China-Based Hackers Breached Littleton Utility in 2023 Through Zero-Day Flaw
Updated
Updated · CBS New York · Aug 4
China-Based Hackers Breached Littleton Utility in 2023 Through Zero-Day Flaw
2 articles · Updated · CBS New York · Aug 4
Summary
Federal officials told Littleton Electric Light and Water Departments in 2023 that China-based hackers had accessed its systems, exposing a breach the Massachusetts utility says every community should take seriously.
A zero-day vulnerability enabled the intrusion, and managers said the attackers were sophisticated enough to leave few clues, delaying identification until DHS and the FBI helped remove them.
Operational technology running Littleton's electric grid and water infrastructure was not breached, but officials said access there could have disrupted treatment systems or cut water flow.
Littleton has since added multifactor authentication, segmented networks and tightened user permissions, while warning that even small utilities are attractive targets because many still rely on outdated operational technology.
The disclosure comes as U.S. officials stay on alert over water-system cyberattacks in at least 7 states, with investigators suspecting Iran in some recent cases.
With AI accelerating zero-day exploits, can underfunded local water utilities ever realistically defend their aging infrastructure against state-sponsored cyberattacks?
If hackers bypass outdated defenses, how quickly could a compromised water treatment facility poison a local town's drinking supply?
As foreign hackers pre-position inside US infrastructure, are these breaches mere espionage or a ticking time bomb for future physical disruptions?