IT-PUB NEWS

CISA says hackers hit 100-plus US water systems

27.08.2026 12:03 • Author: IT-PUB

CISA says hackers hit 100-plus US water systems

CISA says attacks on internet-exposed water and wastewater systems targeted PLCs, caused some outages, and hit rural communities especially hard.

CISA says hackers have targeted more than 100 internet-exposed systems across the U.S. water and wastewater sector, giving new scale to a wave of attacks on critical infrastructure.

The incidents stand out not just for the number of affected systems, but because they hit a basic public service communities rely on every day. As IT-PUB News reports, CISA said the attacks have mostly focused on programmable logic controllers, or PLCs — industrial devices that help run physical equipment in water facilities and other infrastructure networks. That makes the issue more than an ordinary cybersecurity story.

PLCs drew the attackers' focus

According to CISA’s advisory, the intrusions have centered on PLCs used by water providers, energy systems, and other critical infrastructure operators. The agency said hackers have recently targeted PLCs made by several manufacturers, including Rockwell, Schneider Electric, and, more recently, Siemens.

CISA previously said the cyberattacks are relying in part on AI tools that use public information to create scripts aimed at vulnerable Siemens PLCs. The agency did not say the attacks were limited to one company or one type of system, but the focus on industrial controllers shows why the incidents matter beyond the cybersecurity field.

These are not consumer apps or routine office systems. They are part of the machinery that controls how physical systems behave, so a successful intrusion can spill into real-world operations.

Limited supply impact, but real disruption

So far, the intrusions have had little effect on water or wastewater supply for local communities. Even so, CISA said the attacks have caused outages and disruptions while incident responders investigate the breaches.

That distinction matters. Based on the agency’s account, the attacks have not led to widespread service failures. But they still forced operators to manage outages, carry out investigations, and face the possibility that equipment had been altered without their knowledge.

CISA previously reported that some of the intrusions allowed hackers to modify affected PLCs in ways that could disable shutdown processes and alarms. The agency said that could create “unsafe conditions” without alerting the operators responsible for the systems.

Rural communities are under heavier strain

The agency also said many of the affected communities are in rural or isolated areas. In those places, even a limited disruption to a water or wastewater system can affect a wide area and leave local officials with fewer resources to respond quickly.

That makes the attacks more than a technical problem. They also test how resilient essential services are outside major cities, where backup options may be limited and a small number of systems may support many residents at once.

The reported scale of the attacks also adds pressure on operators of public infrastructure that may be exposed to the internet and therefore easier for hackers to find. CISA’s warning suggests the risk is not theoretical and that multiple states have been touched by the campaign.

Public attribution remains unsettled

Reports citing senior American officials say U.S. intelligence believes Iran is likely behind the largely opportunistic attacks on water providers. Those reports link the activity to the U.S. and Israel-led war against Iran.

At the same time, officials have not made a concrete attribution. That leaves responsibility unresolved in public, even as the attacks continue to affect systems in Michigan, Minnesota, and at least five other states.

That gap matters because it shapes how governments, utilities, and the public understand the threat. It also affects whether the attacks are viewed as isolated incidents or part of a broader campaign.

Critical infrastructure stays under pressure

The water-sector attacks have also revived broader concerns about the cybersecurity and resilience of U.S. critical infrastructure. CISA’s warning comes against a wider backdrop of state-linked cyber activity that has already put pressure on essential services in other countries and sectors.

U.S. officials have warned in recent years that hackers working for China have been planting destructive malware on critical infrastructure, with the goal of keeping it ready for use as a distraction in the event of an anticipated Chinese invasion of Taiwan. Russia has also been linked to cyberattacks on water providers, as well as power and energy grids across Europe, in what officials have described as a growing campaign testing the NATO alliance.

For water utilities, the immediate issue is practical: whether exposed systems can be secured before attackers cause more serious disruption. For everyone else, the episode is another reminder that the systems behind everyday services can become targets long before most people notice anything is wrong.


Improve SEO for a small/medium business website for $50