All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to Geopolitics & Global Risk

CISA confirms over 100 US water systems targeted by hackers

Created at 26 Aug · 2:46 PM1 source↑ Market-relevant
IN SHORT

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported that over 100 internet-exposed systems in the U.S. water and wastewater sector were targeted by cyberattacks in July. While most intrusions had minimal impact on services, some allowed hackers to disable safety processes.

Key Numbers

100+U.S. water and wastewater systems targeted

Who's Involved

CISA
U.S. cybersecurity agency confirming cyberattacks
Iran
Suspected perpetrator of the cyberattacks
Rockwell
Manufacturer of targeted programmable logic controllers
Schneider Electric
Manufacturer of targeted programmable logic controllers
Siemens
Manufacturer of targeted programmable logic controllers
CISA confirms over 100 US water systems targeted by hackers

↳ Why This Matters

The widespread targeting of U.S. water systems highlights significant vulnerabilities in critical infrastructure, raising concerns about national security and public safety. The potential for disabling safety mechanisms underscores the risks posed by state-sponsored cyberattacks.

Key facts

  • CISA confirmed cyberattacks targeting over 100 internet-exposed systems in the U.S. water and wastewater sector in July.
  • The attacks primarily targeted programmable logic controllers (PLCs) used to control physical systems.
  • PLCs from manufacturers including Rockwell, Schneider Electric, and Siemens were affected.
  • Some breaches allowed hackers to disable shutdown processes and alarms, potentially creating unsafe conditions.
  • U.S. officials believe Iran is likely behind the attacks, potentially as retaliation for the conflict against Iran.
  • The intrusions have raised broader concerns about the cybersecurity of U.S. critical infrastructure.
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that over 100 internet-exposed systems within the U.S. water and wastewater sector were targeted by cyberattacks in July. These attacks are part of a broader trend of hacks affecting American critical infrastructure.

    The intrusions largely focused on programmable logic controllers (PLCs), which are crucial for managing physical systems in sectors like water, wastewater, and energy. Manufacturers such as Rockwell, Schneider Electric, and Siemens have had their PLCs targeted. CISA noted that some attacks leverage AI tools to develop scripts that exploit vulnerabilities in Siemens PLCs.

    While the impact on water and wastewater supplies has been minimal, some breaches allowed hackers to disable safety mechanisms like shutdown processes and alarms, potentially creating unsafe conditions without operators' knowledge. Many affected communities are in rural areas where infrastructure disruptions can have a significant impact.

    U.S. officials suggest Iran is likely responsible for these opportunistic attacks, possibly as a response to the ongoing conflict involving the U.S. and Israel against Iran. The incidents have amplified concerns regarding the cybersecurity and resilience of critical infrastructure across the United States. Previous warnings have highlighted state-sponsored hacking activities by China and Russia targeting critical infrastructure.

    Frequently asked questions

    CISA stands for the Cybersecurity and Infrastructure Security Agency, a U.S. federal agency responsible for protecting critical infrastructure from cyber threats.

    PLCs are industrial computers used to automate and control electromechanical processes in manufacturing, water treatment, and other critical infrastructure sectors.

    While most attacks had little effect on water or wastewater supplies, some allowed hackers to disable safety processes like shutdown procedures and alarms, potentially creating unsafe conditions.

    U.S. officials believe Iran is likely behind the attacks, possibly in retaliation for the conflict against Iran.

    What Happens Next

    01Incident responders continue to investigate the breaches.
    02Broader concerns about critical infrastructure cybersecurity are expected to persist.

    How It Developed

    CISA confirmed cyberattacks targeting over 100 U.S. water and wastewater systems.
    Hackers targeted programmable logic controllers (PLCs) from manufacturers like Rockwell, Schneider Electric, and Siemens.
    Some intrusions allowed disabling shutdown processes and alarms, creating unsafe conditions.
    U.S. officials suspect Iran is behind the opportunistic attacks, possibly in retaliation for the conflict against Iran.
    Concerns have been raised about the cybersecurity of U.S. critical infrastructure.

    Sources

    T1
    CISA confirms hackers targeted over 100 US water systems during JulyTechCrunch

    Related Stories

    Iranian attacks caused billions in 'unprecedented damage' to US intelligence sites
    26 Aug · 7:06 AM
    Iran: IAEA cannot inspect attacked nuclear sites without new security protocols
    26 Aug · 3:51 PM
    Iran warns of 'new capabilities' if US sanctions persist
    26 Aug · 6:16 AM
    China vows retaliation for U.S. Iran sanctions
    26 Aug · 2:06 PM
    Russia targets Ukraine petrol stations as Ukraine strikes Russian refineries
    26 Aug · 12:06 AM