美国供水系统正遭黑客攻击,因安全漏洞:“无人值守这些系统”


2026年8月6日 美国东部夏令时17:48:11 / 哥伦比亚广播公司新闻

撰稿
2026年8月6日 / 美国东部夏令时下午5:48 / 哥伦比亚广播公司新闻

针对美国公共供水系统的一波网络攻击正加剧各界对水务公司安全漏洞的担忧,安全专家表示,政府官员警告称,黑客正在利用一种特别脆弱的工业计算机。

美国至少12个州的供水系统已成为攻击目标,官员们怀疑这些攻击可能与支持伊朗的黑客有关。官员们表示,这些攻击未影响饮用水供应,水务公司已迅速重新掌控其系统。

但网络安全专家表示,这些事件暴露了数千个公共供水系统长期存在的弱点,其中许多系统依赖安全性极差、联网的工业计算机。

这些被称为可编程逻辑控制器(PLC)的组件负责开启和关闭工业设备,控制水厂内的水压或添加的化学药剂等参数。

美国网络安全与基础设施安全局(CISA)在7月30日的一份公告中表示,可编程逻辑控制器通常连接互联网,使黑客能够访问其功能。安全专家告诉哥伦比亚广播公司新闻,有些可编程逻辑控制器甚至没有设置密码,或使用极易被猜到的密码。

“归根结底,无人值守这些系统,”安全智库安全与技术研究所公共安全与韧性驻所执行主任约书亚·科曼告诉哥伦比亚广播公司新闻,“这些系统直接连在互联网上,没有防火墙、虚拟专用网络(VPN)或任何其他防护措施,大多数情况下甚至没有设置密码。”

运营技术网络安全联盟政策主任迈克尔·加西亚表示,供水系统之所以成为特定攻击目标,是因为它们对恶意行为者来说是“唾手可得的目标”。

以下是关于供水系统网络攻击你需要了解的信息。

美国有多少供水系统遭到了攻击?

加西亚表示,已有报告称12个州的供水系统遭遇网络攻击,但由于没有联邦法规要求地方水务公司上报黑客攻击事件,可能还有更多攻击未被披露。

“没有任何规定要求[水务公司]说,‘这是我们掌握的所有信息,攻击是如何发生的’,”加西亚说,“此次披露实际上完全基于自愿,因此我们甚至无法得知攻击是否造成了大规模影响。”

已报告遭入侵的州包括:

  • 佐治亚州: 服务30万用户的克莱顿县水务局表示,其在7月27日遭遇网络攻击。
  • 密歇根州: 一名州官员表示,7月有“少量”社区遭到袭击。
  • 明尼苏达州: 7月下旬,全州超过30个社区供水系统受到影响。
  • 新泽西州: 据当地美国广播公司下属电视台报道,该州至少有两个社区成为网络攻击目标,州官员拒绝透露城镇名称。
  • 南达科他州: 据当地电视台KOTA-TV报道,拉皮德城的一座污水处理厂在7月下旬遭到攻击。

黑客在做什么,他们想要什么?

美国网络安全与基础设施安全局表示,黑客正在攻击暴露在外的可编程逻辑控制器,通过更改其IP地址将操作人员拒之门外并断开设备连接。联邦调查局在7月30日的一份声明中表示,遭攻击的水务公司出现了水压下降和浸水情况。

在佐治亚州克莱顿县,此次中断导致水压下降,迫使该机构发布煮沸水咨询通知。不过,服务在数小时内便恢复了。

一些水务公司失去了关键的远程控制能力,迫使操作人员切换到手动模式。在多起案例中,黑客获得了对水泵、阀门和水压的远程访问权限。

安全专家指出,到目前为止,遭攻击的水务公司已迅速重新掌控其系统,通常是通过断开系统连接并切换到手动控制。但科曼表示,令人担忧的是,黑客可能会造成更严重的中断,例如水压骤增导致管道破裂,并危及包括医院在内的关键设施。

“两到四小时内断水就意味着医院无法运转,”他说,“对水务行业来说,水压下降可能看起来只是不便,但对依赖供水的医院而言,这可能实际上会造成大规模伤亡事件。”

由于无人公开宣称对此次攻击负责,攻击者的目标仍不明确,安全专家表示。

但由于怀疑攻击来自支持伊朗的黑客,他们的行动可能旨在报复美国与伊朗的战争,向特朗普政府传递信息,或威胁在平民中制造恐慌,科曼说。

“这也可以作为向特朗普政府发出的信号,告诉他们‘别惹我们,因为我们已经进入了你的系统’,”他说,“因此这可能是一种威慑。”

民众应该担心吗?

安全专家告诉哥伦比亚广播公司新闻,风险确实存在,但消费者不必恐慌。

“我们很幸运情况没有变得更糟,但这种运气一部分源于我们有优秀的公共水务工作人员,”加西亚说。

加西亚和科曼都建议人们在家中储存一些水,以防发生紧急情况,无论是飓风之类的自然灾害,还是水务系统遭黑客攻击之类的人为事故。

“我总是告诉人们,专注于你能控制的事情,而你能控制的就是做好准备,”加西亚说,“美国联邦紧急事务管理局(FEMA)一直建议,每户家庭每人每天应储备一加仑水,至少维持两到三天。”

科曼指出,消费者还可以备有净水设备,例如LifeStraw净水吸管,以防供水中断。

“做一个应急准备者和为偶尔的中断做合理准备之间有巨大区别,”他说。

本文由阿兰·谢特编辑

America’s water systems are getting hacked amid security gaps: “No one guarding these systems”

2026-08-06 17:48:11 EDT / CBS News

By

August 6, 2026 / 5:48 PM EDT / CBS News

A wave of cyberattacks targeting U.S. public water systems is heightening concerns about security gaps at utilities, with government officials warning that hackers are exploiting a particularly vulnerable industrial computer, according to security experts.

U.S. water systems in at least a dozen states have been targeted by the attacks, which officials suspect may be linked to Iran-backed hackers. Officials say the attacks have not affected drinking water, and utilities have quickly regained control of their systems.

But cybersecurity experts said the incidents expose longstanding weaknesses in thousands of public water systems, many of which rely on poorly secured, internet-connected industrial computers.

These components, called programmable logic controllers, or PLCs, turn industrial equipment on and off, controlling factors such as water pressure or chemicals added in treatment plants.

PLCs are often connected to the internet, allowing hackers to gain access to their functions, the Cybersecurity & Infrastructure Security Agency (CISA) said in a July 30 notice. Sometimes PLCs have no passwords or easily guessed ones, security experts told CBS News.

“The bottom line is there’s no one guarding these systems,” Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology, a security think tank, told CBS News. “These systems were directly on the internet with no firewalls or VPNs or anything, with no passwords set in most cases.”

Water systems are being targeted specifically because they offer “low-hanging fruit” for malicious actors, said Michael Garcia, policy director of the Operational Technology Cybersecurity Coalition.

Here’s what to know about the water system cyberattacks.

How many U.S. water systems have been targeted?

There are reports of cyberattacks on water systems in a dozen states, but because there’s no federal regulation requiring local utilities to report hacks, more may have gone unreported, Garcia said.

“There’s nothing that requires [utilities] to say, ‘Here’s all the information that we have. Here’s how it happened,’” Garcia said. “This [disclosure] has really been on a goodwill basis, so we actually don’t even know the large-scale impact, if there is one.”

Among the states with reported breaches are:

  • Georgia: The Clayton County Water Authority, which serves 300,000 customers, said it was targeted in a July 27 cyberattack.
  • Michigan: A state official said a “small number” of communities were hit in July.
  • Minnesota: More than 30 community water systems across the state were affected in late July.
  • New Jersey: At least two communities in the state were targeted in a cyberattack, with state officials declining to name the towns, according to a local ABC station.
  • South Dakota: A Rapid City wastewater plant was targeted in late July, according to local station KOTA-TV.

What are the hackers doing, and what do they want?

CISA said the hackers are targeting exposed PLCs, locking out operators and disconnecting the devices by changing their IP addresses. In a July 30 statement, the FBI said targeted water utilities have experienced pressure loss and flooding.

In Georgia’s Clayton County, the disruption caused a drop in water pressure and forced the agency to issue a boil-water advisory. Service was restored within hours, however.

Some utilities have lost critical remote-control capabilities, forcing operators to switch to manual mode. In several cases, the hackers gained remote access to pumps, valves and water pressure.

So far, the targeted utilities have swiftly regained control of their systems, often by taking them offline and switching to manual control, security experts noted. But the worry is that hackers could cause greater disruptions, such as a surge in water pressure that could burst pipes and endanger critical facilities, including hospitals, Corman said.

“No water means no hospital in two to four hours,” he said. “A loss of water pressure might look like an inconvenience for the water sector, but it could actually be a mass casualty event for the hospital that depends upon it.”

Because no one has publicly claimed responsibility for the attacks, the attackers’ objectives remain unclear, security experts said.

But with Iran-backed hackers suspected in the incidents, their efforts may be aimed at psychological revenge for the U.S.’s war with Iran, sending a message to the Trump administration or threatening to stir panic among civilians, Corman said.

“It can also be used as a signal to the Trump administration to say, ‘Don’t mess with us because we’re in your systems,’” he said. “So it could be a deterrent.”

Should people be worried?

The risks are serious, but consumers shouldn’t panic, the security experts told CBS News.

“We’re lucky that it wasn’t worse, but part of that luck is because we have good public utility workers,” Garcia said.

Both Garcia and Corman recommended that people store some water at home in case of an emergency, whether that’s a natural disaster like a hurricane or a man-made issue like a utility hack.

“What I always tell folks is focus on what you can control, and what you can control is being prepared,” Garcia said. “FEMA has always said that you should have one gallon of water a day for however many people are in your household for at least two or three days.”

Consumers can also keep a water filtration device on hand, such as a LifeStraw, in case of a water disruption, Corman noted.

“There’s a huge difference between being a prepper and being rationally prepared for occasional disruption,” he said.

Edited by Alain Sherter

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

湘ICP备2026001899号-2