CISA Says Over 100 US Water Systems Were Targeted In July, And The Exploits Were AI Written
Key takeaways
- CISA confirmed more than 100 internet exposed systems in the US water and wastewater sector were targeted during July
- Attackers changed Siemens S7 PLC IP addresses and passwords, and in some cases switched off shutdown processes and alarms
- Federal agencies say the tooling used against the utilities was AI generated
Attackers reached programmable logic controllers at US water plants, changed their IP addresses and passwords, and in some cases switched off shutdown processes and alarms. The operators watching those systems saw nothing unusual.
CISA confirmed on 26 August that more than 100 internet exposed systems in the US water and wastewater sector were hit during July. The agency's own wording was that this is not a theoretical risk, it is an active threat.
What a PLC is, and why the CISA water system hack matters
The advisory, issued on 19 August jointly with the FBI, NSA, Department of Energy and EPA, focuses on Siemens S7 series programmable logic controllers. A PLC is a small industrial computer that runs pumps, valves and alarms. It is the thing that decides whether a pump stops when a tank is full.
Turning off an alarm on one of these is not data theft. It creates an unsafe physical condition while the screen in the control room stays green. That is the part worth reading twice.
The AI part
Federal agencies say the tooling used in these attacks was AI generated. Iran linked groups have since widened the target list to include Schneider Electric equipment as well.
This is the clearest example yet of AI lowering the skill floor on the one category of hacking that has physical consequences. It is the same capability curve that produced agents running intrusions on their own initiative, pointed at infrastructure that was never designed to be on the public internet.
The question that applies to everyone else
Most people reading this do not run a water plant. The diagnostic is identical anyway: is it reachable from the internet, and does it still have the default password. That covers your camera, your NAS, your router and anything you forwarded a port to in 2021 and forgot about.
CISA is telling utilities to go and find their own exposed PLCs before someone else does. The domestic version of that exercise takes an afternoon. Our running notes on the KEV catalogue this month and the Gitea flaw worth patching now are a decent place to start if you self host anything.
What to watch next
An OT security coalition has gone to Congress asking for reform. Whether that produces mandatory reporting for the water sector, or another advisory in six months, is the thing to track.