The FBI and Environmental Protection Agency issued a joint warning this week after cyberattacks on internet-exposed programmable logic controllers disrupted water and wastewater systems in at least seven U.S. states, forcing some treatment plants to revert to manual operations.
Since July 27, water utility companies across multiple states reported incidents to the FBI, with some facilities experiencing degraded operations. Attackers targeted internet-facing PLCs, modifying passwords to lock out operators and changing IP addresses to disconnect the industrial control systems from their networks.
A Minnesota law enforcement memo revealed that the attackers’ apparent goal was to contaminate drinking water by dropping pipe pressure at treatment facilities. The CISA alert specifically urged water and wastewater utilities to immediately remove all PLCs and operational technology devices from the public internet.
The attacks represent a significant escalation in threats to U.S. critical infrastructure. Water utilities, which often operate with limited cybersecurity budgets and aging control systems, have long been considered vulnerable targets. The widespread nature of the incidents across seven states suggests a coordinated campaign rather than isolated opportunistic breaches.
CISA recommended that utilities inventory and secure all external connections, including cellular modems and vendor-installed links. The agency also urged facilities to enforce multi-factor authentication, strengthen credentials, and rehearse manual operations and recovery procedures in case of future intrusions.
U.S. investigators are examining whether Iran was behind the attacks, according to CBS News. The assessment remains ongoing, but the targeting pattern and technical indicators have drawn comparisons to previous state-sponsored campaigns against American infrastructure.
The incidents come amid growing concern about the security of industrial control systems across the United States. Previous attacks on water infrastructure, including a 2021 incident in Oldsmar, Florida, have highlighted the consequences of inadequate cybersecurity measures at facilities that serve millions of Americans.
With investigations continuing and utilities scrambling to harden defenses, the attacks underscore the urgent need for investment in cybersecurity across the nation’s water sector, where many operators still lack basic protections like network segmentation and multi-factor authentication.
Sources: FBI Advisory, CISA Alert, NBC News Report
Author: Technology Desk
discussion