CISA Reports Attacks on More Than 100 US Water Systems

The US Cybersecurity and Infrastructure Security Agency (CISA) says it observed cyberattacks against more than 100 internet-exposed systems in the US water and wastewater sector during July. The activity adds scale to a series of incidents affecting water providers in Michigan, Minnesota and at least five other states.
The attacks have largely focused on programmable logic controllers (PLCs), the industrial devices used to control physical equipment and machinery. CISA said recent activity has involved controllers made by several vendors, including Rockwell, Schneider Electric and, more recently, Siemens.
Operational technology is the central target
PLCs sit at the point where digital commands become physical actions in water operations, energy systems and other critical infrastructure. Their exposure to the internet makes them a direct target in this campaign, rather than merely an entry point into conventional office networks.
CISA has said the attacks partly rely on AI tools that use publicly available information to develop scripts capable of targeting vulnerable Siemens PLCs. That detail points to a threat model in which publicly accessible technical material can be assembled into tooling directed at exposed industrial devices.
The agency had also reported that some intrusions let attackers modify affected PLCs to disable shutdown processes and alarms. CISA warned that such changes could create unsafe conditions without notifying the operators responsible for the systems.
Disruption extends beyond water delivery
The intrusions have had little effect on water and wastewater supplies to local communities so far. They have nevertheless caused outages and disruption while incident responders investigate the compromises, creating an operational burden even where service delivery remains largely intact.
The consequences may be especially significant for rural or isolated communities, where a disruption to critical infrastructure can affect a broad area of people. The incidents have also intensified wider concerns about the cybersecurity and resilience of critical infrastructure across the United States.
Attribution remains unconfirmed
Reports citing senior US officials say US intelligence assesses that Iran is likely responsible for the largely opportunistic activity against water providers, potentially in response to the US- and Israel-led war against Iran. Officials have not made a concrete attribution.
The campaign unfolds alongside longstanding official warnings about other threats to infrastructure. US officials have warned that China-linked hackers have planted destructive malware on critical infrastructure for possible use as a distraction during an anticipated invasion of Taiwan. Russia has also been linked to attacks on water providers and power and energy grids in Europe in a campaign viewed as testing the NATO alliance.
Business implication
Water operators and other infrastructure owners should treat internet-exposed PLCs as a priority operational risk: identify exposed devices, assess the integrity of alarms and shutdown processes, and ensure incident response can investigate disruption without losing control of essential services.

