The U.S. cybersecurity agency CISA has reported observing cyberattacks targeting over 100 internet-exposed systems within the U.S. water and wastewater sector during July. These attacks occurred amid a broader wave of hacks affecting American critical infrastructure.
The intrusions primarily focused on programmable logic controllers (PLCs), which are used to manage physical systems and machinery in water providers, energy systems, and other critical infrastructure. Hackers have targeted PLCs made by several manufacturers, including Rockwell, Schneider Electric, and Siemens.
CISA previously stated that AI tools, using public information to develop scripts, were partly used in targeting vulnerable Siemens PLCs. While these intrusions have caused some outages and disruption, they have had little effect on water or wastewater supplies to local communities.
Reports citing senior American officials suggest that U.S. intelligence believes Iran is likely behind these opportunistic attacks, possibly in response to the U.S. and Israel-led war against Iran. However, officials have not made a concrete attribution.