US Discloses Attacks on Water Systems and Chinese Hacker Intrusions
U.S. agencies reveal over 100 water systems targeted in July and Chinese state hackers breached federal agencies including the Fed and NASA.
According to TechCrunch, the Cybersecurity and Infrastructure Security Agency (CISA) said in an advisory that the attacks on water systems largely targeted programmable logic controllers (PLCs), which control physical machinery in water, energy and other critical infrastructure. The affected systems span Michigan, Minnesota and at least five other states, officials said.
CISA has observed hackers targeting PLCs made by Rockwell, Schneider Electric and, more recently, Siemens. The agency previously said the intrusions relied in part on AI tools that use public information to develop scripts targeting vulnerable Siemens PLCs. While the attacks had little effect on water supplies, they caused outages and disruption as incident responders investigated, CISA reported. In some cases, hackers modified PLCs to disable shutdown processes and alarms, potentially creating unsafe conditions without operators' knowledge.
Many of the affected communities are in rural or isolated areas, where disruption to critical infrastructure can affect large populations. Citing senior American officials, TechCrunch reported that U.S. intelligence believes Iran is likely behind the largely opportunistic attacks, possibly in response to the U.S. and Israel-led war against Iran, but officials have not made a concrete attribution. The intrusions have raised broader concerns about U.S. critical infrastructure resilience.
Separately, according to CNBC, the DOJ announced on Wednesday morning the seizure of online domains used for hacking platforms known as "QScan and QTRouter," which were used to target U.S. critical infrastructure and other sensitive networks. A court filing said the victims included the Federal Reserve, DOJ, NASA, and networks operated by hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.
The disclosure adds to long-standing U.S. warnings about hacking threats from state actors. U.S. officials have previously warned that Chinese hackers have planted destructive malware on critical infrastructure, ready to activate as a distraction in the event of a Chinese invasion of Taiwan. Russia has also been linked to cyberattacks on water providers and power grids in Europe, seen as aimed at testing the NATO alliance.