According to the United States Cybersecurity and Infrastructure Security Agency (CISA), over 100 United States water and sewage systems exposed to the Internet were cyberattacked in July. This figure has further clarified the scope of the recent succession of multiple state water systems.

Attack concentrated on PLC equipment

These attacks were aimed primarily at programmable logic controllers (PLCs). Such equipment is widely used to control physical equipment and mechanical systems in critical infrastructure such as water and energy. According to CISA, the equipment that was recently attacked involved several manufacturers, including Rockwell, Schneider Electric and Siemens.

CISA mentioned earlier that part of the attack was based on AI tools. The tools will be used to generate scripts using open information to locate and attack the missing Siemens PLC equipment.

Part of the invasion can change key settings

It appears from the disclosed information that the invasion had a relatively low direct impact on local water supply and sewage treatment services and had not caused widespread disruption of supplies. However, during the incident investigation, a number of systems were shut down and operational disturbances.

CISA also previously stated that some of the invaders had modified the settings of the affected PLC to shut down the shutdown process and alarm functions. This means that the system may become unsafe in the absence of a reminder from the operator.

The geomorphological context has caused more attention.

Many of the affected communities are located in rural or relatively remote areas. Such areas tend to expand rapidly when critical infrastructure is disturbed.

Numerous media outlets have cited senior United States officials as saying that United States intelligence services believe that Iran is likely to be associated with this round of opportunistic attacks on the water system, possibly in the context of the United States-Israeli-led war against Iraq. However, the United States officials have not yet made a clear attribution.

The incident also raised external concerns about the resilience of the United States critical infrastructure network. US officials have warned many times in recent years that Chinese hacker organizations have been accused of pre-empting destructive malware in critical infrastructure; Russia has also been associated with numerous attacks on European water, electricity and energy networks.