Cyberattacks on US water systems, first disclosed in Minnesota, have now been linked to at least six other states, SecurityWeek reported on August 3. Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers.
What Happened
The attacks have targeted small and mid-sized water utilities, exploiting internet-exposed control systems and unpatched software. The attackers have not, so far, tampered with water treatment, but they have gained persistent access and could have disrupted operations. The FBI and CISA have issued a joint advisory warning water utilities to take immediate defensive action.
"US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States. Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers," SecurityWeek reported.
Why It Matters
Water utilities are a textbook example of critical infrastructure with underfunded cybersecurity. Most US water systems are small, run by municipal authorities with limited IT staff, and operate industrial control systems that were never designed to be connected to the internet. The Iran-linked campaign has highlighted how vulnerable the sector is, and the multi-state scope is a major escalation from the original Minnesota disclosure.
What's Next
The EPA has pledged to provide additional cybersecurity support to water utilities. Several states have begun emergency audits. The federal government is also considering minimum cybersecurity standards for water utilities, similar to the rules already in place for the electricity sector. Critics argue the standards are overdue and that voluntary guidelines are not enough.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.