Coordinated cyberattacks targeting programmable logic controllers have disrupted water systems across at least a dozen U.S. states, exposing critical vulnerabilities in aging infrastructure and weak security protocols.
Key Points
- Attacks began on July 26, affecting over 30 water systems in Minnesota before spreading to at least 12 states.
- Malicious actors, likely linked to Iran, gained control by exploiting internet-connected devices using default or weak passwords.
- The breaches targeted programmable logic controllers (PLCs), which serve as the central nervous system for industrial control systems.
- The Cybersecurity and Infrastructure Security Agency (CISA) had previously issued multiple warnings regarding these specific vulnerabilities.
- Many public water systems struggle to implement security updates due to limited IT staffing and constrained municipal budgets.