The FBI has issued a warning after water facilities across seven U.S. states reported cyberattack incidents. The coordinated advisory marks an escalation in threats targeting critical infrastructure.
Water treatment and distribution facilities in seven states have been compromised in recent cyberattacks, prompting the FBI to alert operators across the nation to heighten security measures.
The exact number of facilities affected and the scope of the breaches remain under investigation. The FBI did not immediately disclose which states were targeted or whether any service disruptions occurred.
Water infrastructure has emerged as a recurring target for cybercriminals and state-sponsored actors seeking to disrupt essential services. Previous attacks on water systems have ranged from minor operational disruptions to serious threats to public health.
The FBI's warning typically includes indicators of compromise and recommended defensive actions. Officials advise water facility operators to review network access logs, implement multi-factor authentication, and segregate critical control systems from internet-connected networks.
Critical infrastructure operators have faced increasing pressure to bolster cybersecurity defenses. The water sector, which historically operated with limited digital connectivity, now relies on networked systems for treatment, monitoring, and distribution—expanding the attack surface.
The timing of the warning underscores ongoing vulnerabilities in the nation's water supply chain. Cybersecurity experts recommend facilities conduct regular vulnerability assessments, maintain offline backups of operational data, and establish incident response protocols.
Federal agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), coordinate with state and local water authorities on threat intelligence sharing and remediation efforts.
Water facility officials are urged to report suspected cyberattacks to the FBI's Internet Crime Complaint Center and to their state environmental protection agencies. Additional guidance is available through CISA's resources for critical infrastructure protection.
Cyberattacks against hedge funds and private equity firms have been attributed to UNC6671, an extortion group connected to the BlackFile threat actors. The campaign represents an escalating threat to the financial sector.
A Go-based malware distributed through ClickFix attacks is targeting macOS users to steal cryptocurrency, passwords, and Apple Keychain data. The infostealer campaign combines social engineering with credential harvesting.
A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.
Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.