Technology News

CISA confirms hackers targeted over 100 US water systems in July — here’s what we know

Water treatment facility targeted in cyberattack on US critical infrastructure

Federal cybersecurity officials confirmed that hackers targeted more than 100 internet-exposed systems across the U.S. water and wastewater sector during July, shedding new light on the scale of an ongoing campaign that has disrupted utilities in Michigan, Minnesota, and at least five other states. The advisory from the Cybersecurity and Infrastructure Security Agency (CISA) marks the first time the agency has quantified the number of affected systems, which it said have largely been programmable logic controllers (PLCs) — industrial computers that control pumps, valves, and other physical machinery.

In recent weeks, attackers have focused on PLCs manufactured by Rockwell Automation, Schneider Electric, and most recently Siemens. CISA previously disclosed that the intrusions have been aided in part by AI tools that use publicly available information to craft scripts capable of exploiting vulnerable Siemens PLCs. While the attacks have not significantly affected water supplies to local communities, they have caused operational outages and forced emergency response as investigators work to contain the breaches.

Also read: Life360 launches $8 scannable pet tags and 'zoomies alerts' to expand its pet tracking lineup

What the attackers did inside the systems

According to CISA, some of the intrusions allowed hackers to modify affected PLCs to disable shutdown processes and alarms, potentially creating “unsafe conditions” without alerting operators. That level of access is particularly concerning for rural and isolated communities, where a disruption to critical infrastructure can affect a large geographic area and a significant portion of the local population.

The agency has not named the specific utilities or municipalities affected, citing ongoing incident response and security concerns. However, the advisory noted that many of the targeted systems were exposed to the internet without adequate security controls, making them relatively easy entry points for attackers scanning for vulnerable devices.

Also read: Apple's Mac Mini M6 lands at $899 with 4x AI performance boost, ships September 22

Who is likely behind the attacks

Reports citing senior American officials indicate that U.S. intelligence believes Iran is likely responsible for the largely opportunistic attacks, possibly in response to the U.S. and Israel-led war against Iran. Officials have stopped short of a formal, public attribution, but the pattern of targeting — broad scanning of internet-exposed industrial equipment — aligns with prior Iranian cyber operations.

The campaign has reignited broader concerns about the cybersecurity and resiliency of U.S. critical infrastructure. U.S. officials have warned for years that hackers working for China have been planting destructive malware on critical infrastructure, ready to activate as a distraction in the event of an anticipated Chinese invasion of Taiwan. Russia has also been linked to multiple cyberattacks on water providers and power grids across Europe, part of a growing campaign seen as aimed at testing NATO alliance cohesion.

What this means for the water sector and beyond

The scale of the July attacks — more than 100 systems — underscores how vulnerable the water sector remains, despite years of federal warnings and voluntary guidance. Many water utilities, particularly in small and rural communities, operate with limited IT staff and aging industrial control systems that were never designed for internet connectivity.

CISA has repeatedly urged water and wastewater operators to take basic steps: remove internet-facing PLCs, change default passwords, implement multi-factor authentication, and monitor for unusual activity. The agency has also released free cybersecurity assessment tools tailored to the sector.

The attacks also highlight a growing trend of nation-state actors using AI to lower the barrier to entry for industrial exploitation. The use of AI-generated scripts to target Siemens PLCs represents a notable evolution in attack methodology, allowing less sophisticated actors to conduct operations that would previously have required deep expertise.

For consumers, the practical impact so far has been minimal — water quality and supply have largely remained intact. But the disruptions and the potential for unsafe conditions, even if not realized, have forced utilities to divert resources to incident response and hardening. As the investigation continues, CISA has said it will update its advisory with additional indicators of compromise and recommended mitigations.

The coming weeks will likely reveal whether the attacks were a one-off campaign or the beginning of a sustained pressure campaign against U.S. infrastructure. For now, the message from federal officials is clear: the water sector remains a prime target, and the window to secure it before the next wave of attacks is narrowing.

Neelima Kumar

Written by

Neelima Kumar

Neelima Kumar covers technology and artificial intelligence for StockPil, tracking how emerging tech trends intersect with markets and business.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

To Top