'd say is if if you if we kind of
zoom out for a moment and look at the
way that Iran's been um kind of
conducting itself so far in the
conflict, one of the key things that
it's been doing is opportunistic
disruption. So the CIS advisory from uh
late July uh itself calls the these
operations opportunistic targeting. And
I think the word opportunism is such a
critical point because as we've seen in
this conflict in the um 12-day war
between Israel and Iran last year and in
the Russia Ukraine war that's still
ongoing. In conflict cyber actors behave
quite differently and what they're doing
is they're looking for quick things that
they can throw at vulnerable targets
that are poorly defended to see what
sticks and that to me is very much what
it looks like has happened here. Um in
this case Iranian actors have been
targeting a number of critical
infrastructure sectors across the US. So
so not just water. Um they've gone after
uh energy, they've gone after local
government, they've also gone after
transport. I I could keep going with
that list. Um and in this case, I think
they found a particularly poorly set of
defended um systems that had some pretty
basic vulnerabilities from a cyber
perspective. So think, you know, default
passwords, lack of authentication, um
they had operational technology
connected to the internet, which is
highly advised against. Um and so they
threw something quickly. Um they've
actually been building accesses on this.
um back to January 2025 and over the
course of this year, which to me
suggests they weren't looking to
pre-position on something. So, in this
case, they were looking for instant
impact. Part of the reason for that is
there are other systems that they're
prepositioning on where there's evidence
of that against uh different types of US
and Israeli organizations. Part of that
is also because of the real goal here.
So, if you're thinking about an
attacker's intent, what the Iranians are
really after is um information warfare
as an objective. So they're looking for
cognitive effect against the US public
and in this case yes the primary goal is
disruption of the the water systems but
really the secondary goal is that
psychological effect. So how can they
how can they project power by showing
that we can reach into the US homeland
we can tinker with some of your most
critical systems and we can have an
effect even though you know you're
you're attacking us and you're really
grinding us down um you know kinetically
uh back in the actual country. this is
an area we can where we can punch above
our weight and so the goal here it looks
to me is very much to so fear to create
a sense of insecurity and to project
that power directly into the US. Um so
for me it's it's less about
prepositioning for longerterm attacks.
It's much more about immediate quick
impact that they will then amplify
through social media channels and and
through the news. And the last point
I'll end on is it's why information
warfare during conflict is so tricky
because on the one hand there's a real
duty right to to report to the American
public and the global public this is
what we're seeing this is what's going
on there is a real risk as to how things
portrayed because it can risk amplifying
the attack which very much plays into
Iran's objectives of of power projection
that's so interesting and Nikita just
before we started recording we were
talking a little bit about this and I
was saying you know how much does this
actually matter if people weren't I mean
Caitlyn you talked about the costs and
you talked about um boil um orders,
water, sorry, boil water notices, but
like if it didn't really harm people,
are we exaggerating how bad this is
given that cyber attacks are now kind of
a part of warfare in the 21st century?
So, um yeah, interesting. Um and and I
guess Caitlyn, you you said I think you
may have a slightly different take on
this that it it actually, you know,
water is becoming much more of a weapon
of of war. So h how are you thinking
about this within the broader context of
the weaponization of of war and attacks
on water infrastructure in this war
specifically?
>> Sure. And and I would say to your point
about how how bad this was um even if
there were not widespread attacks um as
part of a we could we we might be able
to consider these ongoing because we've
had notices of new states as of 3 days
ago. Even if there were not widespread
impacts on households, communities,
industry, um these attacks did reveal
extreme vulnerabilities. And I I I I'm
thinking Lauren might have some more to
say about that. Um [sighs]
so in in that sense they did have impact
by revealing those you know those severe
vulnerabilities. Um in terms of the
context of these attacks um uh within
the Iran war um you know it's
interesting to think about these attacks
as being opportunistic as Nikita was
saying and this could be this could be
Iran just you know throwing spaghetti
against the wall and seeing what sticks
and this is one thing that is that is
sticking right now. Um at the same time
there are very interesting parallels
between two spates of attacks on water
infrastructure in the Gulf region as
part of this war. One being this spring
and then one being this summer. In the
spring we saw attacks between Mar early
March and early April on multiple
countries on water infrastructure in
Iran, Bahrain, UAE, Kuwait. Those
attacks attributed to United States and
Iran. And then again in summer you had
attacks on water infrastructure in Iran
and Kuwait attributed to the United
States and Kuwait sorry and Iran. So two
two different spates of attacks. Um
around the time of that first debate you
had President Trump speaking publicly or
at least writing publicly about this and
this is from two social. He said if if
the Hormoo strait is not immediately
open for business we'll conclude our
lovely stay in Iran by doing a number of
things um uh and Car Island possibly all
desalination plans. So, sorry. Um,
blowing up and completely obliterating
lots of things, including Car Island and
possibly all the desalination plants,
which we have purposely not yet touched.
So, there was an official
acknowledgement at least of intent to
target those things. And then you did
have direct targeting. Um, that was in
March. We were tracking those attacks in
the Gulf at the same time that SISA was
putting out public notices of those
attacks happening to US water utilities
and in states here in the United States.
Again, you had a ramp up in hostilities
in the Gulf this July. At the same time
that FBI, SISA and others warn of
increasing attacks and we're seeing
reports of increased attacks. So on the
one hand, it could be opportunistic. On
the other hand, we are seeing strong
parallels between these attacks in the
Gulf and in the United States. Yeah,
just to jump in here because I think to
tie um connected tissue I think to to
both of your points like I think what we
are seeing is opportunistic
targeting of water systems by Iran. So
if if that's a way to kind of draw
connected dots because as I think Nikita
you noted at the very beginning we you
know Iran is target 2013 and in 2023 and
now we're in 2026 has cons consistently
through its uh proxies tied to the IRGC
targeted water sector infrastructure. So
a dam in 2013, water system in
Pennsylvania in 2023, and then right now
I think to to the point what we've seen
is opportunistic targeting of a specific
industrial control system that
specifically targets water utilities
across a range of states that were
vulnerable or had vulnerable systems. So
to me I think it does certainly you know
point to the fact that there is a
specific emphasis on water or
specifically an an emphasis and a um
developed you know capability of being
able to target vulnerable uh water
sector infrastructure that has obviously
caused physical but not safety impacts
across the United States ac across 12
different states. You know, we were
earlier when these attacks were first
starting to be discussed, there was some
conversation around, you know, why
Minnesota, why Michigan, for example.
But now we're having a conversation
where it's South Dakota and Georgia and
Alabama. Um, and I think that more so
speaks to the infrastructure as opposed
to the state.
>> So before we start to bring this to a
close, I would love to hear from each of
you what you think should be done about
this. Now, my understanding is there's a
bit of a debate among the um sort of in
the cyber security world about whether
you should go on offense or defense. Um,
and again, my understanding is that the
Trump administration has leaned a little
more into the offensive piece of that,
but tackling whichever part of that you
want to, I'd love to hear what you think
should be done um to to better improve
to better build resilience of water
infrastructure, but then also to deter
Iran. So, Lauren, I know you just spoke,
but can I go back to you and c can I
start with you on what you would like to
see be done in response?
>> Sure. So I'm I'm going to focus on the
the defensive side of the coin and and
going to say that I think as we've all
talked about and pointed to different
you know data points
US critical water infrastructure or
expand that to critical infrastructure
but I'll talk about water specifically
has been known to be vulnerable from a
cyber security perspective for a long
time and we're seeing that vulnerability
um be act acted upon in an opportunist
IC but maybe also in the broader context
of the war potentially strategic way um
by a nation state threat actor which you
know means that nation state threat
actors are impacting and kind of coming
home to roost um in our you know
municipalities across the country. So
that's the situation that we find
ourselves in today and there has been a
lot of discussion over years fortunately
now it's kind of coming to a head in
this current crisis about identifying
and implementing requiring specific
cyber security requirements or
regulations for the water sector in
particular. So there were conversations
around um the Biden administration
putting out water sector cyber security
requirements several years ago. There
was a lot of push back. there tends to
be push back from the industry when
you're talking about adding on cyber
security requirements because those of
course cost money and uh you know the
money that it costs uh to focus on cyber
security then the argument is that it
gets passed on to consumers. So this was
the kind of the
um thrust of arguments against kind of
acting and moving on these requirements
several years ago. Now there there um I
think several different layers of
activities happening across the country
and Caitlyn you're probably tracking
more than I am but specifically I'll
point to um two senators uh Senator
Clolobashar Senator Schiff Minnesota and
California senators who have put um out
um draft legislation essentially that
would better empower the EPA, the
Environmental Protection Agency, better
empower uh cyber security agencies to
identify and require ire um best uh
specific practices for for utilities
across the country. And fortunately as
well they are putting up um kind of
dollars against those requirements which
is the most important challenge yet fund
these mandates. So $300 million is what
they have um identified. We see states
that are well resourced doing this as
well. New York for example um just put
up you know $9 million against uh cyber
security requirements to to better shore
up their capabilities. But that's that's
a state that's being proactive and has
been working on these issues for for
several months. So, you know, it is a
time of crisis, but we are at least now
um seeing some activity on the national
level. But that's I'll leave this maybe
for a closing thought. Um that's also
against the backdrop of kind of uh
federal funding cuts and staffing cuts
at our critical cyber security agencies,
which is not necessarily a good news
story here.
>> Yeah. Okay. Caitlyn, can I turn to you
next? Yeah, certainly. This week so far,
I've been tracking some legislation
that's been introduced, at least two
pieces that have been introduced. Um, I
saw a letter from industry that referred
to four other pieces of legislation that
policymakers should consider supporting.
So, there are there's no shortage of
proposals on the Hill about how to
address issues like this. Um, in terms
of what's best to do to fortify our
defenses against the ongoing attacks and
potential future attacks, one thing that
I think is really important is
essentially to review what's already in
place. It might not be a matter of
reinventing the wheel, creating entirely
new um authorities and agencies, etc.
There might already be a a good set of
tools in place that just need attention
uh and staffing and funding that we can
use in the near term. Um, apart from
legislation, I'll also note that there
was an an op-ed in the Washington Post
this spring that talked about actually a
volunteer effort to match cyber security
experts with the lowest resourced water
utilities to actually just give them
those better cyber cyber capabilities in
the immediate term, not a long-term fix,
but that's a near just a near-term thing
that just to put on folks radars. But I
think a first step in Congress is just
to review what's already in place
because again, might not have to
reinvent the wheel. Um, in terms of any
new legislation that might come on, it's
really important to get input from
experts from industry and academia and
elsewhere as well as water utilities of
all sizes because these actually are the
smallest utilities that are being that
are being attacked right now. And then
finally, whenever new legislation, and
maybe this is the moment for new
legislation to be passed, um, that uh
that that legislation protect water
utilities of all sizes. And again, right
now it's the smallest ones that are
being attacked because they have the
smallest amount of resources and there
is great psychological impact there. At
least one piece of legislation that I
saw proposed recently actually applies
only to medium and large size utilities.
I think that would be highly ineffective
to pass new legislation that does not
protect the utilities that are precisely
being targeted. Um so just some thoughts
there, but I I'll be watching with a lot
of interest on the hill to see if this
is a moment for bipartisan action on the
issue.
>> Great. Nikita, do you have anything to
say on the offensive side? Because
there's Oh, and please do add on the
defensive side as well if you're
interested, but I I wonder like should a
response be limited to the cyber
>> like to the cyber realm or would you
like to see a broader response that that
goes beyond that?
>> Um I think I think it's really important
to think about the different facets of
of cyerspace, right? So um I I'll kind
of make three points. The the first is
if you look at Iran's wider behavior in
this conflict, yes, they're pursuing
opportunistic disruption. They're also
investing a lot and really prioritizing
in in cyber espionage. They're also
thinking about these these cyber enabled
influence operations, which is what
we've discussed a little bit and having
that psychological effect. And so I
think a much of the the coverage of of
these particular instances pointed out
with many of these utilities, they look
at the war and think, hold on, that's
that's going on all the way over there.
That doesn't affect me. whereas actually
because of the the different attack
types I've mentioned and and the
psychological value that we've discussed
um it makes them the perfect targets. So
there's an even higher premium on what
Lauren and and Caitlyn have discussed in
terms of having those basic cyber
security standards in place. Um minimum
kind of requirements um and then really
thinking about their their resilience in
the longer term because um it's very
much Iran's way of connecting and
bringing home something that's far away
to the American public that makes um
American businesses um however big or
small the perfect targets in this
conflict. And so kind of reflecting on
response, I' I'd pick out two things.
The first is from an offensive
perspective, this is an administration
that really does put a premium on
offensive cyber operations. They want
the United States to have a more
aggressive stance in cyerspace. They
want to take the fight to their
adversaries much more. And what I found
interesting about this attack was um
President Trump's response where he was
quite quish uh sorry, he was quite quick
to to quash any talk of this being Iran
as the responsible actor behind these
cyber attacks. um and he in fact uh
tried to blame um democratic officials
for for being responsible which was um
you know pretty surprising and and they
were very quick to refute that in turn
but I think that in itself is a
strategic move right so again if we're
zooming out and we're thinking about
what's going on more broadly with this
conflict diplomatic negotiations are
ongoing they're quite fragile they're
quite fraught and so the way I read um
President Trump's statement was uh
almost an effort to to minimize um the
the kind of risks or the threats posed
by these particular attacks in order to
preserve those wider diplomatic channels
and keep negotiations going. The thing I
would say about that is um we absolutely
shouldn't take that at face value and
think oh well that's it the US isn't
going to to do anything in response to
Iran. Um I think firstly doing defensive
measures and and strengthening your
defensive measures isn't itself a very
important form of response um to
adversaries. I think the second thing is
I would very much assume that the United
States will use offensive cyber
capabilities to respond to Iran in
private. Um, and it might not be
something that they they talk about or
they're transparent about, but I imagine
that would be taking place behind closed
doors. And then the last thing I'll
point out is um if we look at the
response of some of the um you know mun
municipal officials in these attacks, um
some of them did a really fantastic job.
um in Minnesota in particular, they were
very quick to revert to manual planning,
thinking about um water reserves and how
they could switch those instead so that
public water supply wasn't actually
disrupted or impacted. Um and I think
that was a really fantastic example of
cyber resilience in practice where you
have those manual uh backup methods in
place and you can turn to those quickly
uh in order to minimize the impact of a
particular cyber attack and and really
withstand um a cyber attack. So I think
it's a fantastic example of um a good
response.
>> Thank you. Just a really quick note to
foot and this is a whole other
conversation around this
administration's response to um
adversary cyber activities. your your
anecdote about President Trump's
response to Iran reminded me of a side
of a conversation with a journalist that
he had after the Trump she summit where
someone asked him about uh China or like
Beijing's um cyber activities and he was
quick to deflect there as well and said
something along the lines of you know we
do it and they do it too.
>> So I think there's a bigger there's a
bigger story there when it comes to not
wanting cyber operations from nation
state actors to detract from other
administration priorities.
>> Interesting. Okay, unfortunately I have
to start bringing us to a to a close
now. So, the title of this episode now
seems kind of obvious based on what
you've all been saying, but I probably
have to ask you anyway. So, did Iran
attack US water systems? Lauren?
>> Yes.
>> Yes. Kayn,
>> uh, according to US government agencies
and at least earlier this year. Yes.
>> Okay, Nikita.
>> Highly likely. Yes.
>> Yeah. Okay. So now then the more fun
one. So is there a word or phrase that
you that you would like to ban pundits
from using when talking about anything
we've been discussing today or or more
broadly? Um let's go the other way
around. Nikita, can I start with you?
>> Sure. Um I'd like to ban the phrase
cyber escalation. Um I've I've seen that
thrown around a little bit in response
to these attacks. I think it's a very
unhelpful narrative. Um, there's
actually something I'm I'm about to put
out a short commentary on, which is, um,
I don't think this is a it's helpful to
read this as escalation. Um, it's also
very difficult to determine what
escalation looks like in cyerspace. And
in this case, I think it is something
opportunistic. There are also political
reasons to to minimize these and and
preserve wider uh, relationships. And um
I think you know ultimately we're
talking about psychological impact not
not kind of um not necessarily physical
or psychological in addition to physical
and I think escalation just sucks the
nuance out of those discussions.
>> Interesting. Okay. Thank you Kaitlin.
>> Yeah. Um one way that I've heard this
phenomenon described is um Iran coming
for people's tap. Is Iran coming for
your taps um in your household taps? And
I think that that's counterproductive. I
think that this is a moment to bring
attention to the importance of
fortifying our public water utilities to
threats of all types of to cyber attacks
to infrastructure degragation, climate
shocks, etc. Um so I think that that
moment is very very important and I hope
those things happen. Um to lead the
public to think that Iran is targeting
um individual household taps is again uh
that that's counterproductive.
>> Okay. Yeah. Lauren,
>> I think I I want to ban not a word, but
it just uh I want to ban talking about
these attacks in isolation without
looking at the broader context, which is
obviously the opposite of what we've
done today. But [laughter] yeah.
>> Yes. Okay. Cuz I actually um there was a
a piece of me that thought, are we doing
exactly what we we shouldn't be doing by
by playing this up and giving it too
much attention? But I think you've
actually done the opposite of that. So
to summarize then what I've heard you
say. So you've said firstly what
actually happened. So at least seven
states have been attacked maybe up to a
dozen. Um hackers got into systems
across the the country largely through
the or I think through the internet. Um
that resulted in boilwater notices,
financial losses, and Caitlyn you
highlighted it could be ongoing as well.
We've had another one as as recently as
3 days ago. And I should say we recorded
this on the 13th of August as well. Um
so kind of why is it so vulnerable?
Well, water is critical to absolutely
everything. Uh, and it is also
fundamentally vulnerable and I think
you've said, you know, a lot of these
utilities have small budgets, small
staff, and it's a really fragmented
system as well, which means it's very
difficult to uh protect all of it. Um,
and it's seen as lowhanging fruit to
actors like Iran. So then, was it Iran?
And I think the consensus seems to be
very very likely and that uh Nikita you
gave several reasons for that. This
matches the behavioral signature of past
Iranian attacks. There's a history of
targeting water since at least 2013 and
the technical piece as well. Targeting
uh PLC's is something that they've done
before and it also fits into the broader
context. I think you've said yes, it's
an opportunistic attack, but it's also a
sort of strategic opportunistic attack
uh because of that history of water and
and uh targeting water. Caitlyn, you
highlighted uh the different spates of
attacks on water that we had in the war
earlier on in the spring and then also
in the summer with dissalination plants
being hit. Um attacks attributed to both
the US and and to Iran. Um, and then I
think, uh, Nikita, you said it's it's
not just, you know, it's it's partly
about seeing what sticks. It's partly
about having instant impact, but it's
also about projecting power and the
information warfare piece of this. It's
a psychological thing, trying to bring
the war and the consequences of the war
home to Americans so they can feel it.
So then we finished by talking about the
response. And on the defensive side, um
you would like to see um identifying
specific uh regulations uh water
security uh cyber cyber uh security
requirements for the water sector. Um
and there's some interesting legislation
um including uh that uh tries to uh
gather best practices and also funds
some of these defenses. But Caitlyn, you
said it's not just, you know, we we
don't have to reinvent the wheel. uh
there are some interesting and important
pieces in place. It needs attention. It
needs staffing and it needs funding. And
then on the offensive side, kind of
interestingly, although the Trump
administration at large has focused
quite a lot on building the offensive
capabilities, President Trump himself
has chosen to downplay these attacks uh
and and not to link them directly to
Iran. Maybe that's because of uh the
state of uh diplomacy in the the war um
where you know the 60-day so-called
ceasefire is about to expire. Um and and
maybe he wants to create more of an
opening for diplomacy. Um but or you
also said we should we shouldn't assume
that there isn't a more private a
quieter uh response from the US
government. So um
I think I think we've covered a lot. Uh
that was um that was I think some real
nuance to this conversation. Um you know
some quite alarmist headlines but I
think you've really helped us think
through um you know what actually
matters, what's new and what needs to be
done really importantly. So I should say
that um in the show notes we will link
pieces from all three of you. Um you've
been doing really great work on this and
and so I'll make sure that the audience
has access to that. Um a final plug as
well for the audience. I keep saying
this, but we have a survey out at the
moment for uh about State of Play. So,
if you do have thoughts that you'd like
to share with us, we'd be really really
grateful uh to hear what you'd like to
see more of, what you'd like to change,
what you'd like to hear less of. Um but
I think for now, I'll say uh Caitlyn,
Lauren, Nikita, thank you so much. It's
such a pleasure. I am sure you're going
to collaborate more and I'm very excited
to see what you produce, but thanks for
using this platform to share some of
your analysis. Thank you so much.
>> Thank you. Oh, thank you.
>> Summary.
>> Thanks for listening to State of Play.
If you enjoyed this episode, subscribe
to it wherever [music] you heard it. And
you can find more analysis at
www.csis.org/geopolitics.
This podcast was produced by Sarah
Baker. Until next time.