The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said it observed cyberattacks targeting more than 100 internet-exposed systems across the U.S. water and wastewater sector, providing the first official scale figure for an ongoing wave of attacks on American critical infrastructure that surfaced publicly in late July.
What CISA Confirmed
In an advisory, CISA said the attacks have largely targeted programmable logic controllers (PLCs), industrial hardware used to control physical equipment and machinery across water providers, energy systems, and other critical infrastructure. In recent weeks, hackers have targeted PLCs made by several manufacturers, including Rockwell, Schneider Electric, and, more recently, Siemens.
CISA said the campaign relies in part on AI tools that draw on public information to generate scripts capable of targeting vulnerable Siemens PLCs, a detail that marks one of the clearer public confirmations of AI-assisted attack tooling being used against U.S. critical infrastructure.
Real-World Impact
The intrusions have had little effect on actual water or wastewater supply to communities, but have caused outages and operational disruption as incident responders investigate the breaches. CISA previously reported that some intrusions allowed hackers to modify affected PLCs to disable shutdown processes and alarms, potentially creating unsafe conditions without alerting the operators running the systems. Many of the affected communities are in rural or isolated areas, where disruption to a single water system can affect a disproportionately large population.
The Iran Connection
The confirmed scale gives new context to attacks that have already hit water providers in Michigan, Minnesota, and at least five other states. Senior American officials, speaking to reporters, have said U.S. intelligence believes Iran is likely behind the largely opportunistic attacks, probably in response to the U.S. and Israel-led military campaign against Iran, though officials have stopped short of a formal, concrete public attribution.
Not an Isolated Threat
CISA’s confirmation lands alongside broader, longer-running warnings about nation-state threats to U.S. infrastructure. Officials have separately warned that China-linked hackers have been planting malware inside U.S. critical infrastructure systems, believed to be positioned for activation as a distraction in the event of a Chinese move against Taiwan. Russia has also been linked to cyberattacks on water providers and power grids across Europe as part of a campaign widely seen as testing NATO’s resilience.
Why It Matters
CISA’s figure, more than 100 targeted systems, is the clearest official quantification yet of how widespread this campaign against U.S. water infrastructure actually is. For water utility operators, many of which are small, locally run systems without dedicated cybersecurity staff, the confirmation that AI tools are being used to identify and target vulnerable equipment raises the urgency of patching and network segmentation for internet-exposed industrial control systems. For policymakers, the scale adds pressure to accelerate funding and support for critical infrastructure cybersecurity, an area that has historically lagged behind sectors like finance and energy in security investment.
What Water Utility Operators Should Do
CISA’s advisory points toward reducing exposure: identifying and disconnecting unnecessarily internet-exposed PLCs, applying available patches from manufacturers including Rockwell, Schneider Electric, and Siemens, and monitoring for unauthorized changes to shutdown and alarm configurations.
For continuing coverage of critical infrastructure cybersecurity and nation-state cyber threats, keep following Tech News Reports for ongoing updates.

