According to the federal agency, the intrusions have impacted facilities in Michigan, Minnesota, and at least five other states, marking a significant escalation in threats against American critical infrastructure.
While the attacks have not caused major disruptions to water supplies, they have forced several providers to deal with outages and service interruptions during the forensic investigation process.
CISA warned that some hackers successfully modified PLCs to disable safety alarms and shutdown protocols, a tactic that could create dangerous conditions without the operators' knowledge.
The agency noted that these vulnerabilities are particularly concerning for rural and isolated communities, where a single infrastructure failure can impact a broad geographic area.
Federal officials and intelligence reports suggest the campaign is likely linked to Iranian actors who are using artificial intelligence tools to develop malicious scripts.
These automated tools help attackers identify and exploit vulnerable hardware manufactured by companies such as Rockwell, Schneider Electric, and Siemens.
This wave of activity follows broader warnings from U.S.
officials regarding foreign malware being planted within domestic energy and water grids, highlighting a persistent effort by international adversaries to test the resiliency of the nation’s utility systems.