US Alerts on Water System Attacks
CISA and the FBI report a rise in OT attacks on water and wastewater systems, including lockouts and password changes in several states.
CISA and the FBI warned of a significant escalation in attacks against OT devices in U.S. water systems. Reports include operators being locked out of OT networks and malicious changes to passwords and monitoring and control settings.
CISA and the FBI publicly warned of a significant rise in attacks against OT devices used in U.S. water systems. Reports include operators being locked out of their OT networks and malicious changes to passwords and monitoring and control settings.
Disconnecting exposed equipment
In response, CISA issued a specific alert for water and wastewater utilities. The agency urged them to disconnect PLCs and other control devices from the internet as soon as possible, and to review public IP ranges to remove direct exposure of OT systems.
Scope and affected equipment
The Wall Street Journal and El Imparcial reported that recent attacks on water and sewage systems affected at least seven U.S. states. The impact reached equipment that controls wells, pumps and water towers. In some cases, attackers changed passwords and network settings, which blocked remote control of the equipment.
Shift in technical focus
Cybersecurity Dive said the campaign expanded its focus from Rockwell Automation equipment to Schneider Electric and Siemens. That shift points to an evolution in OT targeting, with multiple industrial vendors affected across water and energy.
The official U.S. response also included public calls from CISA for water and wastewater operators to disconnect control systems from the internet as soon as possible and adopt network segmentation practices. In that coverage, the agency also released a separate advisory on Iranian actors.
International coverage from The Straits Times and Chinese-language media repeated the message and showed that the warning spread across different regions, with the same emphasis on disconnecting control systems and reducing direct OT exposure.
Sources
- AA23-335A – Actores cibernéticos afiliados a la Guardia Revolucionaria Islámica iraní (IRGC) apuntan a PLC Unitronicscisa.gov· CISA
- US cyber defence agency warns hackers are increasingly targeting water systemsstraitstimes.com· The Straits Times
- Iran‑Linked Actors Infiltrate US Water and Energy Control Systems, Manipulating PLCslivethreat.ai· LiveThreat.ai
- Americas OT/ICS & SCADA Cybersecurityshieldworkz.com· Shieldworkz
- Technical analysis of Iranian Cyber campaigns targeting OT/ICS in water and energy sectorsshieldworkz.com· Shieldworkz
- OT and ICS cybersecurity explained: from industrial plants to utilitiesacronis.com· Acronis
- US authorities see 'significant escalation' in attacks on water system devicescybersecuritydive.com· Cybersecurity Dive
- CISA warns of 'significant increase' in cyber threats to US water utilitieseenews.net· E&E News
- Wave of Hacks Hits U.S. Water Facilitieswsj.com· The Wall Street JournalUnverified URL
- 美多州水務系統遭駭疑與伊朗有關官方籲業者斷網money.udn.com· United Daily News
- Hackers iraníes estarían en la mira por parte de EEUU, luego que se reportara ciberataques a sistema de agua en siete estados del país y alcanzaran equipos que controlan pozos, bombas y torres de aguaelimparcial.com· El Imparcial



