
US security agencies CISA, FBI, and NSA have issued warnings about a rise in cyberattacks targeting water supply and wastewater systems. According to officials, attackers are using artificial intelligence (AI) to identify vulnerabilities in Siemens S7 Programmable Logic Controller (PLC) devices and launch attacks. Unauthorized access incidents have been reported at water facilities in Minnesota and Michigan, with systems in Arkansas, Georgia, and New Jersey also targeted.
American security agencies have noted an increasing number of cyberattacks targeting water supply and wastewater management systems nationwide. A joint warning released on Wednesday highlighted that all Siemens S7 PLC devices are at risk. These devices are utilized to automate physical process controls in sectors such as energy, water supply, manufacturing, and agriculture. According to the authorities, breaches in these devices could disrupt services, pose security hazards, and potentially cause damage to critical infrastructure equipment.
US officials explain that attackers are using publicly available information and AI-generated ‘exploit scripts’ to seek out and compromise PLC devices running outdated software or lacking adequate security. CISA has described this as part of a broad cyber campaign against American water supply and wastewater systems. Officials indicated that rural communities are particularly vulnerable.
In such areas, water systems often cover extensive geographic regions, meaning disruptions in one system can impact large populations. This warning follows recent months of cyberattacks on US water suppliers and wastewater service providers. Some of these attacks are suspected to have been conducted by hacker groups linked to Iran, as per American intelligence assessments.





