Cyberattacks on U.S. water systems escalate, Iran suspected
Translated from English, summarized and contextualized by DistantNews.
At a glance
- U.S. officials are investigating a series of cyberattacks targeting water and wastewater systems across at least seven states.
- Multiple reports link these attacks to Iran, with the FBI confirming that some activity has degraded water operations, leading to boil water notices and manual system operations.
- The Cybersecurity and Infrastructure Security Agency (CISA) is warning water facilities to disconnect vulnerable internet-connected devices, particularly programmable logic controllers (PLCs), to prevent further exploitation.
Federal and state authorities in the United States are actively investigating a wave of cyberattacks that have impacted water and wastewater systems in at least seven states this week. Reports from various media outlets suggest a connection to Iran.
The FBI confirmed on Thursday that "some of that activity has degraded water operations." The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added that these attacks have forced communities to issue boil water notices and revert to manual operations for their water systems.
some of that activity has degraded water operations
In response, CISA and other agencies are urging water facilities nationwide to enhance their cybersecurity measures. They specifically advise disconnecting vulnerable equipment, such as programmable logic controllers (PLCs), from the internet to mitigate the risk of further attacks. CISA emphasized in an advisory that "threat actors are targeting water entities of all sizes," and even organizations with robust cybersecurity protocols should "validate their external connections."
These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections.
These incidents follow a recent advisory from CISA last week, which warned that "Iranian-affiliated cyber actors" were exploiting PLCs within U.S. critical infrastructure, including water systems. While warnings about Iranian cyber threats have intensified since the U.S. and Israel's actions against Iran in late February, officials have not yet publicly attributed this week's specific water system attacks to a particular threat actor. President Trump, however, dismissed the possibility of Iranian involvement on Friday, while also criticizing leaders in Minnesota, one of the affected states.
PLCs are crucial internet-connected devices used for the remote control and monitoring of industrial operations. In water systems, they are integrated into infrastructure like dams, pumping stations, and treatment facilities. A report from the Canadian Centre for Cyber Security noted that increased internet connectivity expands an organization's "threat surface," making it more susceptible to exploitation by hackers. CISA's advisory detailed that Iranian-affiliated actors have been using third-party software to gain remote access to PLCs, manipulate system data, and potentially cause "unsafe conditions" without alerting operators, bypassing essential safety procedures.
Iranian-affiliated cyber actors were exploiting PLCs across U.S. critical infrastructure, including water systems.
Originally published by Global News in English. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.