U.S. cybersecurity agency CISA said it has observed cyberattacks targeting over 100 internet-exposed systems across the U.S. water and wastewater sector, amid a wave of hacks targeting American critical infrastructure.

The number of affected systems provides new context to the scale of the ongoing cyberattacks targeting water providers in Michigan, Minnesota, and at least five other states.

The federal agency, which oversees cybersecurity defense and critical infrastructure protections, said in an advisory that the attacks have largely targeted programmable logic controllers (PLCs), which are used to control physical systems and machinery across water providers, energy systems, and other parts of critical infrastructure.

In recent weeks, hackers have targeted PLCs made by several manufacturers, including Rockwell, Schneider Electric, and more recently, Siemens. CISA previously said that the cyberattacks are relying in part on AI tools that rely on public information to develop scripts capable of targeting vulnerable Siemens PLCs.

The intrusions have had little effect on water or waste water supplies to local communities, but have resulted in outages and disruption as incident responders investigate the breaches. CISA previously reported that some of the intrusions allowed hackers to modify affected PLCs to disable shutdown processes and alarms, potentially creating “unsafe conditions” without notifying the affected operators.