At least seven US states hit by water facilities hack, CISA urges operators to disconnect from the internet

The US Civilian Cybersecurity Agency, the Cybersecurity and Infrastructure Security Agency (CISA), issued a warning on Thursday, July 30, alerting that cyber attacks on drinking water and wastewater treatment systems have significantly increased recently. They called on all relevant operators across the US to quickly isolate or disconnect industrial control system (OT) devices connected directly to the internet to reduce the risk of hacking.

Two days before this warning was issued, the Minnesota IT Services Agency disclosed that over 30 community water systems in the state experienced “coordinated network attacks” on July 26 and 27.

Following this, the Federal Bureau of Investigation (FBI) stated that at least seven states in the US had reported similar security incidents in water and wastewater treatment companies, with some attacks leading to “degraded water operations.”

While local officials emphasized that water quality has not been directly threatened, these cyber attacks have caused significant disruptions to physical operations.

According to federal agencies and cybersecurity experts’ investigations, hackers mainly targeted industrial control equipment such as Programmable Logic Controllers (PLC) and Human-Machine Interfaces (HMI), manipulating system login passwords maliciously, disrupting remote control functions, forcing some water plants to go offline urgently, and resort to time-consuming manual operations to restore normal water supply system operations.

Some affected communities reported decreased water pressure, equipment malfunctions, and local overflows caused by the attacks. In a few areas, a “Boil Water Notice” was preemptively issued, requiring residents to boil tap water before drinking or cooking to reduce potential risks.

Several US media outlets cited knowledgeable officials indicating that investigators believe the Minnesota attack incident may be related to hacking groups associated with Iran, but as of now, the US government has not officially disclosed the source of the attacks.

Senior cybersecurity experts analyzed that Iranian-affiliated hackers have been continuously targeting critical US infrastructure and PLC devices in recent years, and this recent event shows that attackers are not only attempting to invade information systems but also directly interfere with industrial control equipment, posing higher risks to essential infrastructure like water supply.

Currently, the federal government is assessing and investigating such activities under the overarching national security background.

CISA urges water utilities nationwide to immediately check whether PLCs, HMIs, or other industrial control devices are still directly exposed to the internet and take measures such as network isolation, multi-factor authentication, and strengthened access controls to reduce the likelihood of intrusion.

Amid the ongoing tensions between the US and Iran, with escalating conflicts between the two countries, the US government is actively investigating the source of the attacks and evaluating whether related cyber activities are linked to the current geopolitical situation.