US water systems targeted in cyberattacks across seven states, FBI warns; Iranian hackers suspected
Investigators are probing whether a wave of cyberattacks targeting water and wastewater utilities across the United States is the work of Iranian hackers, CBS cited
Investigators are probing whether a wave of cyberattacks targeting water and wastewater utilities across the United States is the work of Iranian hackers, CBS cited US officials and sources familiar with the incident as saying. While authorities are examining possible Iranian involvement, they cautioned that the attacks have not been definitively attributed and the assessment could change as more technical evidence is collected. Officials are also investigating whether the attackers deliberately attempted to appear Iran-based to exploit heightened tensions between Washington and Tehran. The investigation follows a joint public warning issued by the FBI and the Environmental Protection Agency (EPA), which said malicious cyber actors had targeted internet-connected industrial control systems used by water utilities in at least seven US states, disrupting operations at some facilities.
FBI warns of attacks on critical water infrastructure In a Public Service Announcement issued on July 30, the FBI and EPA said attackers have been exploiting internet-facing Operational Technology (OT) devices, particularly Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers (PLCs). According to the agencies, utilities in at least seven states have reported incidents since July 27, with some attacks degrading water operations. The cyber actors reportedly gained remote access to exposed PLCs and altered device settings, including changing IP addresses and passwords, leaving operators unable to monitor or control key equipment. Although the FBI has so far observed attacks involving the specified Rockwell PLCs, it warned that similar risks may exist for other industrial control systems connected directly to the internet.
How the attacks disrupted water operations The FBI said the attacks affected industrial control systems that manage essential functions within water and wastewater treatment facilities. After compromising internet-facing PLCs, the attackers reportedly Changed device IP addresses and passwords. Locked operators out of monitoring and control systems. Modified PLC project files, with at least one utility reporting discrepancies in ladder logic. Exploited similar third-party network configurations across multiple organizations. The operational impact varied depending on each PLC's role. Some utilities reported Loss of water pressure. Flooding incidents. Reduced visibility into connected equipment. Disruptions to automated operations. The FBI warned that pressure loss in water systems could potentially allow untreated groundwater to seep into drinking water pipelines, creating public health concerns.
