By

August 6, 2026 / 5:48 PM EDT

/ CBS News

Add CBS News on Google

A wave of cyberattacks targeting U.S. public water systems is heightening concerns about security gaps at utilities, with government officials warning that hackers are exploiting a particularly vulnerable industrial computer, according to security experts.U.S. water systems in at least a dozen states have been targeted by the attacks, which officials suspect may be linked to Iran-backed hackers. Officials say the attacks have not affected drinking water, and utilities have quickly regained control of their systems. But cybersecurity experts said the incidents expose longstanding weaknesses in thousands of public water systems, many of which rely on poorly secured, internet-connected industrial computers.These components, called programmable logic controllers, or PLCs, turn industrial equipment on and off, controlling factors such as water pressure or chemicals added in treatment plants.PLCs are often connected to the internet, allowing hackers to gain access to their functions, the Cybersecurity & Infrastructure Security Agency (CISA) said in a July 30 notice. Sometimes PLCs have no passwords or easily guessed ones, security experts told CBS News. "The bottom line is there's no one guarding these systems," Joshua Corman, executive in residence for public safety and resilience at the Institute for Security and Technology, a security think tank, told CBS News. "These systems were directly on the internet with no firewalls or VPNs or anything, with no passwords set in most cases."Water systems are being targeted specifically because they offer "low-hanging fruit" for malicious actors, said Michael Garcia, policy director of the Operational Technology Cybersecurity Coalition.