The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that hackers targeted more than 100 internet-exposed systems in the American water and wastewater sector during July. The attacks affected water providers in Michigan, Minnesota, and at least five other states, according to a federal advisory. The disclosure offers new context on the scale of the ongoing campaign against U.S. critical infrastructure.
CISA stated that the intrusions largely focused on programmable logic controllers, or PLCs, which are devices used to manage physical machinery at water utilities, energy facilities, and other critical operations. The hackers targeted PLCs made by Rockwell, Schneider Electric, and Siemens. CISA previously noted that the attackers are using AI tools that pull from public information to build scripts capable of hitting vulnerable Siemens controllers.
The breaches have caused little disruption to water or wastewater supplies for local communities, but they have led to outages and operational hiccups as response teams investigate. In some cases, CISA reported that attackers modified the PLCs to disable shutdown procedures and alarms, which could create unsafe conditions without alerting operators. Many of the affected systems are in rural or isolated areas, where an outage can impact a large population.
U.S. intelligence believes Iran is likely responsible for the attacks, based on reports citing senior American officials. The hackers appear to be acting opportunistically, possibly as retaliation for the U.S. and Israel-led conflict with Iran, though officials have not made a firm attribution. The campaign has raised broader questions about the security and resilience of American critical infrastructure.
The water sector attacks come amid heightened concerns about foreign hacking of U.S. systems. U.S. officials have previously warned that Chinese state-backed hackers have planted destructive malware on critical infrastructure, ready to trigger as a distraction in the event of an invasion of Taiwan. Russia has also been tied to cyberattacks on water providers and power grids across Europe, a campaign seen as testing the NATO alliance.
More cybersecurity news from TechManNews.







