Over 100 US water systems were hacked, and that number is the least alarming part

Hackers have found a way to disable alarms and shutdown processes at water facilities without alerting the operators running them. That detail alone should stop you cold. According to TechCrunch, the US Cybersecurity and Infrastructure Security Agency has confirmed that more than 100 internet-exposed water and wastewater systems across the country have been targeted in a wave of cyberattacks, hitting providers in Michigan, Minnesota, and at least five other states.

The attacks have focused primarily on programmable logic controllers, or PLCs. These are the hardware components that actually run physical systems, controlling pumps, valves, chemical dosing, and the automated safety checks that keep water safe. When a PLC is compromised, the damage isn’t just digital. CISA confirmed that some intrusions allowed attackers to modify PLCs in ways that could create what the agency called “unsafe conditions” without triggering any notifications to facility operators. That’s not a data breach. That’s a physical safety failure.

So far, the disruptions haven’t cut off water supplies to communities. But there have been outages, and incident responders have had to investigate active breaches at facilities that often run on skeleton crews. Many of the targeted systems are in rural or isolated areas, where a prolonged outage hits harder and where the resources to respond quickly are thin.

What’s driving the attacks? US intelligence officials believe Iran is likely responsible, treating these incidents as retaliation tied to American and Israeli military pressure on Tehran. The attribution isn’t yet definitive, but the pattern fits. And CISA has noted that attackers are using AI tools that pull from publicly available information to build scripts targeting vulnerable Siemens PLCs, alongside hardware from Rockwell and Schneider Electric.

The broader context matters here. This isn’t a standalone story about water. It sits inside a much larger campaign of attacks on American critical infrastructure. Chinese state hackers have reportedly embedded destructive malware across US infrastructure systems, ready to activate if tensions over Taiwan escalate. Russia has been linked to similar attacks on power grids and water providers across Europe. These aren’t random criminal operations. They’re strategic.

What all of this exposes is a structural problem. Critical infrastructure in the US, especially at the municipal and rural level, has been chronically underfunded when it comes to security. PLCs that were never designed to be internet-connected are now reachable from anywhere in the world. Vendors sell these systems with default credentials and minimal security tooling. And facilities often lack the staff or budget to monitor for intrusions in real time.

CISA can issue advisories. But advisories don’t patch legacy hardware or hire security staff for a small-town water authority running on a tight budget.