What pops in your mind when you hear the term ‘hacker’? Years of corny representations in pop culture probably conjure up the image of a sweaty, obese man giggling to himself in his parent’s basement. Recently, the proliferation of state-sponsored hacker groups may have shifted this view somewhat. Still, even the worst breaches, such as the SolarWinds incident disclosed in December 2020, only move the needle of our collective attention span for few days at most. The danger is too abstract to take seriously.

But, what about attacks against critical infrastructure? Does a hacker’s attempt to poison a small Florida town’s water supply transform your conception from goofy punchline to legitimate terrorist? It should.

Oldsmar Florida water supply hack

On February 8, 2021, an unknown hacker or hacker group attacked Oldsmar’s water treatment plant[1].  The culprit took control of the treatment plant’s computer system and briefly increased the amount of lye in the water supply from 100ppm (parts per million) to 11,100. Lye is a corrosive chemical used to balance water’s pH, but it can be very harmful or even deadly in the incorrect ratio. Needless to say, a 100-fold rise in the amount of lye would have meant dire consequences for Oldsmar.

Luckily, a plant worker spotted the intrusion immediately and decreased the lye to normal levels quickly so no tainted water made it into the system. Had the plant operator not been on their game, or if the plant was completely automated, it could have been a disaster. Many smaller water treatment plants throughout the United States do not have constant human supervision, and they’re even less likely to have robust cybersecurity defenses.

Currently, the identity of the malicious agent(s) responsible for the attack is unknown. Both the FBI and Secret Service are investigating the matter[2]. Oldsmar is a town of approximately 15,000 people on the Gulf Coast of Florida, so you wouldn’t think it’s exactly a prime target for nation-state actors. Furthermore, the attack was not very sophisticated[3], pointing toward a more inexperienced perpetrator.

Preliminary analysis shows that the hacker accessed the water plant’s computer system via the remote desktop program, Teamviewer[4]. The system ran Windows 7, an older, outdated operating system that Microsoft has not supported with security patches for over a year. This, combined with poor password policies, led to the dangerous breach.

Not the first incident of cyber terrorism

The Oldsmar hack is very frightening but not the first occurrence of cyber terrorism. Here are a few notable past examples.

Israel water supply attack

Water supply attacks didn’t begin with Oldsmar. In May 2020, Israel implicated Iran in an attack on water treatment plants throughout the country. There is a striking similarity to the Oldsmar situation in that the hack’s goal was to change the proportion of chemicals mixed into the water[5]. So had Israel not noticed and foiled the assault, thousands of people could have been harmed.

The Israel-Iran conflict is way beyond this article’s scope, but know that this cyber incident is just one event in a long game of cat-and-mouse between the two archnemeses. With tactics such as these escalating the conflict, hopefully sanity prevails before a catastrophe happens.

Australia targeted by China

In another geopolitical squabble, in June 2020, Australia reported attacks against a variety of its critical infrastructure[6]. While officially unconfirmed, government officials attributed the attacks to China. Power plants, water networks, transportation grids, and communications grids all fell in the crosshairs.

The prevailing explanation for China’s motivation is that Australia put pressure on the communist nation to let an independent research team investigate the origins of the COVID-19 pandemic. This led to increased tensions, with China placing restrictions on trade with Australia and encouraging its citizens not to visit as tourists[7]. Analysts believe the hacks fell into this category of retaliation.

Ukrainian power grid hijacked

When discussing cyberattacks against infrastructure, you can’t leave out the Ukrainian power grid’s hack in December of 2015. Malicious agents infiltrated deep into the control systems of nearly 60 power Ukrainian substations[8]. It cut the power to 230,000 people in the area for between 1-6 hours. It was the first time a hack of a country’s electrical grid resulted in significant power outages. Cybersecurity experts pinpoint Russia as the offenders, and the very next year, they struck again by blacking out a small portion of Kyiv[9].

A look to the future

These situations largely avoided the worst potential consequences of cyber terrorism, can that be counted on forever? The truth is that all countries have vulnerable Industrial Control Systems (ICS) tied to critical infrastructure. The number of vulnerabilities disclosed in 2020 increased by 25% compared to the previous year, and this trend is only expected to continue[10].

There needs to be a national discussion about the prevention of cyber terrorism, as well as the contingency plans required just in case the worst happens. There can’t be a situation where a city’s electrical grid is so compromised that citizens are without power for a significant amount of time. Or where a threat actor successfully poison’s a town’s water supply. If society is not proactive about these scenarios, calamity is inevitable.

