Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Tech

US says hackers are targeting vulnerable water systems with the help of AI

Hackers are targeting internet-connected Siemens controllers used in water facilities around the United States.

The United States is warning of hackers targeting vulnerable water systems using artificial intelligence, according to recent reports from cybersecurity agencies. The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) have all issued a joint statement on the growing threat.

The hackers are specifically targeting Siemens S7 programmable logic controllers, which are crucial for controlling automated physical processes in various sectors including energy, water systems, manufacturing, and agriculture.

The agencies emphasize that these attacks could lead to significant disruptions, ranging from downtime to safety incidents or equipment damage in critical infrastructure reliant on these devices. They attribute the attacks to hackers exploiting these devices by using AI to generate exploit scripts based on publicly available information, targeting devices running outdated software or with poor security measures.

CISA has long advised critical infrastructure owners to isolate these devices from the internet, but rural communities are often the most affected due to the extensive coverage of these systems.

An incident response professional familiar with the challenges of securing critical infrastructure pointed out the significance of AI's role in identifying and targeting the vulnerable programmable logic controllers. However, he added a cautionary note, stressing that these devices are inherently vulnerable even without AI intervention.

This warning follows a series of cyberattacks attributed to suspected Iranian hackers targeting U.S. water suppliers and wastewater providers in recent months. These attacks have intensified, following the initial intrusions at internet-connected systems in critical infrastructure. Reports from officials across the U.S. highlight intrusions at facilities in Minnesota, Michigan, Arkansas, Georgia, and New Jersey.

Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techcrunch.com →

More in Tech

More from Thursday 20 August →