The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert over a sharp surge in malicious cyber activity targeting the nation’s public water and wastewater systems, a critical piece of national infrastructure that serves millions of Americans across the country. The threat actors are specifically targeting programmable logic controllers (PLCs) — the automated industrial computers that manage core operational functions of water systems — and altering access passwords to lock out legitimate system operators, CISA confirmed. These malicious actions have already forced facilities to issue boil water advisories for affected communities and require manual operation of critical treatment and distribution processes while the issue is resolved.
The national alert was triggered by a recent coordinated cyberattack targeting more than 30 small community water systems across the state of Minnesota, which took place earlier this week, according to Minnesota’s state information technology agency. Multiple U.S. law enforcement and national security investigators are currently probing whether the attack can be linked to Iranian-backed threat actors, multiple media outlets have reported, though investigators stress that the attribution remains preliminary and may shift as more forensic data is collected and analyzed. This ongoing assessment comes at a moment of heightened geopolitical tension between the U.S. and Iran amid the ongoing Israel-related conflict in the region and intermittent diplomatic negotiations aimed at de-escalating cross-region strikes. When contacted by the BBC for comment on the reported Iranian connection, CISA declined to confirm any details related to the attribution investigation.
Minnesota IT Services (MNIT) released an official statement confirming that investigators have verified malicious cyber activity targeting the water systems’ information technology infrastructure, but noted that not all of the 30 targeted communities experienced disruptions to their drinking water or wastewater services. “We have provided all relevant intelligence and forensic data to the federal government, which is evaluating this activity within the broader national threat context and is leading ongoing efforts to attribute the attack to a specific threat actor,” John Israel, Minnesota’s chief information security officer, said in the statement.
This latest warning is not the first time federal agencies have flagged the vulnerability of U.S. water infrastructure. CISA and other federal bodies have issued repeated public advisories over the past year warning of potential cyberattacks on water and wastewater systems from foreign threat groups, including actors affiliated with the Iranian government. Back in April, CISA released specific guidance warning that Iranian-aligned hackers were targeting internet-connected operational devices produced by industrial technology firm Rockwell Automation, including the PLCs that are central to water system operations. Earlier in July, CISA updated that advisory to expand the warning to cover connected operational devices manufactured by other major industrial vendors, reflecting the growing breadth of the threat.
Across the United States, there are more than 152,000 public drinking water systems and over 16,000 separate wastewater treatment facilities, according to federal data. CISA has repeatedly emphasized that many of these systems, particularly smaller community operations that lack the budget for robust cyber defense infrastructure, are disproportionately vulnerable to malicious cyber intrusions.
