CISA: Over 100 US Water Systems Hit in July Cyberattacks
Over 100 US water systems were targeted in July cyberattacks on exposed PLCs, likely by Iran-linked actors, CISA said.
In an advisory, CISA said threat actors targeted programmable logic controllers (PLCs), industrial computers that control water pumps and valves. The attackers modified passwords to lock out operators and changed IP addresses to disconnect the devices, leading to boil water notices and sustained manual operations, the agency reported. The affected utilities span at least a dozen states, mostly small rural systems in Minnesota, Michigan, Georgia, South Dakota and New Jersey, according to The Register.
While CISA has not attributed the campaign to a specific group, The Register said the attacks are widely suspected to be carried out by an Iranian state-sponsored actor. Matt Hartman, chief strategy officer at the Merlin Group and former acting head of cyber at CISA, told The Register that the scale indicates a systemic vulnerability. “More than 100 water systems with internet-exposed assets were hit in a single month, which points to a systemic vulnerability across the sector, not a run of isolated, unlucky targets,” he said. John Gallagher, vice president at OT security firm Viakoo, said that while 100 systems represent about 0.5 percent of U.S. water utilities, the real threat is that these are test runs for a larger-scale attack.
The warning follows a joint advisory from five federal agencies last week, which said attackers are using AI-generated exploitation scripts to compromise internet-exposed Siemens S7 Series PLCs at water, manufacturing, energy and other critical facilities. Cynthia Kaiser, senior vice president at Halcyon Ransomware Research Center and a former FBI cyber division deputy assistant director, told The Register that this appears to be a continuation of the same suite of activity suspected to be affiliated with Iran targeting PLCs. She said adversaries are actively targeting operational technology because these devices underpin essential health, safety and critical infrastructure across society.
CISA urged organizations to keep PLCs off the public internet, route remote access through VPNs or gateways, replace default passwords, enable stronger authentication and restrict access to allowlisted IP addresses from trusted OT systems. “Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations,” the agency wrote.