As a teenager, I could break into critical municipal systems without much effort. I wasn't a master hacker, but I knew where the weak points were—default passwords, unpatched servers, open ports. Attackers don't need genius when defenders leave the doors unlocked.
That's exactly how Iranian-affiliated hackers managed to lock out multiple U.S. water utilities this summer, forcing operators to revert to manual controls. The intrusions weren't sophisticated; they exploited decades-old vulnerabilities. What surprised me wasn't that it happened, but that it took so long. The scariest part is how little technical skill was required to disrupt something as essential as water.
These weaknesses have existed for years, but the ongoing conflict with Iran has accelerated the attacks. Critical infrastructure defense still moves at human speed, while adversaries—now aided by artificial intelligence—operate around the clock. Until the Iran situation is resolved, this attack surface remains open, and water is just the beginning.
The attackers' goal is to undermine public confidence in systems we take for granted: clean tap water, reliable electricity, punctual transit. This is asymmetric warfare—inflicting maximum psychological damage without conventional military engagement. They don't need to breach a bank or cross a border to cause panic; they just need to make people question whether their water is safe to drink.
Water utilities are especially exposed because most are run by local governments with tight budgets competing against schools, roads, and other priorities. The hackers have now written a playbook for what works, and we should expect it to expand from water to other municipal services—power, transit, wastewater. Centralized systems pose hidden risks that make such attacks more damaging.
Meanwhile, AI is outpacing current defenses. Attackers scan horizontally, probing thousands of systems for the same vulnerability at once. Defenders fix vertically, one device at a time. No human security team can match the scale of AI-driven scanning. CISA and the FBI can issue warnings and publish indicators, but a finding doesn't reduce risk—a fix does.
The solution isn't a technological breakthrough. It's treating cyber hygiene as core infrastructure, not an afterthought. Utilities need continuous, automated discovery of every internet-connected device, enforced password and configuration policies, and a refusal to accept unpatched systems as an excuse. Even when vendor patches aren't available, there are often durable mitigations.
The next leap in critical infrastructure security isn't better threat intelligence; it's drastically shortening the time between identifying an exposure and eliminating it. Attackers don't exploit reports—they exploit what we haven't fixed.
The systems that hit more than 30 water utilities relied on the same mundane loopholes I used as a teenager. The uncomfortable truth is that the fix isn't more complex than the attack. It's continuous, pervasive cyber hygiene—starting now. Iran isn't waiting for the war to end before probing for the next vulnerability, and neither should we.
