Loading summary
A
Cybersecurity Today is brought to you by nordlayer. Teams today work across multiple tools and devices, but security often remains fragmented, and this is exactly what Nord Layer can help you address. Nord Layer gives your company centralized control over access by individuals and teams and keeps connection secure from anywhere with no additional hardware required. Visit nordlayer.com cybersecurity today and use the discount code NLSUMMER26 for a special discount on your purchase.
B
Welcome to a special edition of Cybersecurity Today. Instead of our usual mix of headlines, I wanted to spend this episode diving into multiple stories that cover different angles on the water utility hacking crisis in North America. We're going to start with who was behind the attacks in the United States and Canada. How the scale keeps expanding. Minnesota to seven US States to now an international angle with a Canadian utility hack. We'll dive into the mechanics of the attacks, the impacts and the findings from a cyber insurance war game on a larger scale. Simulated crisis targeting the water sector. We'll end with some hope. How a group of volunteers in the United States are trying to help the smallest utilities improve their security let's get started. This summer's water utility hacking spree is the widest and most disruptive Iranian operation against the United States since its war with Iran began in late February. Iranian crews have already paralyzed medical supply company Stryker and broken into the personal email of FBI Director Kash Patel. This one went after the pipes, and there's now a document tying the attacks on American water utilities to Tehran. A memo obtained by Wired circulated to members of the Water Information Sharing and Analysis center, or isac, links the wave of intrusions against Minnesota water and wastewater utilities to Iran and Minnesota was never the whole picture. The FBI and the Environmental Protection Agency issued a joint alert last Thursday and said the intrusions occurred in at least seven states beginning the previous Monday, with some of the activity degrading water operations. The federal alert says the same class of equipment was being hit across the country on the same time frame. The targets are programmable logic controllers exposed to the public Internet, Specifically the Micrologix 1100 and 1400 series from Rockwell Automation's Allen Bradley line. Attackers reached the devices and rewrote their configurations, changing IP addresses and passwords that locks the utility out of its own controls and CISA's advisory notes. The attackers were also pulling and manipulating the project files that govern the automated systems. The FBI and EPA documented loss of pressure and flooding as operational effects and warned that a pressure drop can draw untreated groundwater back into the pipes. Back in Minnesota. More than 30 municipal water and wastewater systems were targeted and and in some cases the attacks cut communications. The intrusions also tampered with operator displays, the screens the humans in the plant rely on to know what the plant is actually doing. In Braham, a city of 1700, the hack reportedly caused a brief outage at the water plant, South St. Paul officials said. Contingency procedures kicked in and public works staff kept water and wastewater running by hand. Tenable reported the operational pattern observed is consistent with Cyber Avengers, the crew tied to the Iranian Revolutionary Guard Corps that rewrote Unitronic's controller code in 2023 and disrupted water services from Israel to Ireland to Pittsburgh. Clarity told Wired it has found evidence pointing instead at Handala, the group that claimed the Stryker attack and the Patel email breach. The New York Times reported that the US and some state officials have concluded that the Minnesota attacks were likely Iranian state sponsored without naming the group. In addition to the US attacks, there was also an attack on a Canadian water supply, though not by Iran. In St. Noel, Quebec, a municipality of fewer than 400 people, the mayor watched a video of intruders wandering through the controls of his town's drinking water treatment station. The clip went up on July 24 on the Telegram channel of a group calling itself Z Pentest alliance, upbeat music playing over a screen, recording a cursor sliding over the chlorine dosage settings and moving them up and down. The plant dropped into safe mode. The water was not contaminated, and Marquis says the facility's network isn't connected to anything else. Canada's version of the nsa, the Communications Security Establishment, logged a hack at a second Quebec water plant last year. On Monday, I sat in on a panel at BSIDES Las Vegas, where a utility operator, a cybersecurity practitioner and an official from the EPA worked through these attacks in front of a packed audience, three things came out. The first is tied to how water utilities procure technologies. The public tendering process that small utilities are required to run creates some of the security problems. The second is triage. For a lot of small water systems, cybersecurity competes with keeping the water flowing, and doing that wins every time. The third one is the kicker. Rapid cycling of certain specialized water pumps can cause permanent physical damage, and replacing that equipment can take 12 to 18 months. Meanwhile, the insurance industry has been trying to run the math on what the damage would look like from a mass utility hack. In April, an insurance cybersecurity organization called Cyber accuview convened about 30 insurance executives in a Times Square conference room for a closed door war game. It was run by former CISA strategist Joshua Corman and Wired was allowed to observe on condition of anonymity for the participants. The scenario wasn't Iran, it looked at China's Volt Typhoon. The date of the game was set for July 2027 days before an anticipated invasion of Taiwan. The opening move was a restricted federal advisory reporting thousands of breached water utilities with unresponsive controls and anecdotal physical damage. 5000 utilities impacted 24 hours of game time. By the second round, the second order effects became visible. Refrigeration was failing at cold storage warehouses. Water dependent drug manufacturing had bottlenecked into insulin shortages. Data center cooling was failing and taking cloud services down with it. 2000 hospitals had no water and some were evacuating as H Vac Systems quit in the July heat. Corpsman also arranged for the incident response market to be sold out. At one table he rolled a 20 sided die and informed the players that Dragos, Crowdstrike and Mandid had no responders available. Everyone was busy with someone else. One task was to decide which clients get help first. Tables opened with the answers you might expect. Biggest customer by revenue first come, first serve. Whatever the government defines as national security. By day two, every team landed on saving lives. One participant was the only person in the room to say out loud that lives may not be the operative priority when treasury is on the phone asking for numbers or when an official is telling you that dual use military civilian infrastructure is now priority number one. Cyber Accuview CEO Mark Camillo's read on the exercise is that a catastrophic attack of this kind may simply be uninsurable, that the cost would bankrupt carriers unless they invoke the act of War exclusions that void coverage when armed conflict breaks out, which is its own damage to public trust. Those exclusions produced years of litigation after Russia's NotPetya attack in 2017. Camillo suggested fix is a federal backstop along the lines of the Terrorism Risk Insurance Program in the United States. Corman's own conclusion is that the insurance industry has more leverage than government to help prevent a mass event and it runs through how they determine policy conditions. He notes it's important for insurance to require customers to audit their edge devices and require them to join information sharing groups like the water ISAC. Only 0.3% of America's 151,000 water utilities belong to an ISAC. All of this is why volunteers are so critical. Right now There are roughly 50,000 community water systems in the United States, and the overwhelming majority are small, under funded and running aging equipment. In late 2024, DEFCON, the University of Chicago's Harris School of Public Policy, and the National Rural Water association launched DEFCON Franklin to pair volunteer security professionals with rural utilities that had nowhere else to turn. The name is a nod to Benjamin Franklin and America's first volunteer fire department. Franklin has deployed 27 volunteers to 21 utilities across seven states, and it still has active relationships with six of them. The work is unglamorous, helping find and reset default passwords, implement multi factor authentication and incident response documentation. Franklin founder Jake Braun told Cybersecurity Dive that almost none of the utilities had any written plan for what to do during an attack. Volunteers also spend time mapping the networks that contractors built and walked away from without documenting. Two findings from the Franklin program are worth noting. The first is that the vendor quote unquote charity model mostly isn't Franklin reviewed the free services security companies offer water utilities and found most came with expensive strings, a costly appliance you have to buy first, or a monitoring platform that needs a paid consultant to interpret Brown's metaphor for all this is free like a puppy. Utilities were under pressure to explain why they weren't accepting all this generosity, and the answer was they couldn't afford it. The second thing to note is attrition. Utilities kept dropping out of the program, not because they stopped caring, but because water safety, cybersecurity and payroll all land on the same two person team. Chelsea Johnson runs public works in Wilder, Idaho, and she noted her job is keeping water in the taps and toilets flushing for 1500 people. She notes they'd never be able to afford to pay a ransom if they were attacked. And she told Cybersecurity Dive that her experience working with Franklin volunteer David Armstrong was phenomenal. She says she learned a great deal from him. Johnson says she's sharing what she's learned with others she meets every few months with public works directors from neighboring towns. She brought multi factor authentication to the last meeting and had to walk the room through how to turn it on. Pass keys are on the agenda for the next meeting. Ron acknowledges the scale of the problem is enormous and it will likely take a huge amount of effort. His next target for volunteers is the utilities responsible for keeping data centers running. And that's Cybersecurity Today for Wednesday, August 5th I've been your host, David Shipley this story is the culmination of warnings I and many others have been sounding for years and perhaps the last best chance we have to avoid the catastrophic outcomes outlined in the insurance industry's April exercise. Thanks for listening. I'd love any feedback on today's Deep Dive episode, or any comments on the show in general. Thanks to all of you who've left reviews or ratings on your favorite podcast platform. It really does help. As a reminder, I'm at Black Hat and DEF CON this week and if you see me, please do feel free to say hi. I love meeting our listeners at events and learning about their stories. I'll be back on Friday with the latest headlines and a quick recap on some of the talks at Hacker Summer Camp this year.
A
Once again, we'd like to thank NORD Layer for their support in sponsoring this show. Teams today work across multiple tools and devices, but security often remains fragmented. This is exactly what NORD Layer can help you address. It provides a network security platform with easy to manage network access, monitoring and control, and without additional hardware or complex infrastructure. NORD Layer helps businesses of all sizes manage and secure access to company resources going beyond what traditional VPNs can offer. And it provides encrypted connectivity with visibility across your entire network environment. And did we mention no new hardware required? Visit nordlayer.com cybersecurity today and use the code NLSUMMER26 for a special discount during their summer sale.
Host: Jim Love
Date: August 5, 2026
This special edition of "Cybersecurity Today" goes deep into the ongoing water utility hacking crisis affecting North America in the summer of 2026. Instead of the usual roundup of cybersecurity headlines, the episode explores who is behind these attacks, how the threats have expanded, the technical mechanics of the intrusions, the devastating impacts, and the results from a large-scale cyber insurance war game simulating a mass utility hack. The episode ends on a hopeful note, highlighting grassroots volunteer efforts to help underfunded small utilities shore up their digital defenses.
| Timestamp | Segment Description | |-----------|-----------------------------------------------------| | 00:37 | Episode introduction and scope of Iranian attacks | | 02:00 | Memo linking attacks to Tehran; FBI/EPA alert | | 03:30 | Technical mechanics: how PLCs were compromised | | 06:25 | St. Noel, Quebec hack and Z Pentest Alliance | | 08:00 | Las Vegas panel: procurement, priorities, pump damage| | 09:15 | Cyber insurance war game scenario (China/Volt Typhoon)| | 09:50 | Second-order effects: hospitals, food, cloud failings| | 10:42 | The (un)insurability of catastrophic cyber events | | 11:33 | Insurance leverage on policy conditions | | 12:01 | DEFCON Franklin’s grassroots cybersecurity program | | 13:09 | “Free like a puppy”: pitfalls of security charity | | 14:12 | Real-world impact: Chelsea Johnson, Wilder, Idaho | | 15:10 | Looking forward: protecting data center utilities |
This episode balances alarm over the growing threat with hope and concrete, practical steps from the cyber-volunteer community. It’s an urgent call for stronger policy, industry involvement, and grassroots action. As host Jim Love closes:
"This story is the culmination of warnings I and many others have been sounding for years and perhaps the last best chance we have to avoid the catastrophic outcomes outlined in the insurance industry’s April exercise." (16:08)
For listeners: