READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Over 100 US Water Systems Hit by Hackers Since July. A Kansas Tech Vendor Got Hit Too.

Over 100 US Water Systems Hit by Hackers Since July. A Kansas Tech Vendor Got Hit Too.
CISA now says more than 100 internet-exposed U.S. water and wastewater systems were targeted starting in July, with intelligence officials pointing to Iran without a formal attribution. Separately, the FBI is investigating a ransomware breach at Kansas-based Micro-Comm that officials say is unrelated. Both cases expose the same problem: America hooked critical infrastructure up to the internet without locking the doors.

CISA has confirmed that hackers targeted more than 100 internet-exposed water and wastewater systems across the United States starting in late July, according to an advisory from the agency reported by TechCrunch. That number gives the clearest scale yet to a hacking campaign that's hit water utilities in Minnesota, Wisconsin, and at least five other states.

The targets are programmable logic controllers, or PLCs, the industrial devices that run pumps, valves, and safety alarms at water plants. CISA said hackers have gone after PLCs made by Rockwell Automation, Schneider Electric, and Siemens. On August 19, the agency said the attackers are now using AI-generated exploitation scripts, disguised as legitimate monitoring tools, to find and target vulnerable Siemens S7 controllers, according to a joint advisory from the FBI, NSA, and CISA cited by the Epoch Times.

That advisory called the threat "not theoretical" and listed water and wastewater, energy, chemical, and food and agriculture as the sectors most targeted. It did not name a specific hacker group or country. American officials have told reporters, according to TechCrunch, that intelligence assessments point to Iran as the likely actor behind the water-sector intrusions, probably in retaliation for the U.S. and Israeli military campaign against Iran. This is an assessment, not a formal attribution. No U.S. agency has put a name on the attackers in public.

A cybersecurity firm called Encrygma said on August 19 that a group linked to Iran's Islamic Revolutionary Guard Corps, known as CyberAv3ngers, is behind the water-system attacks, per the Epoch Times. This is one private firm's assessment, not a government finding.

The damage so far

CISA says the intrusions have not contaminated water supplies. But they've caused real disruption. Some attacks forced utilities into sustained manual operations and triggered boil-water notices, according to CISA's advisory cited by the International Business Times. Hackers have also been able to change passwords and IP addresses on internet-facing devices, cutting off operators from monitoring and control systems, per an FBI public-service announcement referenced by IBT. In some cases, hackers modified PLCs to disable shutdown processes and alarms, TechCrunch reported, which could create unsafe conditions without alerting plant operators.

Most of the hit utilities are in rural or isolated communities, where a single water system can serve a large area with limited backup capacity.

The political fight in Minnesota

This isn't just a technical story. It became a political one in July, when President Trump blamed Minnesota's state government for the breach that hit more than 30 municipal water facilities there, according to Breitbart's reporting on NBC News coverage. "I think I blame it on Minnesota because they're grossly incompetent," Trump said, dismissing the Iran theory: "Iran should be so lucky. Iran's got bigger problems than worrying about Minnesota."

Governor Tim Walz pushed back hard: "Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran."

Neither side has the receipts to fully back their claim. Minnesota IT spokesperson Emily Zimmer said there was no indication the breaches contaminated water supplies, but state and federal officials have not publicly named a responsible party. Trump's claim that Minnesota's government is to blame for the intrusion itself isn't supported by anything in the federal advisories, which focus on nationwide PLC vulnerabilities, not state-specific incompetence. Walz's claim that Trump "knows exactly" who's responsible also outruns what CISA and the FBI have said on the record, which is that attribution remains unconfirmed.

A separate breach, a different actor

Layered on top of the state-sponsored concerns is a completely separate incident: a ransomware attack on Micro-Comm, a small PLC manufacturer based in Olathe, Kansas, first reported by Reuters and confirmed by both the company and the FBI. A group calling itself Barracuda claimed responsibility and, on August 6, posted what it said was nearly 850,000 files totaling roughly 644 gigabytes of stolen data.

Micro-Comm co-owner Jim Cote said the company discovered the intrusion on July 31. He told Reuters the leaked files didn't include customer passwords, credentials, or details on how Micro-Comm remotely accesses its equipment. The FBI's Kansas City field office, through spokesperson Dixon Land, confirmed it's investigating and coordinating with other law enforcement agencies.

Cote said the FBI told the company the attack looked opportunistic, not a targeted strike tied to the Iran-linked campaign. Barracuda describes itself as financially motivated, not government sponsored. Micro-Comm told customers in an August 8 newsletter the breach was "in no way related to water system hacks currently being reported on the news."

That distinction matters, but it doesn't make the Micro-Comm breach less relevant. Internet-monitoring firm Censys found roughly 200 of the company's SCADAview CSX systems exposed directly to the internet across U.S. states, according to Reuters. That's the same underlying problem driving the Iran-linked PLC attacks: critical infrastructure equipment sitting online, reachable by anyone who knows where to look.

What happens now

CISA and the FBI have told water operators nationwide to pull PLCs and industrial control systems off the open internet, apply security patches, and tighten monitoring, according to the IBT report. Siemens has updated its own security guidance telling customers to follow those federal recommendations. Whether thousands of small, often underfunded rural water districts have the money or staff to actually do that is the open question nobody in these advisories has answered.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
International Business TimesU.S. Water Systems Are Already Under Cyberattacks. Now A Key Technology Supplier Has Been Hacked Too.
center-left
TechCrunchCISA confirms hackers targeted over 100 US water systems during July
center-left
The IndependentFBI probe into water system cyberattacks expands after tech supplier is targeted
left
The IndependentFBI probe into cyberattacks on US water systems expands after tech supplier is targeted
right
BreitbartFBI Warns of Cyberattacks on Municipal Water Systems Across Seven States
right
Epoch TimesUS Government Says Hackers Attacking Vulnerable Water Systems With AI Help
unknown
WMBD RadioExclusive-Hack of water sector supplier draws FBI scrutiny as Iran-linked cyber concerns grow
unknown
PressBeeFBI probe into cyberattacks on US water systems expands after tech supplier is targeted