US Alerts on Water System Attacks
CISA and the FBI report a rise in OT attacks on water and wastewater systems, including lockouts and password changes in several states.
CISA and the FBI warned of a significant escalation in attacks against OT devices in U.S. water systems. Reports include operators being locked out of OT networks and malicious changes to passwords and monitoring and control settings.
CISA and the FBI have publicly warned of a significant escalation in attacks against OT devices in U.S. water systems. The incidents include operators being locked out of OT networks and malicious changes to passwords and monitoring and control settings.
What did CISA order water and wastewater utilities to do?
CISA issued a specific alert for water and wastewater utilities and asked them to disconnect PLCs and other control devices from the internet as soon as possible. It also told operators to review their public IP ranges to remove direct exposure of OT.
How far did the recent attacks spread?
The Wall Street Journal and El Imparcial reported that the [recent attacks on water and sewage systems](/en/news/mexico-govt-monterrey-water-hit) affected at least seven U.S. states. The impact reached equipment that controls wells, pumps, and water towers.
What did the attackers do in some cases?
In some cases, attackers changed passwords and network settings, which blocked remote control of the equipment.
Which vendors did the campaign expand toward?
Cybersecurity Dive said the campaign expanded its focus from Rockwell Automation equipment to Schneider Electric and Siemens, suggesting a broader wave of activity against OT. Multiple industrial vendors were hit across water and energy.
The U.S. response also included public calls from CISA for water and wastewater operators to remove internet access from control systems as soon as possible and adopt network segmentation practices. In that coverage, the agency also released a separate advisory on Iranian actors.
International coverage, including The Straits Times and Chinese-language media, echoed that message. The warning reached different media markets with the same emphasis on disconnecting control systems and reducing direct OT exposure.
Sources
- AA23-335A – Actores cibernéticos afiliados a la Guardia Revolucionaria Islámica iraní (IRGC) apuntan a PLC Unitronicscisa.gov· CISA
- US cyber defence agency warns hackers are increasingly targeting water systemsstraitstimes.com· The Straits Times
- Iran‑Linked Actors Infiltrate US Water and Energy Control Systems, Manipulating PLCslivethreat.ai· LiveThreat.ai
- Americas OT/ICS & SCADA Cybersecurityshieldworkz.com· Shieldworkz
- Technical analysis of Iranian Cyber campaigns targeting OT/ICS in water and energy sectorsshieldworkz.com· Shieldworkz
- OT and ICS cybersecurity explained: from industrial plants to utilitiesacronis.com· Acronis
- US authorities see 'significant escalation' in attacks on water system devicescybersecuritydive.com· Cybersecurity Dive
- CISA warns of 'significant increase' in cyber threats to US water utilitieseenews.net· E&E News
- Wave of Hacks Hits U.S. Water Facilitieswsj.com· The Wall Street JournalUnverified URL
- 美多州水務系統遭駭疑與伊朗有關官方籲業者斷網money.udn.com· United Daily News
- Hackers iraníes estarían en la mira por parte de EEUU, luego que se reportara ciberataques a sistema de agua en siete estados del país y alcanzaran equipos que controlan pozos, bombas y torres de aguaelimparcial.com· El Imparcial



