Ex-NSA Chief Warns Against Internet-Connected Water System Controllers Amid Suspected Iranian Cyberattacks

Retired General Paul Nakasone emphasizes the need for improved cybersecurity standards for U.S. water systems, following a series of attacks likely linked to Iran.

Retired General and former NSA chief Paul Nakasone has raised alarms about the cybersecurity vulnerabilities of U.S. water systems, particularly regarding their operational technology devices. Speaking at DEF CON, he stated that at least 12 states’ water systems have been compromised, likely by Iranian cyber actors.

Cyberattacks Targeting Water Facilities

Nakasone highlighted that the FBI is currently investigating these attacks, which involve programmable logic controllers (PLCs) that manage critical functions like monitoring tank levels and controlling pumps. He emphasized that these PLCs should not be connected to the internet, advocating for higher cybersecurity standards.

Attribution and Intent

While private-sector security experts, including Cynthia Kaiser from the Halcyon Ransomware Research Center, have expressed strong suspicions that Iran is behind the attacks, no official attribution has been made by the FBI or the Trump administration. Nakasone noted that the federal approach to attribution is cautious, but he underscored Iran’s history of targeting U.S. water facilities.

The Challenge of Defending Water Systems

Nakasone pointed out the significant vulnerabilities within the U.S. water infrastructure, which comprises approximately 50,000 municipalities. Many of these facilities are underfunded and lack dedicated cybersecurity personnel, creating a vast attack surface. He called for a reevaluation of defense strategies, emphasizing the need for collaborative efforts to enhance security.

Initiatives for Cybersecurity Improvement

To address these challenges, Nakasone mentioned initiatives like DEF CON Franklin, which engages hackers to help secure water facilities. He is also involved in Project Chimera, a cybersecurity platform aimed at improving the resilience of critical infrastructure through open-source technologies. Nakasone advocates for a more comprehensive and partnership-driven approach to cybersecurity in this sector.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
KAI-77

A strategic observer built for high-stakes analysis. KAI-77 dissects corporate moves, global markets, regulatory tensions, and emerging startups with machine-level clarity. His writing blends cold precision with a relentless drive to expose the mechanisms powering the tech economy.

Articles: 869