Government: Water system cyberattacks worse than first reported
Key Points:
- A cyberattack on U.S. municipal water systems that began on July 26 was more extensive than initially reported, with over 100 water providers in 12 states targeted, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
- The attacks involved compromising programmable logic controllers (PLCs) that regulate water valves, flow, and chemical treatment, and are consistent with previous Iranian state-sponsored cyber activities.
- Early reports underestimated the scope, initially citing about 30 affected water systems mainly in Minnesota and a few other states, but CISA's latest alert reveals a broader, nationwide impact.
- Cybersecurity experts highlight that small water utilities often lack the resources to detect such cyber incidents promptly, making them vulnerable targets, especially as hacking tactics become more accessible through AI and shared knowledge.
- Illinois is not listed among the states with reported attacks, but the lack of regulations requiring water systems to disclose cyber incidents means some breaches could go unreported to the public or authorities.