The U.S. cybersecurity agency CISA has reported that over 100 internet-exposed systems in the water and wastewater sector across America have been targeted by cyberattacks this July.
These attacks primarily target programmable logic controllers (PLCs), which control physical systems within these infrastructures, including those found at major water providers and energy networks. Recent investigations suggest that AI tools, based on public data, are being used to target vulnerable Siemens PLCs.
While the intrusions have caused no direct harm to local communities, they have led to outages as incident responders investigate the breaches. CISA has warned that some hackers may modify these controllers to disable shutdown processes and alarms, potentially creating unsafe conditions without operators’ knowledge.
The affected areas are predominantly rural or isolated, impacting a large population when disruptions occur. American officials suspect Iran might be behind many of these opportunistic attacks, possibly as part of retaliation for U.S.-led actions against Tehran.
These incidents raise significant concerns about the cybersecurity and resilience of critical infrastructure across America, with past warnings from U.S. officials suggesting that China and Russia are also targeting similar systems in Europe and elsewhere.







