Decoding the world of cybersecurity

US water-sector targeting exceeds 100 systems

More than 100 internet-exposed systems in the US water and wastewater sector were targeted during July, widening the known scale of recent attacks on operational technology.

US water-sector targeting exceeds 100 systems
Summary
  • CISA says malicious activity targeted more than 100 internet-exposed systems in the US water and wastewater sector during July.
  • The campaign commonly involved exposed programmable logic controllers, while earlier warnings documented active threats to Siemens S7 equipment.
  • The disclosed count describes targeted systems, not 100 confirmed breaches, and public attribution of the wider campaign remains unresolved.

The known scale of a cyber campaign against US water and wastewater infrastructure has widened, with the US Cybersecurity and Infrastructure Security Agency reportedly observing malicious activity targeting more than 100 internet-exposed systems during July.

The new figure adds scale to a threat that CISA had already been tracking through July and August. On 30 July, the agency warned of a significant increase in cyber actors targeting programmable logic controllers, or PLCs, in the water and wastewater sector and urged operators to remove exposed operational technology from direct internet access.

On 19 August, CISA, the NSA, FBI, Department of Energy, and Environmental Protection Agency issued a further advisory focused on an active threat to Siemens S7 Series PLCs. Cyber Insider covered that warning when it was issued.

The agencies said attackers were carrying out reconnaissance and capability development against US Siemens installations, including the use of AI-generated exploitation scripts disguised as legitimate monitoring tools. Critical manufacturing, energy, water and wastewater, chemical, food and agriculture, and commercial facilities were among the sectors identified as targets.

The larger water-sector count now indicates that the problem extends beyond isolated local incidents. PLCs are embedded in physical processes, where a compromise can affect pumps, valves, alarms, pressure, treatment operations, and other equipment depending on the system and configuration.

That does not mean more than 100 utilities lost control of physical operations. The disclosed figure describes targeted internet-exposed systems, while the number of successful compromises and the operational consequences across the wider set remain unclear. Separating attempted access, confirmed compromise, and physical-process impact remains essential when describing attacks against industrial environments.

The US campaign has attracted scrutiny over possible Iranian involvement. Earlier joint advisories have documented Iranian-affiliated actors targeting internet-exposed PLCs, and US officials and security specialists have examined whether the latest activity forms part of the same pattern. Public authorities have nevertheless stopped short of making a definitive attribution for the wider sequence of recent water-system attacks.

The exposure has wider relevance because the underlying industrial technologies are not unique to US utilities. Siemens, Schneider Electric, and Rockwell Automation equipment is deployed internationally, including across European manufacturing, energy, and infrastructure environments. The country-specific campaign therefore sits on top of a much broader architectural issue: operational devices that were designed to manage physical processes but remain reachable through networks that can be discovered and probed remotely.

Industrial control systems also have different recovery constraints from conventional corporate IT. Taking a device offline, resetting a controller, or applying changes can affect a live process, meaning remediation may require coordination between security personnel, engineers, operators, vendors, and safety functions.

That creates a resilience problem even where an attacker produces only limited physical impact. Incident response itself can force downtime, manual operation, additional inspections, and loss of confidence in whether controller logic or configuration can still be trusted.

The latest scale estimate does not establish a new attacker or a new vulnerability. Instead, it changes the understanding of how broadly an already documented campaign has reached. The issue has moved from warnings about exposed industrial controllers to evidence of sustained targeting across a significant number of operational systems.

×