- Hackers have targeted exposed programmable logic controllers (PLCs) in water systems, locking out operators and changing IP addresses.
- At least two communities in a state have been targeted, although officials have declined to name the towns.
- The Clayton County Water Authority, which serves 300,000 customers, was hit on July 27, causing a drop in water pressure and a boil-water advisory.
- A Rapid City wastewater plant was targeted in late July.
- CISA issued a July 30 advisory about hackers targeting exposed PLCs.
- The FBI reported that targeted utilities have experienced pressure loss and flooding.
- Utilities have regained control, often by taking systems offline and switching to manual mode.
- U.S. water systems in at least a dozen states have been targeted by the attacks, which officials suspect may be linked to Iran-backed hackers.
- Officials say the attacks have not affected drinking water, and utilities have quickly regained control of their systems.
- Cybersecurity experts warn that the incidents expose longstanding weaknesses in thousands of public water systems, many of which rely on poorly secured, internet-connected industrial computers.
- PLCs are often connected to the internet, allowing hackers to gain access to their functions.
- Security experts noted that sometimes PLCs have no passwords or easily guessed ones.
- Joshua Corman, a security expert, stated that there's no one guarding these systems.
- Michael Garcia mentioned that water systems are targeted because they offer low-hanging fruit for malicious actors.
- There are reports of cyberattacks on water systems in a dozen states, but due to the lack of federal regulation, more may have gone unreported.
Cyberattacks on U.S. water systems have raised alarms as at least a dozen states report incidents linked to Iranian hackers. While officials confirm that drinking water has not been compromised, the attacks reveal critical vulnerabilities in public water systems, many of which utilize poorly secured, internet-connected industrial computers.189
These systems often employ programmable logic controllers (PLCs) that manage essential functions like water pressure and chemical treatments. Unfortunately, many PLCs are directly connected to the internet, making them susceptible to hacking. Joshua Corman, a security expert, emphasized, "The bottom line is there's no one guarding these systems." He noted that many systems lack basic security measures such as firewalls or even passwords.1113
The Cybersecurity & Infrastructure Security Agency (CISA) has highlighted that some PLCs have no passwords or use easily guessed ones, further exacerbating the risk. Michael Garcia, policy director of the Operational Technology Cybersecurity Coalition, pointed out that water systems are targeted because they represent "low-hanging fruit" for cybercriminals. He also noted that the absence of federal regulations means many attacks may go unreported, stating, "There's nothing that requires [utilities] to say, 'Here's all the information that we have.'" The Clayton County Water Authority in Georgia, which serves 300,000 customers, experienced a cyberattack on July 27, resulting in a temporary drop in water pressure and a boil-water advisory, although service was restored quickly.35714
“The attacks have not affected drinking water, and utilities have regained control, but experts warn that hackers could cause pressure surges that burst pipes and endanger hospitals. CISA and the FBI have issued alerts, and officials suspect Iran-backed hackers may be seeking psychological revenge against the Trump administration.”


