CISA: 100+ Internet-Exposed U.S. Water Systems Targeted

CISA observed more than 100 internet-exposed water and wastewater systems targeted in July 2026, often via programmable logic controllers tied to cellular modems.

The Cybersecurity and Infrastructure Security Agency reported that more than 100 internet-exposed water and wastewater systems were targeted by malicious cyber activity in July 2026. The intrusions frequently used programmable logic controllers, or PLCs, connected directly to cellular modems to reach operational technology used by utilities.

Federal and state officials said the incidents occurred across multiple states, with at least 12 believed to have been targeted. Minnesota, Michigan, South Dakota, Georgia, New Jersey and Alabama are among the states that confirmed activity. Officials reported no major service disruptions tied to the incidents.

CISA linked the activity to actors associated with Iran and said the intrusions sought access to operational technology rather than consumer data. The agency has previously warned about attacks that targeted PLCs and industrial control system products from Siemens, Schneider Electric and Rockwell Automation.

“In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” the agency wrote.

In updated guidance, CISA advised water utilities and operators to identify all internet-accessible systems using internal inventories and external scans, then remove or restrict any exposures that are not necessary for operations. For systems that must remain reachable, the agency recommended replacing default passwords, applying security updates, routing remote access through secure gateways or jump hosts, enforcing multifactor authentication and continuously monitoring network traffic.

CISA specifically warned about leaving PLCs and other industrial control devices reachable via cellular modems or the public internet, and it recommended regular reassessments of network exposures as internal setups and third-party connections change.

The agency said it is sharing technical details and mitigation advice with affected utilities and state partners and urged operators to report suspected intrusions to federal authorities so investigators can track activity and share defensive measures.

Articles by this author