Are Cloud-based Water Systems at Risk?

Son sistemas de agua basados en la nube en riesgo

8/1/2026

Is your city’s water supply at risk from afar? It could be if the system is on the cloud. Hackers have targeted water systems in several US states in a coordinated cyber-attack causing some utilities to issue ‘boil water’ notices, and to take their systems offline.

This has been happening for quite some time. A couple of years ago, I presented a report to my local city council when they were proposing replacement of old water meters. I presented the dangers of cloud-based water systems, and fortunately, they listened. In reality, the cost of an additional communications tower was probably what killed it, however, I’d like to think security played a factor.

The latest attacks are among the most serious cyber-attacks on water systems in the US in years. Hackers are targeting water entities of all sizes. Various government agencies, including the FBI and the Environmental Protection Agency, have been scrambling to help secure the water facilities and ensure the safety of drinking water. Water facilities are urged to take vulnerable industrial equipment offline.

The first public sign of the cyber-attacks came from Minnesota authorities, who said hackers recently targeted up to 30 water systems in that state. It’s believed they were trying to cause loss of system pressure and subsequent potential contamination of water supply, according to CNN.

Hackers are targeting internet-based programmable logic controllers (PLCs) - devices that allow machinery to communicate with water facilities and other industrial plants. The devices monitor water pressure, chemical dosing and other features in water systems to ensure they are safe.

Roughly six states have reported cyber-related incidents over the last week. Wisconsin officials detected malicious cyber activity at their water facilities and urged utilities to take “immediate action to prevent potentially serious impacts to [their] systems.”

The incidents are another in a series of recent cyber-attacks that have raised safety concerns for US water utilities. The water sector has struggled for years with funding to provide training against online threats. That bodes a simple question: “Why bother putting your systems online?” The answer is simple: Follow the money. For most, it’s more cost effective… until it isn’t.

Water systems have enjoyed the benefits of modern-day remote access. Sadly, those who wish to do harm also enjoy the benefit of hackers smart enough to gain access. Just because we CAN connect something to the internet doesn’t necessarily mean we SHOULD. Connectivity requires responsibility. Water is essential. We can ill-afford making it an easy target for nefarious actors.

While the U.S. government has not directly blamed anyone for the hacks, Iran does have a history of hacking the water sector, including during the current war. Allegedly, in April, Iran-linked hackers successfully targeted and caused disruptions at multiple US oil, gas, and water sites.

Sadly, the progression of modern technology is advancing beyond our ability to prevent abuse of that same technology. People consistently put their personal information online via ignorance, or in spite of the dangers it can bring. Cities are no different. I’m thankful my small town decided to keep their system in-house.

Source used: Scripps

****

Traduccion: LocalTranslate

Su ciudad está en riesgo de alejado? Podría ser si el sistema está en la nube. Los hackers han atacado los sistemas de agua en varios estados de EE.UU. en un ciberataque coordinado que ha causado que algunos servicios públicos emitan, hirvieran los avisos. y desconecten sus sistemas.

Esto ha estado sucediendo durante bastante tiempo. Hace un par de años, presenté un informe a mi ayuntamiento local cuando proponían reemplazos de viejos medidores de agua. Presenté los peligros de los sistemas de agua basados en la nube, y afortunadamente, escucharon. En realidad, el costo de una torre de comunicaciones adicional fue lo que probablemente la mató, sin embargo, como pensar que la seguridad jugó un factor.

Los últimos ataques se encuentran entre los ciberataques más graves contra los sistemas de agua en EE.UU. en años. Los hackers están apuntando a entidades de agua de todos los tamaños. Varias agencias gubernamentales, incluyendo el FBI y la Agencia de Protección Ambiental, han estado luchando para ayudar a asegurar las instalaciones de agua y asegurar la seguridad del agua potable. Se insta a las instalaciones de agua a desconectar los equipos industriales vulnerables.

La primera señal pública de los ciberataques vino de las autoridades de Minnesota, que dijeron que los hackers atacaron recientemente hasta 30 sistemas de agua en ese estado. Se cree que estaban tratando de causar la presión del sistema y la posterior posible contaminación del suministro de agua, según CNN.

Los hackers están apuntando a controladores lógicos programables basados en internet (PLC) - dispositivos que permiten a la maquinaria comunicarse con instalaciones de agua y otras plantas industriales. Los dispositivos monitorean la presión del agua, la dosis química y otras características en los sistemas de agua para asegurarse de que son seguros.

Unos seis estados han reportado incidentes relacionados con cibernéticos en la última semana. Funcionarios de Wisconsin detectaron actividad cibernética maliciosa en sus instalaciones de agua e instaron a los servicios públicos a tomar "medidas inmediatas para prevenir impactos potencialmente graves a sus sistemas.

Los incidentes son otro de una serie de ciberataques recientes que han planteado preocupaciones de seguridad para los servicios de agua estadounidenses. El sector del agua ha luchado durante años con fondos para proporcionar capacitación contra amenazas en línea. Esa boda a una pregunta simple: WY se molesta en poner sus sistemas en línea? La respuesta es simple: Sigue el dinero. Para la mayoría, es más rentable hasta que no lo es.

Los sistemas de agua han disfrutado de los beneficios del acceso remoto moderno. Lamentablemente, que desean hacer daño también gozan del beneficio de los hackers lo suficientemente inteligentes como para tener acceso. Sólo porque podemos conectar algo a internet no.t necesariamente significamos que nos preocupamos. La conectividad requiere responsabilidad. El agua es esencial. Podemos hacer que sea un blanco fácil para los actores nefastos.

Aunque el gobierno de Estados Unidos no ha culpado directamente a nadie por los hackers, Irán tiene un historial de hackers al sector del agua, incluso durante la guerra actual. Supuestamente, en abril, pisados vinculados a Irán atacaron exitosamente y causaron interrupciones en múltiples sitios de petróleo, gas y agua de Estados Unidos.

Lamentablemente, la progresión de la tecnología moderna está avanzando más allá de nuestra capacidad de prevenir el abuso de esa misma tecnología. La gente constantemente pone su información personal en línea a través de la ignorancia, o a pesar de los peligros que puede traer. Las ciudades no son diferentes. Agradecido mi pequeño pueblo decidió mantener su sistema en casa.

Fuente utilizada: Scripps