Fully Operational: Stuxnet 15 Years Later and the Evolution of Cyber Threats to Critical Infrastructure

Defense Posture and Global ThreatsHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection · 2025-07-22 · 119th Congress
The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection convened this hearing to mark the 15th anniversary of the discovery of the Stuxnet malware and examine how cyber threats to US critical infrastructure — particularly operational technology (OT) systems like water, energy, and transportation controls — have evolved since then. Begins at 0:15:15
Transcript
Highlights

Title

Stuxnet at 15: cyber threats to critical infrastructure and OT security

Purpose

The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection convened this hearing to mark the 15th anniversary of the discovery of the Stuxnet malware and examine how cyber threats to US critical infrastructure — particularly operational technology (OT) systems like water, energy, and transportation controls — have evolved since then. The hearing also addressed the pending expiration of the Cybersecurity Information Sharing Act of 2015 and the State and Local Cybersecurity Grant Program, and heard testimony on Iranian, Chinese, and other nation-state threats to OT. Begins at0:15:15

Who spoke

Chairman Andrew Garbarino (R-NY)0:15:15: Opened by describing Stuxnet's history and destruction of roughly 1,000 centrifuges at Natanz0:15:40, cited a 133% surge in Iranian cyberattacks in May-June 20250:18:23, and later questioned witnesses on CISA's effectiveness0:10:53 and reauthorization of CISA 20151:37:51.

Ranking Member Eric Swalwell (D-CA)0:19:35: Congratulated Garbarino on becoming full committee chairman0:19:35, described a joint visit to Lawrence Livermore National Laboratory0:20:31, warned CISA has lost about 1,000 employees to DOGE cuts0:22:36, and later pressed Dr. Gleason on the lapse of Lawrence Livermore's funding agreements with DHS0:59:36.

Ms. Kim Zetter, author/journalist0:26:41: Explained Stuxnet was designed to sabotage, not merely spy on, Iran's Natanz centrifuges0:27:27, and noted that unsophisticated actors like Iran don't need Stuxnet-level skill to cause disruption0:28:38; cited a 2025 CISA alert on a decade-old train braking system flaw with no replacement protocol ready until 20270:31:02.

Mr. Robert Lee, CEO, Dragos0:32:06: Said Dragos tracks over 25 state and non-state actors targeting OT and nine malware families built for industrial systems, including the versatile "Pipedream"0:32:34; testified only about 5% of cybersecurity spending goes to OT versus 95% to IT, and roughly 10% of US OT infrastructure is being monitored1:15:30; said 95-98% of electric and water utilities under $100 million in revenue are below the "cyber poverty line"1:29:13.

Ms. Tatyana Bolton, OT Cyber Coalition0:36:58: Said if CISA 2015's protections lapse, information sharing would drop 80-90%0:39:55; noted most OT owners spend "99 cents of every dollar" on physical rather than cyber security0:39:55; described turf guarding and lack of a single federal point of contact for industry0:49:51.

Dr. Nathaniel Gleason, Lawrence Livermore National Laboratory0:41:48: Described the 2022 discovery of Chinese-manufactured (Dahua) surveillance cameras beaconing to overseas servers found on OT networks of Cyber Sentry partners0:43:39; testified Livermore's CISA funding agreement expired the prior Sunday, halting threat monitoring of deployed sensors0:59:361:00:04; also said the lab's National Risk Management Center agreement expired in March1:32:08.

Rep. Carlos Gimenez (R-FL)0:47:21: Asked whether malware is evolving to defend itself like a biological virus0:47:50; discussed Chinese surveillance cameras found at the Port of Miami-Dade0:52:07; in a second round asked panelists about US offensive cyber capability and the case for a dedicated Cyber Force1:17:011:19:18.

Rep. Wesley Hunt / "Mr. Latrell" (R-TX)0:53:03: Asked witnesses how to scale OT defense recommendations nationally0:53:08; pressed for a single, publicized list of security priorities communities could act on1:21:05.

Rep. Andy Ogles (R-TN)1:04:37: Described vulnerabilities in rural counties and electric/water cooperatives, warning small communities could be hit first in a coordinated attack1:07:44; in a second round emphasized the "cyber poverty line" and need for a cyber force without creating bureaucratic bloat1:29:06.

Rep. Nellie Pou / "Miss MacGyver" (D-NJ)1:23:41: Highlighted critical infrastructure in her district (major airport, port, railroads) and asked about the importance of the State and Local Cybersecurity Grant Program1:24:34, later noting conflicting federal vulnerability guidance1:26:31.

Key moments

Dr. Gleason testified Lawrence Livermore's interagency funding agreement with DHS for the Cyber Sentry program expired "last Sunday," legally halting analysts from monitoring already-deployed sensor data on critical infrastructure networks0:59:361:01:181:02:06.

Ms. Zetter revealed a CISA alert this month about a decade-old train braking protocol flaw — discovered in 2012, initially dismissed by the Association of American Railroads — with a replacement protocol not ready until 2027 at the earliest0:31:020:31:30.

Mr. Lee said Dragos, working with NSA, discovered the "Pipedream" malware — versatile against everything from drones to water and power systems — and coordinated with CISA to warn operators before adversaries could deploy it0:33:000:33:57.

Bolton and Lee both cited conflicting federal OT security guidance: CISA's "top five" controls list reportedly differs from the SANS Institute's five critical controls, leaving local operators uncertain where to start1:15:001:27:34.

Zetter noted that Colonial Pipeline, despite its 2021 shutdown, lacked a CISO and was breached via an unused legacy VPN account and a leaked password, undercutting its CEO's later claim of highly segmented networks1:09:101:10:04.

Gleason described identifying Chinese-manufactured (Dahua) surveillance cameras on multiple Cyber Sentry partners' OT networks, some beaconing to hostile overseas servers and transmitting encrypted video, with capability for backdoor network access0:43:390:44:05.

Bolton estimated 80-90% of federal information sharing would be cut off if CISA 2015 lapses in September0:39:551:35:09.

Lee said Dragos tracks over 25 state/non-state actors targeting OT, but only about 10% of US OT infrastructure is currently monitored, and 95-98% of small electric/water utilities fall below the "cyber poverty line"0:32:341:16:001:29:13.

Gimenez and Lee discussed whether the US should create a dedicated Cyber Force akin to the Space Force; Lee said he now supports it after previously opposing the idea in the Air Force1:19:181:19:48.

Zetter closed by warning that adversaries who previously lacked the will to strike US infrastructure may now have it as tensions with China rise, converging capability and intent for the first time1:42:331:43:02.

Metadata

CommitteeHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection
Chamber / CongressHouse · 119th Congress
Date2025-07-22
TypeHearing
Witnesses
Mr. Robert Lee — Chief Executive Officer and Co-Founder, Dragos, Inc.
Dr. Nathaniel Gleason — Program Leader, Lawrence Livermore National Laboratory
Ms. Kim Zetter — Author and Journalist
Ms. Tatyana Bolton — Executive Director, The Operational Technology Cyber Coalition
Videoyoutube
Transcript270 caption blocks · 15,866 words · 1:43:48 runtime
EventCongress.gov 118444