Key facts
- CISA confirmed cyberattacks targeting over 100 internet-exposed systems in the U.S. water and wastewater sector in July.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported that over 100 internet-exposed systems in the U.S. water and wastewater sector were targeted by cyberattacks in July. While most intrusions had minimal impact on services, some allowed hackers to disable safety processes.

The widespread targeting of U.S. water systems highlights significant vulnerabilities in critical infrastructure, raising concerns about national security and public safety. The potential for disabling safety mechanisms underscores the risks posed by state-sponsored cyberattacks.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that over 100 internet-exposed systems within the U.S. water and wastewater sector were targeted by cyberattacks in July. These attacks are part of a broader trend of hacks affecting American critical infrastructure.
The intrusions largely focused on programmable logic controllers (PLCs), which are crucial for managing physical systems in sectors like water, wastewater, and energy. Manufacturers such as Rockwell, Schneider Electric, and Siemens have had their PLCs targeted. CISA noted that some attacks leverage AI tools to develop scripts that exploit vulnerabilities in Siemens PLCs.
While the impact on water and wastewater supplies has been minimal, some breaches allowed hackers to disable safety mechanisms like shutdown processes and alarms, potentially creating unsafe conditions without operators' knowledge. Many affected communities are in rural areas where infrastructure disruptions can have a significant impact.
U.S. officials suggest Iran is likely responsible for these opportunistic attacks, possibly as a response to the ongoing conflict involving the U.S. and Israel against Iran. The incidents have amplified concerns regarding the cybersecurity and resilience of critical infrastructure across the United States. Previous warnings have highlighted state-sponsored hacking activities by China and Russia targeting critical infrastructure.