Puerto Rico’s water crisis moved to a new phase as rationing began in the San Juan region amid a severe drought that has caused outages and low water pressure across the island for about a year.
Forescout counted 4,407 exposed Rockwell/Allen‑Bradley PLCs worldwide (2,844 in the U.S.) as of Aug. 3, with 22 internet-facing in cities affected by recent water-utility cyberattacks. Attackers could disrupt operations by changing IPs or passwords on already-accessible controllers, even without exploiting a vulnerability; 19 of the 22 exposed units ran firmware susceptible to CVE-2017-16740. Many exposed devices are on large mobile carrier networks (about 70% of U.S. exposed controllers). Authorities advise removing public Internet exposure, enforcing strong authentication, and using VPNs/private networks. A separate recovery advisory exists for resetting affected MicroLogix 1400/1100 PLCs to default and restoring known-good projects, but it requires offline backups. No agency has publicly attributed the campaign yet, and researchers caution that similar configurations could enable broader compromises.
A coordinated cyberattack hit the operational technology behind more than 30 U.S. water systems, including in Minnesota, over July 26–27, forcing some facilities to go offline or operate manually; Minnesota reported no drinking-water quality issues. Investigators say Iranian-affiliated actors are the leading, though not yet confirmed, suspects. The incident underscores vulnerabilities in aging, internet-connected water controls and the cybersecurity gaps facing smaller utilities, prompting CISA and EPA to urge isolating vital systems from untrusted networks and tightening access. Residents should follow official guidance, maintain emergency water, and beware scams as the nation reassesses water-system protections across roughly 170,000 U.S. facilities.
Federal authorities warn that malicious actors have remotely tampered with water- and wastewater-treatment systems, interrupting operations in several states. Investigators, including spy agencies, suspect Iran in at least one case in Minnesota, with attackers reportedly manipulating operating technology like PLCs. The EPA and FBI are warning about vulnerabilities in critical water infrastructure, and the EPA has rolled back some cybersecurity standards following lawsuits, underscoring ongoing risks to U.S. water systems.
Trump blamed Gov. Walz for Minnesota’s water-hacking incidents, while FBI, EPA and CISA warn of a broader campaign likely tied to Iran. Minnesota reports breaches at about 30 community water systems, with advisories urging operators to take vulnerable PLCs offline and issue boil-water notices as investigators examine a growing, multi-state threat to U.S. water infrastructure.
U.S. municipal water systems in at least seven states were hit by cyberattacks this week, with more than 30 Minnesota facilities affected. Hackers reportedly gained remote access to internet-facing devices, changed IP addresses and passwords, and degraded monitoring, but no contamination has been reported. The FBI and EPA issued a public advisory urging utilities to harden defenses—such as isolating PLCs behind secure gateways, enforcing strong passwords, and restricting device communications—while attribution is still under investigation amid concerns of Iran-linked cyber activity.
U.S. intelligence agencies assess Iran was likely behind a coordinated cyberattack on more than 30 Minnesota municipal water systems; the FBI is investigating as U.S.-Iran tensions escalate, with the attack disrupting some operating technology but not cutting water supply.
Fatbergs—mega blockages of fat, oil and wipes—are clogging sewers around the world; UK water firms use AI-powered radar sensors to detect abnormal water levels and trigger responses, while robots are being developed to inspect and clear blockages, aiming to cut spills and keep workers out of dangerous sewers.
A group of hackers linked to Russia's military intelligence unit, Sandworm, known as Cyber Army of Russia Reborn, has claimed credit for targeting the digital systems of water utilities in the United States, Poland, and France, attempting to sabotage critical infrastructure. The group has posted videos on Telegram showing their manipulation of control systems in these utilities, causing disruptions such as overflowing water tanks in Texas and tampering with a small water mill in France. A new report by cybersecurity firm Mandiant has linked Cyber Army of Russia Reborn to Sandworm, raising concerns about the group's aggressive and dangerous actions, which go beyond previous cyberattacks attributed to Sandworm.
Multiple organizations in the United States, including a small water authority in Pennsylvania, were breached by Iran-affiliated hackers who targeted Israeli-made industrial control devices, according to U.S. and Israeli authorities. The FBI, EPA, CISA, and Israel's National Cyber Directorate confirmed the breaches and warned that other industries outside of water facilities, such as energy, food and beverage manufacturing, and healthcare, may also be vulnerable. The hackers, known as "Cyber Av3ngers," are affiliated with Iran's Islamic Revolutionary Guards Corps and have exploited cybersecurity weaknesses, including poor password security and exposure to the internet. The attack highlights the need for improved cybersecurity measures in critical infrastructure sectors.
Multiple water utilities in the US running the same Israeli-made computer system have been breached by hackers, according to federal officials. The cyberattacks, which have targeted less than 10 water facilities, have not caused disruptions or threatened drinking water. The hackers have defaced computer screens in low-level attacks, raising concerns among US officials. US and Israeli authorities have attributed the attacks to hackers affiliated with the Iranian government. Efforts are underway to remove industrial equipment from the internet to prevent further hacks. The US water sector has struggled to address cybersecurity threats due to limited resources.