After the Water Attacks
Last month, attackers reached into water treatment plants across a dozen states and started moving the controls. Some of them found out what happens when you do. I've been thinking about what to say to the people I advise ever since, and I talked through part of it on a recent episode of The Risky Bit, part of Galactic's Threat Aware podcast network.
This letter is the rest of that conversation.
If you're a security advisor or MSP, this letter is yours to use. Update the signature, send it to the business leaders and organizations you work with, and make it your own. That's exactly what it's here for.
We owe you a different kind of conversation than the ones we've been having.
We don't see you as a risk score. We don't think of your company as an attack surface or your people as endpoints. When we push you about patching a controller you’ve run happily for a decade, or about that remote-access tool nobody remembers turning on, we keep picturing the people on the other side of your business. The family that drinks your water. The night-shift operator who trusts that the alarm will sound. The town that assumes someone, somewhere, is paying attention.
For years, when we talked about attacks on critical infrastructure, it landed like a movie plot. Something that happens to other people, in other places, on a screen. We understand why. We didn't always explain it in a way that felt real, and the threat itself stayed politely theoretical. It was easy to nod, agree that it mattered, and move the budget somewhere with a clearer return.
Then came the last few weeks. Attackers reached into the machinery that runs water systems in at least a dozen states. But they didn't steal anything worth reselling. They got in and took hold of the valves and the pumps, the physical things that decide whether clean water makes it to a kitchen tap. In one Minnesota town the plant went dark and people were asked to stop using water until it came back. Nobody was poisoned, and the supply held. But something quieter took a hit. A person somewhere woke up a little less sure that the water was safe, and a little less sure that anyone had it handled.
That feeling is what we've been trying to tell you about all along. Ordinary trust, the kind a person extends to their water supply without thinking about it, is the hardest thing in the world to hand back once it slips. That's what a water system delivers, and that's what this kind of attack is really after.
We want to be careful here, because this is not a told-you-so moment. We take no comfort in being right about this, and we are not keeping score. If it felt abstract before, some of that is on us for describing a valve as a "programmable logic controller" instead of what it is, which is the hand that turns the water on and off.
We would rather build trust by helping than by marking down the date we warned you.
We’re saying it now because the same people have already named where they’re headed next. They’ve said out loud that electricity and transportation are on the list. The grid that keeps a hospital running. The trains and planes carrying people who never imagined their commute or their flight home had anything to do with a software vulnerability. The equipment underneath all of it looks a lot like the equipment that just got hit. If we wait for our own version of the last few weeks before we move, we’ll be reading the same story with our own name in it.
We need to be honest about how we failed to reach you before. We sent the polite warnings. We reached for the scare tactics. We told you the cautionary tale about the other company that wired the money to the wrong account and never saw it again. None of that was wrong, and none of it was enough. So this time we're trying something truer. We're asking you to help us protect real people, because that's what this has always been about, and we should have said it that way from the start.
If you're ready to have that conversation, we are too.
On the same side of the table,
Seth Loe
Chief Security Officer, Galactic Advisors


