Recent Cyber Attacks on U.S. Water Systems

A Special Report from the National Rural Water Association and CISA

This week, multiple public water systems, including small utilities across several states, have experienced cyber-attacks targeting internet-connected programmable logic controllers (PLCs). The Cybersecurity and Infrastructure Security Agency (CISA) is currently observing a significant increase in the targeting of PLCs located in the water and wastewater sector. While attribution of these attacks remains pending federal investigation, the timing coincides with escalating Iranian-affiliated PLC exploitation activity documented in CISA Advisory AA26-097A.

Targeting of internet-connected operational technology devices at U.S. water and wastewater utilities can cause physical disruptions to utility operations, potentially impacting the public health and economic prosperity of communities.

CISA is urgently recommending that critical infrastructure owners and operators remove exposed PLC devices from the internet. Please note that this exposure includes cellular modems that may be connected to your control systems. To securely enable remote access to your water sites, please see the following guidance: Secure connectivity principles for Operational Technology.

NRWA and State Rural Water Associations are engaging in conversations with federal partners about this issue. If you need assistance, please contact your State Rural Water Association or your local CISA Regional Office.