US warns of active cyber threat to critical water supply
US agencies warn of an active cyber threat targeting Siemens industrial controllers used in water supply and other critical infrastructure. Hackers are scanning exposed devices and using AI-assisted tools. Recent attacks hit utilities in multiple states, though officials have not formally blamed Iran. The NSA, FBI, Department of Energy, EPA and Cybersecurity and Infrastructure Security Agency described an "active threat" against Siemens S7 Series programmable logic controllers used across factories, energy sites and utilities.
Key Takeaways
- A joint US advisory flags an active threat to Siemens S7 Series PLCs used in water supply and other critical sectors.
- Attackers are scanning the internet for exposed controllers and using AI-generated tools to help gain access.
- Utilities in at least 12 states faced related attacks in late July, including more than 30 community systems in Minnesota.
- Siemens said it has not detected increased attack levels or previously unknown vulnerabilities in its ICS products.
- Federal officials have not formally attributed the water utility incidents to Iran despite suspected links raised by experts.
What happened and why does it matter for water supply?
The warning centers on operational technology that runs physical plant equipment, not just corporate IT networks. According to the advisory, a successful breach could disrupt operations, force facilities offline, damage equipment and create safety hazards. Officials also warned of cascading disruptions across interconnected systems.
The alert follows a wave of cyber incidents against local water systems. Minnesota reported a coordinated campaign of at least 30 incidents on July 26 and July 27. Cybersecurity Dive reported utilities in at least 12 states were impacted, including Michigan, Georgia, South Dakota and New Jersey.
In Georgia, the Clayton County Water Authority said a July 27 attack briefly disrupted OT systems and prompted a boil water advisory before testing confirmed the water supply was safe and service was restored within hours. New Jersey officials said two July incidents involved internet-exposed devices; operators shifted to manual control with no disruption to safe drinking water.
How are hackers targeting Siemens controllers?
Agencies say attackers are scanning for exposed or poorly protected Siemens controllers and using AI-generated tools that reduce the expertise and time needed to exploit industrial systems. The activity appears aimed in part at studying targeted systems and developing the ability to disrupt operations later.
CISA had already flagged a significant increase in PLC-focused attacks in late July and said Iranian-affiliated hackers had been exploiting industrial equipment made by Siemens, Rockwell Automation and Schneider Electric. Earlier reporting also cited Schneider Electric Modicon M340 and Siemens S7-1200 series devices among newly targeted controllers.
Siemens told Fox Business it is aware of the alert and coordinating with CISA. A company spokesperson said Siemens had "not identified increased attack levels or unknown vulnerabilities in Siemens ICS products" and would update customers through its ProductCERT team.
Is Iran behind the water plant breaches?
Cybersecurity experts suspect possible Iran links, and authorities have investigated Iran-nexus groups targeting water and energy systems. A group calling itself APT Iran claimed credit for the Minnesota attacks and said it was working with CyberAv3ngers, according to Check Point Research cited by Cybersecurity Dive.
Federal officials have stopped short of formally blaming Tehran for the July water incidents. President Donald Trump said July 31 that he did not believe Tehran was responsible.
Industry groups are pushing Congress for stronger standards and funding. Operators are being urged to remove devices from the open internet, enable multifactor authentication, change weak passwords and replace end-of-life software. For more infrastructure and market risk coverage, see BlasterPost Fintech & Crypto Alerts.