Threats

CISA Warns Water Sector

July 31, 2026 04:02 · 12 min read
CISA Warns Water Sector

The US Cybersecurity and Infrastructure Security Agency (CISA) is urging water and wastewater system (WWS) operators to protect operational technology (OT) against malicious activity targeting programmable logic controllers (PLCs).

Coordinated Attacks on PLCs

The alert comes just days after a coordinated cyberattack disrupted automated controls at dozens of water utilities in Minnesota. In an alert published July 30, CISA said it is observing a significant increase in threat actors targeting PLCs in the water and wastewater sector, and urged critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other OT from the internet as soon as possible.

Tactics and Techniques

The agency described specific tactics it has seen against exposed controllers: attackers have modified passwords to lock out operators and disconnected PLCs by changing their IP addresses. According to CISA, the attacks have resulted in “boil water notices” and sustained manual operations that closely mirror what several Minnesota utilities reported this week.

Notably, the alert stressed that the targeting spans water entities of all sizes, and that even organizations with mature cybersecurity programs should validate their external connections. CISA specifically called out cellular modems installed by operators, vendors, or system integrators that may not be documented or captured in routine attack surface scans.

Minnesota Attacks

Minnesota IT Services (MNIT) reported that OT systems at more than 30 community water systems were hit on July 26 and 27. Statements from affected cities, including Maple Plain, Braham, South St. Paul, and Plymouth, indicated that some automated control functions were disrupted, though contingency procedures were activated and water and wastewater operations remained functional in most cases.

The affected cities told residents that drinking water remained safe. State and federal agencies are investigating, and no formal attribution has been made.

Ties to Iranian PLC Campaign

The timing of the Minnesota intrusions is notable, coming shortly after the US government warned critical infrastructure organizations about Iran-linked attacks on industrial control systems made by Siemens, Rockwell Automation, and Schneider Electric.

Investigators have observed activity against Rockwell CompactLogix and Micro850, Schneider Electric Modicon M340, and Siemens S7-1200 series PLCs. Iranian threat groups, including CyberAv3ngers and Handala, fit the profile for attacks on water systems of the kind seen in Minnesota, though investigators have not linked the incidents to any specific actor.

Recommendations for OT Operators

CISA’s core message to the sector is unchanged but increasingly urgent: internet-exposed OT must be secured. The July 30 alert recommends three immediate steps: disconnect the PLC from the internet, enable password protection and change default passwords, and allowlist IP addresses so that remote access is permitted only from known engineering laptops or other critical OT assets.

CISA also advised that, after disconnecting PLCs, operators ensure they have a known-clean backup of the PLC image in case they are locked out by a modified password. Owners and operators of Rockwell Automation MicroLogix 1400 controllers are pointed to Rockwell’s dedicated guidance for restoring access when the password is unknown.

Beyond the immediate steps, utilities are encouraged to review the tactics, techniques, and indicators of compromise in AA26-097A for signs of current or historical activity on their networks.


Source: SecurityWeek

Source: SecurityWeek

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free