// TECHCRUNCH — INTELLIGENZA ARTIFICIALE
CISA confirms hackers targeted over 100 US water systems during July
U.S. cybersecurity agency CISA said it has observed cyberattacks targeting over 100 internet-exposed systems across the U.S. water and wastewater sector, amid a wave of hacks targeting American critical infrastructure.
The number of affected systems provides new context to the scale of the ongoing cyberattacks targeting water providers in Michigan, Minnesota, and at least five other states.
The federal agency, which oversees cybersecurity defense and critical infrastructure protections, said in an advisory that the attacks have largely targeted programmable logic controllers (PLCs), which are used to control physical systems and machinery across water providers, energy systems, and other parts of critical infrastructure.
In recent weeks, hackers have targeted PLCs made by several manufacturers, including Rockwell, Schneider Electric, and more recently, Siemens. CISA previously said that the cyberattacks are relying in part on AI tools that rely on public information to develop scripts capable of targeting vulnerable Siemens PLCs.
The intrusions have had little effect on water or waste water supplies to local communities, but have resulted in outages and disruption as incident responders investigate the breaches. CISA previously reported that some of the intrusions allowed hackers to modify affected PLCs to disable shutdown processes and alarms, potentially creating “unsafe conditions” without notifying the affected operators.
Many of the affected communities are in rural or isolated areas, where disruption to critical infrastructure systems can affect a large area of people.
Reports citing senior American officials say that U.S. intelligence believes Iran is likely behind the largely opportunistic attacks on water providers, likely in response to the U.S. and Israel-led war against Iran, but officials have fallen short of a concrete attribution.
The intrusions have sparked broader concerns about the cybersecurity and resiliency of critical infrastructure across the United States.
U.S. officials have warned in recent years that hackers working for China have been planting destructive malware on critical infrastructure ready to activate as a distraction in the event of an anticipated Chinese invasion of Taiwan. Russia has also been linked to several cyberattacks on water providers, and power and energy grids, across Europe as part of a growing campaign seen as aimed at testing the NATO alliance.