Chemical Plant

Something wicked this way comes: More deaths, chemical releases and cyberattacks on this this nation’s water and chemical infrastructure.

The Chemical Safety Board reports that more workers are getting killed in chemical plants this year:  Thirty-six people died from on-the-job chemical accidents in the US in a recent 11-month period, “the largest number of fatalities ever investigated by the Chemical Safety and Hazard Investigation Board (CSB) in a comparable time period.”

Meanwhile, the US experienced a chemical accident that harmed humans or the environment every other day on average between 2004-2025.

For close observers, this rise in workplace deaths and incidents is no surprise. The Trump administration has filled EPA with “former industry lobbyists, executives, and attorneys who have spent their careers attacking protections covering everything from water quality to greenhouse gas emissions to toxic chemicals.”

And they are in the process of finalizing a new EPA chemical plant safety regulation that would significantly weaken protections the Biden administration issued in 2024 (which followed an Obama administration modernization that was repealed by Trump 1.0). The fact that Trump has stopped the stronger Biden rule from coming into effect, the weakened new proposal and enforcement rollbacks at EPA and OSHA send a loud and clear message to the chemical industry that the watchdogs are no longer watching.

A recent report by the Environmental Integrity Project (EIP) shows the Trump EPA has initiated a record low number of actions against polluters, compared to past administrations, even compared to Trump’s first term. Meanwhile, the number of OSHA inspectors is at its lowest level in the agency’s history..

But all that is not what’s most alarming: the nation has noted a much more troubling problem with our infrastructure, potentially including refineries and chemical plants — cyberattacks.

In June, Minnesota water facilities that are connected to the internet have recently experienced a “coordinated cyberattack” that targeted operational technology at more than 30 Minnesota community water systems. But the attacks weren’t limited to Minnesota. Attacks were also reported in Georgia, New Jersey and Michigan. The FBI confirmed that they are conducting investigations in at least seven states where water and wastewater facilities have experienced similar attacks. There are more than 150,000 water and wastewater treatment systems in the U.S., so the potential for catastrophe is huge.

The suspected culprit is Iran – this time around.

It wouldn’t be the first time nation-states have disrupted critical services for geopolitical reasons. Starting in 2015, Russia notably launched a series of cyberattacks on Ukrainian power grids, plunging residents into darkness before ever launching a full-scale invasion.

Iranian-linked hackers have gone after U.S. power and water before.

For example, in 2023, an Iranian-linked hacktivist group broke into and defaced industrial machines in a water facility in Aliquippa, Pa. The machines, some of whose components were made in Israel, were manipulated to display anti-Israel messages during the war between Israel and Hamas.

But there may be a far bigger problem brewing than just contaminated water  — one that stems largely from Trump’s disastrous war in Iran and the general influence of the chemical industry on American politics.

A Little History

Following the 9/11 attacks almost 20 years ago, the country became more aware of the vulnerability of the nation’s chemical plants to sabotage.  And this was no small concern. Today, over 177 million Americans live in worst-case scenario zones near chemical facilities.  And although “environmental justice” is being attacked by the Trump administration as “woke,” the fact is that a disproportionate number of the millions in greatest danger from a chemical accident are Black, Latino or low income. Some 12,000 schools sit within a mile of one of these facilities.

A struggle between the corporate chemical industry and more environmentally conscious citizens and politicians broke out between those who felt that the best way to protect chemical facilities was more armed guards, higher fences, louder alarms and more ferocious guard dogs —  and those who believed that the way to protect citizens living near chemical plants and plant workers was to reduce the hazard in the plants.

I explained the logic  almost twenty years ago while the battle over chemical plant safety was raging,

As outlaw Willie Sutton explained, they robbed banks because that’s where the money was. Terrorists would be tempted to attack chemical plants because that’s where the greatest potential for terror is. Take the money out of the banks — or the catastrophic potential out of chemical plants — and no one cares.

That logic seemed to make sense to everyone for a while. Shortly after 9/11, then New Jersey Senator Jon Corzine (D-NJ) introduced legislation that would have forced the chemical industry to implement, where possible, inherently safer technologies (e.g. substituting safer chemicals, storing smaller amounts of hazardous chemicals, etc.), along with increased traditional security measures. Reducing chemical hazards in the plants, Corzine and environmental groups argued, not only reduced the threat of terrorism, but also reduced the home-grown threat of major chemical plant disasters, arguably a much bigger threat than terrorism at home or (mythical) weapons of mass destruction in Iraq.

Reducing chemical hazards in the plants, Corzine and environmental groups argued, not only reduced the threat of terrorism, but also reduced the home-grown threat of major chemical plant disasters, arguably a much bigger threat than terrorism at home or (mythical) weapons of mass destruction in Iraq.

The bill was passed unanimously by the Senate committee. But then the American Chemistry Council (formerly the Chemical Manufacturers Association) woke up and invested millions to convince their clients in Congress to kill Corzine’s bill, suggesting instead an legislation that focused almost entirely on traditional security (guns, guards and gates), and relies on compliance with voluntary guidelines — developed by the American Chemistry Council. They argued that mandating any kind of inherently safer technologies would drive the American chemical industry out of business, but never fear: they assured us that refineries chemical plants were already taking care of the problem.

The other argument raging at that time was who would take responsibility for chemical plant security: The Environmental Protection Agency or the newly founded Department of Homeland Security.

Well, to make a long story short, the chemical industry won.  Corzine’s bill was killed, inherently safer chemicals and technologies were put on the shelf, and Homeland Security was given the responsibility to protect our chemical plants against terrorism. And to make matters worse, the right of surrounding communities to know what hazardous chemicals are being used in their backyards was curtailed for fear that terrorists would weaponize that knowledge.

In 2007, DHS established a regulatory program called the Chemical Facility Anti-Terrorism Standards (CFATS) which was designed to identify and regulate high-risk facilities that possess certain chemicals of interest (COI) at specific concentrations and quantities. And in 2014, Congress reauthorized and amended the program through the Protecting and Securing Chemical Facilities from Terrorist Attacks Act of 2014. The CFATS regulation applies to facilities across many industries, including chemical manufacturing, storage, and distribution. energy and utilities, agriculture and food, explosives, mining and other facilities that use or store hazardous chemicals. Facilities’ cybersecurity measures are specifically inspected and assessed under the CFATS program.

Unfortunately for chemical plant security, however, the statutory authority for the CFATS program expired on July 28, 2023 and has not been renewed.

One Step Forward, Two Steps Back

Progress in this country generally grows out of disasters. In 2013, an huge ammonium nitrate explosion at West Fertilizer in West, Texas killed 15 people (mostly emergency responders) and destroyed much of the town of West. Responding to that catastrophe, President Obama issued an Executive Order calling on OSHA, EPA and DHS to work together to address chemical plant safety and to update their regulations. OSHA and EPA immediately started work on updating their chemical plant safety regulations. OSHA, tragically unable to issue or update standard in any reasonable timeframe, made a little progress on updating its Process Safety Management Standard (PSM), a standard initially issued in 1992 to protect workers in chemical facilities. EPA got busy updating its Risk Management Program (RMP) regulation which was similar to PSM, but designed to protect the communities surrounding chemical facilities. EPA actually succeeded in issuing a strong regulation updating some parts of its RMP regulation.

But as mentioned above, Trump suspended implementation of the Obama regulations and then replaced them with a weak update. The Biden administration then issued a stronger regulation which included inherently safer technology requirements. That rule has been suspended by the current Trump administration which is on the verge of issuing a replacement regulation that significantly weakens the Biden rule.

“EPA’s objective is deregulation and increasing corporate profits.” — Rick Engler, former CSB Board member

The weakened rule, along with a record drop in EPA enforcement actions, and continuing attempts to eliminate the Chemical Safety Board (CSB) sends a strong message to the chemical industry that the government watchdog is napping rather than watching. They found that the number of EPA enforcement actions in the Trump administration are “87% lower than Obama’s first year of his second term and 76% lower than Biden’s first year. And that’s 81% lower than even the first year of Trump’s first term in 2017.”

As Rick Engler, a chemical safety expert who served on the CSB board under the Obama administration explained, the Trump administration’s goal is not disaster prevention:  “Their objective is deregulation and increasing corporate profits.”

Back to the Present

We began this piece discussing cyber attacks on the nation’s water plants, presumably by Iran.  Sounds scary, but it’s questionable how seriously the Trump administration takes these attacks.  Indications are, not very seriously:

“I blame it on Minnesota because they’re grossly incompetent,” Trump said at a cabinet meeting last Friday at Camp David in Maryland, without providing evidence to support his claims. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota … Iran’s got bigger problems than worrying about Minnesota.”

Tim Walz, the governor of Minnesota, fired back in a post on X: “Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”

Trump may be using the attacks for political purposes, but at least some government agencies are taking the threat to water plants seriously. The Cybersecurity and Infrastructure Security Agency (CISA) recently recommended that water utilities take measures such as disconnecting their controls from the internet, shielding remote access operations behind a VPN or gateway device and improving password protection.  CISA is a DHS agency created in 2018 that protects national critical infrastructure from cyber and physical threats

The good news is that CISA has a number of programs that help chemical facilities against cyberattacks.  The bad news is that like many other government agencies, CISA has faced significant workforce reductions, losing roughly a third of its personnel through restructuring, buyouts, and attrition. And Trump’s proposed fiscal year 2027 budget includes a $707 million cut across programs within CISA in order to eliminate “weaponization and waste.” Compare the relatively small funding for the CISA budget compared with the billions we’re spending chasing non-existent nuclear weapons in Iran.

More Bhopals?

Cyberattacks on water plants are troubling. They can mean water cutoffs and contaminated drinking water. That’s bad, but not as bad as potential cyberattacks on the nation’s chemical plant infrastructure which can result in catastrophic damage to surrounding communities and mass casualties, threatening not just workers in chemical plants, but also surrounding communities at a scale we haven’t seen since Bhopal. Clearly, more guards, guns and dogs aren’t going to protect our chemical infrastructure from cyberattacks.

If you’re looking for something else to keep you awake at night, consider what would happen if foreign actors shut down critical alarms and control instrumentation in a chemical plant.  Below is a summary of the immediate causes of the 2005 BP Texas City refinery explosion that killed 15 workers. (emphasis added)

The isomerization unit was restarted after a maintenance outage. During the startup, operations personnel pumped flammable liquid hydrocarbons into the tower for over three hours without any liquid being removed because critical alarms and control instrumentation provided false indications that failed to alert the operators of the high level in the tower. Consequently, unknown to the operations crew, the tall tower was overfilled and liquid overflowed into the overhead pipe which filled with liquid, rapidly raising the pressure at the bottom. The three pressure relief valves opened for six minutes, discharging a large quantity of flammable liquid to a blowdown drum and stack that overfilled with flammable liquid, which led to a geyser-like release which was not connected to a flare system to safely contain liquids and combust flammable vapors released from the process. The released volatile liquid evaporated as it fell to the ground and formed a flammable vapor cloud which ignited, killing 15 workers.

Now imagine a cyberattack that shuts down critical alarms and control instrumentation at chemical plants and refineries across the country. Imagine if, instead of just flammable vapors igniting and tragically killing 15 workers, the plant’s disabled instruments and alarms were controlling a hydrofluoric acid (HF) process. About 40 refineries across the United States still use HF as part of the process of making gasoline, even though safer alternatives are readily available.

According to the Natural Resources Defense Council, HF can destroy skin, tissue, and bone on contact. Exposing as little as 1 percent of a person’s skin to HF (about the size of one’s hand) can lead to death. When inhaled, HF can fatally damage lungs, disrupt heart rhythms, and cause other serious health effects.

If HF is released into the air from a refinery pipe or vessel at normal atmospheric conditions, its unique chemistry leads it to mix with moisture in the atmosphere, and form a dense, ground-hugging, toxic cloud that can travel for miles. About 19 million people live close enough to an HF refinery that they could become caught in such a deadly cloud. Many more live along the trucking and train routes that bring HF from its sole manufacturing facility in Louisiana to refineries all over the United States.  

The Bottom Line

So what is to be done? Clearly more guns, guards and dogs aren’t going to protect us.

CISA and CFATS have tools to protect chemical plants against cyberattacks, but are they enough?

In 2020, the Government Accountability Office issues a report entitled Critical Infrastructure Protection: Actions Needed to Enhance DHS Oversight of Cybersecurity at High-Risk Chemical Facilities.  The report found that

the CFATS program has guidance designed to help the estimated 3,300 CFATS-covered facilities comply with cybersecurity and other standards, but the guidance has not been updated in more than 10 years, in contrast with internal control standards which recommend periodic review. CFATS officials stated that the program does not have a process to routinely review its cybersecurity guidance to ensure that it is up to date with current threats and technological advances. Without such a process, facilities could be more vulnerable to cyber-related threats.

One recommendation, which GAO says was implemented, directed CFATS “to implement a documented process for reviewing and, if deemed necessary, revising its guidance for implementing cybersecurity measures at regularly defined intervals.”

But other recommendations — such as tracking delivery and performance data for its cybersecurity training, developing a plan to evaluate the effectiveness of its cybersecurity training, maintaining reliable, readily available information about the cyber integration levels of covered chemical facilities and inspector cybersecurity expertise and developing a workforce plan that addresses the program’s cybersecurity-related needs — are all marked as “closed, no longer valid,” because “on July 28, 2023, the statutory authority for the Chemical Facility Anti-Terrorism Standards (CFATS) program to operate  expired.”

That’s reassuring.

Even the American Chemistry Council agrees that threats still remain:

Computer-based automated Industrial Control Systems (ICS) are widely used by chemical companies to manage and operate their facilities. While the ICS technology is normally separated from internet access by non-approved users, cyber hacking into a chemical facility by other means still poses a challenge for our industry. For example, we have seen the frequency of ransomware cyberattacks dramatically increase over the past few years.

And the growing ability of increasingly powerful A.I. systems to crack even the most sophisticated computer safeguard does not instill confidence — especially for those living near a chemical facility. Remember, cyberattacks don’t just need to threaten major facilities to be catastrophic. The West ammonium nitrate explosion showed that even incidents at tiny facilities can wreak widespread destruction and death.

Ultimately, we’re back where we started from: the only effective way to reduce the threat of chemical facilities is a requirement to replace highly hazardous chemicals and processes with inherently safer processes and chemicals.

Ultimately, we’re back where we started: the only effective way to reduce the threat of chemical facilities is a requirement to replace highly hazardous chemicals and processes with inherently safer processes and chemicals. And we need strong regulation and active enforcement of those regulations — elements that are completely missing today.  Given the country’s budget situation and fecklessness of our political leaders, it’s unlikely that EPA, or especially OSHA, will soon be empowered to issue stronger regulatory protections or funded to the extent that it can adequately enforce their regulations across the country.

So where do we go from here? It is clear that the most effective solution to threats at chemical facilities — whether home-grown of the work of foreign actors — is to reduce that hazard at the source. It’s likely that we can never adequately protect all of the HF tanks in the country — and with A.I. that chances of keeping terrorists out of a plants computer systems is increasingly threatened. That means that Congress must mandate, and agencies must issue strong requirements to substitute inherently safer technologies and chemicals where possible.

CSB Board Chair Steve Owens “called the stream of recent accidents that have killed chemical plant workers ‘heartbreaking.’ He noted that most of the victims were workers at a wide range of chemical and related industries but also included two children and their father on a factory visit.

The government has an obligation to fund and equip the EPA and OSHA to address the causes of these deaths. But unless we can reduce the inherent hazards in this country’s refineries and chemical plants, we won’t just have more individual worker deaths to fear, but more Bhopals.

By Jordan Barab

Jordan Barab was OSHA Deputy Assistant Secretary from 2009-2017. He ran AFSCME's health & safety program from 1982-98. He also worked at the House Education and & Labor Committee (2007-2009, 2019-2021) and the Chemical Safety Board.

2 thoughts on “Do Cyberattacks on Water Plants Warn of More Bhopals?”
  1. Jordan, Thank you for this excellent, comprehensive report. Another critical facet of this story is U.S. destruction of Iranian infrastructure in an illegal and immoral war intended to secure the Middle East for the security of our energy supply and U.S. hegemony. How many Iranian refineries, chemical plants, water treatment sites, and storage facilities have U.S. forces bombed so far? How many casualties have resulted? What toxic releases occurred? And are there information sources to figure this out? We know that oil stocks have boomed during the war — are there any data sources to document the U.S. impact on deaths and environmental destruction in the region? Central to stopping these dangers to workers and surrounding communities the U.S. is to stop this war.
    Rick Engler
    Former CSB Board Member, (2015-2020)

  2. Sadly, I believe there will be cyber attacks on chemical plants which could be catastrophic. But no one seems to give a crap about cyber security. They just gutted CISA. This whole administration is incompetent and we are all worse for wear

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from Confined Space

Subscribe now to keep reading and get access to the full archive.

Continue reading