What could Iran possibly have to do with the Florida Keys’ drinking water?
Turns out, plenty.
Cybercriminals affiliated with Iran are hacking into local water utilities and hijacking their control systems, according to repeated and urgent warnings issued by federal agencies since April.
The Florida Keys Aqueduct Authority has not been hacked and the Keys’ drinking water has not been affected in any way, FKAA executive director Greg Veliz told the Keys Weekly.
“We’re prepared. We’re aware of the threats and the warnings,” said Veliz, who was the city manager of Key West when city hall computers were hit with a ransomware attack. “I’m sensitive about cybersecurity after that, so we implemented security upgrades when I came to FKAA.
“Our IT department believes our risk is low, but they are being vigilant,” said Veliz.
The cyberattacks have occurred in seven states, including Georgia, Michigan and Minnesota, where 30 small-town water facilities were digitally invaded. Federal officials have not said which other states have experienced attacks.
So far, there have been no reports of contamination. The attacks have caused low-pressure flow, boil-water advisories and reported flooding.
The online intruders gain access to a utility by hacking into system controls that are connected directly to the internet. Once in the system, “they have modified passwords and changed IP addresses” to lock out the legitimate operators and take control, states the July 30 advisory from CISA.
The agency has advised all water utilities to disconnect all systems from the internet and switch to manual controls.
“All we do is manual operations,” Veliz said. “We’re prepared. And if everything works as planned, we’re good.”
He reiterated that the aqueduct authority has not been targeted, attacked or hacked, and there have been no effects to the Keys’ water supply.