The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported observing cyberattacks targeting over 100 internet-exposed systems within the U.S. water and wastewater sector, as stated in a TechCrunch article. This revelation provides context to the scale of ongoing cyberattacks affecting water providers in Michigan, Minnesota, and at least five other states. The attacks have primarily focused on programmable logic controllers (PLCs), which are utilized to manage physical systems and machinery across water providers, energy systems, and other critical infrastructure components [https://techcrunch.com/2026/08/26/cisa-confirms-hackers-targeted-over-100-us-water-systems-during-july/].
CISA’s advisory indicates that recent weeks have seen hackers targeting PLCs manufactured by companies such as Rockwell, Schneider Electric, and Siemens. The agency previously noted that these cyberattacks leverage AI tools to develop scripts capable of exploiting vulnerable Siemens PLCs using publicly available information. Although the intrusions have had minimal impact on water or wastewater supplies to local communities, they have caused outages and disruptions as incident responders investigate the breaches. CISA reported that some intrusions enabled hackers to modify affected PLCs, disabling shutdown processes and alarms, potentially creating “unsafe conditions” without alerting the affected operators. Many of the impacted communities are located in rural or isolated areas, where disruptions to critical infrastructure systems can affect a large population. Reports citing senior American officials suggest that U.S. intelligence believes Iran is likely behind these opportunistic attacks on water providers, possibly in response to the U.S. and Israel-led conflict with Iran, though officials have not provided concrete attribution. The intrusions have raised broader concerns about the cybersecurity and resilience of critical infrastructure across the United States.