< Back to all clusters
[TECHNOLOGY] · United States · 2 sources

started · updated

United States water systems targeted by cyberattacks

A series of cyberattacks targeting public water systems across the United States has raised significant concerns regarding the security of critical infrastructure. Federal officials suspect hackers potentially linked to Iran are exploiting long-standing vulnerabilities in programmable logic controllers (PLCs). These industrial computers, which regulate essential functions such as pressure, valves, and chemical levels, are often exposed to the internet without adequate firewalls, VPNs, or passwords.

The attacks have impacted at least a dozen states, including Georgia, Michigan, Minnesota, New Jersey, and South Dakota. Specific incidents include an attack on the Clayton County Water Authority in Georgia, which resulted in pressure drops and boil water advisories, and the compromise of over 30 community water systems in Minnesota. In several instances, hackers gained remote access to pumps and valves, forcing operators to revert to manual control.

While water companies have largely regained control, experts warn of severe potential consequences, such as pipe bursts caused by sudden pressure changes that could damage hospitals and other essential infrastructure. The true scope of the damage may be underreported because there is currently no federal mandate requiring water companies to report such breaches.

Entities

CISA · Clayton County Water Authority · Iran · United States