Cyberattacks on water and wastewater facilities have been reported in at least a dozen US states, with attackers exploiting vulnerabilities in industrial control systems. These attacks, potentially linked to Iranian groups, highlight significant security gaps in the nation's water infrastructure. Minnesota was among the first to report such incidents, revealing that operational technology systems for over 30 water systems were targeted. The Cybersecurity and Infrastructure Security Agency (CISA) has advised critical infrastructure operators to disconnect publicly exposed programmable logic controllers (PLCs) from the internet. These attacks involve modifying PLC passwords and changing IP addresses, effectively locking operators out of their systems. While no disruptions to the water supply have been confirmed, some attacks have forced manual operations and temporary advisories, such as in Georgia, where a water pressure drop led to a boil water advisory.
Municipal water officials from states like Georgia, Michigan, South Dakota, Alabama, and New Jersey have also reported similar attacks. Despite no official attribution, the attacks bear similarities to previous campaigns linked to the Iranian Revolutionary Guard Corps and the CyberAv3ngers group. Experts note that many PLCs lack basic security features, making them vulnerable targets. The decentralized nature and limited cybersecurity resources of most water systems further complicate the situation. Some experts suggest that these attacks might aim to instill fear rather than cause permanent damage, aligning with the tactics of hacktivist groups. However, the lack of claims of responsibility points to a more organized effort. The attacks underscore the urgent need for improved cybersecurity measures in the water sector.


