CISA Confirms Cyberattack on Over 100 US Water Systems in July
The U.S. cybersecurity agency CISA has reported a rise in cyberattacks targeting over 100 internet-connected systems in the U.S. water and wastewater sectors, coinciding with a spike in hacks aimed at American critical infrastructure.
This figure highlights the scale of the persistent cyberattacks impacting water service providers in Michigan, Minnesota, and various other states.
CISA, which oversees cybersecurity initiatives and the protection of critical infrastructure, has issued a warning that these attacks mainly target programmable logic controllers (PLCs) used to operate physical systems and machinery across different sectors, including water services and energy systems.
Recently, cybercriminals have focused on PLCs from several manufacturers, including Rockwell, Schneider Electric, and more recently, Siemens. CISA has reported that these cyberattacks partially utilize AI tools derived from public data to generate scripts designed to exploit vulnerabilities in Siemens PLCs.
While the breaches have had limited impact on local water and wastewater supplies, outages and disruptions have occurred as incident response teams investigate these events. CISA previously mentioned that some breaches permitted hackers to modify the functionality of affected PLCs, disabling shutdown protocols and alarms, potentially leading to “unsafe conditions” without notifying the relevant operators.
A substantial number of affected communities are located in rural or remote regions, where interruptions to critical infrastructure can impact a large number of residents.
Reports from high-ranking U.S. officials suggest that intelligence assessments indicate Iran may be behind these largely opportunistic attacks on water providers, possibly as a response to ongoing military actions led by the U.S. and Israel against Iran, though officials have not made an explicit attribution.
These intrusions have raised serious concerns regarding the cybersecurity and resilience of critical infrastructure across the United States.
In recent years, U.S. officials have warned that hackers linked to China have been embedding destructive malware in critical infrastructure, preparing to activate it as a diversion in anticipation of military action against Taiwan. Additionally, Russia has been implicated in multiple cyberattacks on water utilities, as well as power and energy networks throughout Europe, in a campaign seen as testing the NATO alliance.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


