The Cybersecurity and Infrastructure Security Agency confirmed that hackers targeted over 100 U.S. water systems in July. The attacks are suspected to be backed by Iran.
CISA issued the warning as part of an ongoing wave of cyberattacks targeting critical water infrastructure across the country. The federal cyber agency did not disclose which systems were affected or the extent of any damage.
Water systems are classified as critical infrastructure by the U.S. government. Attacks on these assets raise concerns about potential disruptions to public water supplies and broader national security implications.
The campaign reflects a broader trend of state-sponsored actors targeting essential services. Iran-backed groups have previously conducted reconnaissance and limited intrusions against U.S. critical infrastructure.
CISA recommends water utilities implement network segmentation, multifactor authentication, and continuous monitoring. The agency continues to investigate the scope and impact of the July incidents.
The confirmation marks another significant incident in a series of cyberattacks against American infrastructure this year.
Snowflake is phasing out password authentication for legacy service accounts, requiring organizations to adopt passwordless methods. The real challenge: identifying which accounts exist, who manages them, and what access they hold.
Medical technology company Boston Scientific disclosed a cyberattack that disrupted IT systems and operations worldwide. The company is working to restore normal services.
The FBI has disrupted infrastructure used by Chinese state-sponsored actors to conduct cyber espionage operations. The takedown targeted a technical quartermaster operation that provided reconnaissance, proxy management, and operational routing capabilities.
PeopleFinders has launched Stud or Dud, a new website that allows users to run background checks on potential romantic partners. The service uses the same public data as PeopleFinders.com.