CISA warns of July cyberattacks on US water utilities

The US Cybersecurity and Infrastructure Security Agency (CISA) is urging water and wastewater utilities to lock down internet-exposed operational technology after a July wave of cyberattacks targeted programmable logic controllers (PLCs) at facilities in multiple states.[1][2][3][10] The agency reports a “significant increase” in threat activity against PLCs used in the Water and Wastewater Systems (WWS) sector and is pressing operators to remove critical controllers and other industrial gear from direct exposure to the public internet.[1][8][9]

The latest alert follows a coordinated campaign in late July that probed at least dozens of community water systems, including more than 30 utilities in Minnesota over a two-day span, according to state officials and incident summaries.[2][4][10] Additional systems in Michigan and other states also reported suspicious activity against their operational technology environments, prompting some utilities to switch to manual operations and, in limited cases, issue precautionary boil-water notices while systems were inspected.[3][4][10] CISA officials said they have not confirmed any incidents of deliberate water contamination but warned that the same access paths used in these intrusions could be leveraged for more disruptive or destructive actions in future campaigns.[1][3][8]

The July activity comes on the heels of a broader campaign in which Iranian-affiliated cyber actors have been exploiting weaknesses in industrial control systems used by water, energy and municipal infrastructure providers.[14][15] In a recent joint advisory, CISA and the FBI described how these actors targeted PLCs and other devices from Rockwell Automation, Schneider Electric and Siemens in an effort to gain control over physical processes, including pumps and chemical dosing systems.[14][15] Security researchers have tied much of this activity to exploitation of CVE-2021-22681, a critical authentication bypass in Rockwell Automation Logix controllers that carries a CVSS v3 score of 9.8 and has been observed in real-world attacks, leading CISA to add it to its Known Exploited Vulnerabilities catalog earlier this year.[5] Federal investigators have not publicly attributed the July water-utility intrusions to a specific group, but officials note that the tactics and targeted technologies closely resemble those seen in the Iranian-linked PLC exploitation campaign.[10][14][15]

CISA and the Environmental Protection Agency have repeatedly warned that internet-exposed human-machine interfaces (HMIs) and PLCs present an easy attack path into critical water infrastructure when left without strong authentication or network segmentation.[6][12] In a prior joint factsheet, the agencies explained that threat actors who find vulnerable HMIs can remotely view system status, change setpoints and potentially disrupt treatment processes if basic safeguards are missing.[6][12] Investigations into recent incidents have found multiple cases where controllers responsible for pumps, valves and chemical dosing were reachable from the public internet, sometimes using default or weak passwords, making them attractive targets for both state-linked and criminal actors.[1][8][11]

In its latest sector-wide alert, CISA is urging water and wastewater utilities to inventory all internet-exposed devices, disconnect PLCs and HMIs from the public web wherever feasible, and move remote access behind virtual private networks protected with multifactor authentication.[1][6][13] The agency also recommends strict network segmentation between corporate IT and operational technology environments, limiting traffic to only the ports and systems required for plant operations, and regularly reviewing firewall rules for unnecessary exposure.[1][11][13] Utilities are being encouraged to enroll in CISA’s free Cyber Hygiene vulnerability scanning services, which can help identify exposed assets and unpatched systems before threat actors do, and to report any suspected anomalous activity to federal partners for investigation and support.[1][13]

The campaign is a particular concern for smaller and rural systems that may lack dedicated security staff and rely heavily on remote access to operate widely distributed facilities.[2][7][10] Regulators and industry groups are warning that July’s incidents highlight how basic cyber hygiene issues—such as leaving industrial controllers directly reachable from the internet or failing to change default credentials—can escalate into national security concerns when they involve critical infrastructure.[1][6][13] As federal agencies continue to investigate the scope of the July attacks and monitor for follow-on activity, water operators are under growing pressure to reduce their internet exposure, close known PLC vulnerabilities and adopt the baseline defenses outlined in CISA’s water-sector guidance.[1][5][13]

References

  1. CISA Urges Water and Wastewater Systems Sector to Protect OT …
  2. US cyber defense agency warns hackers are increasingly …
  3. Sweeping cyberattack on water systems in multiple states …
  4. Cybersecurity Alert: Coordinated Cyberattacks Hit 30+ Water Systems
  5. Minnesota & other US Water Cyber Attacks, CISA AA26-097A
  6. Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems
  7. August 3, 2026 – Cyber Attacks on Water Systems Update
  8. Unspecified threat actors targeting US water systems, CISA warns
  9. Raleigh Water prepared after national cyberattacks on water utility …
  10. Review of the July 2026 Cyberattacks Against U.S. Water and …
  11. CISA Alert: Defending Water Utilities Against Internet- …
  12. Internet-Exposed HMIs Pose Cybersecurity Risks to Water …
  13. [PDF] Top Cyber Actions for Securing Water Systems – CISA
  14. Iranian-Affiliated Cyber Actors Exploit Programmable Logic … – CISA
  15. CISA, FBI warn that Iran-linked hackers are expanding target set for …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply