Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.

Water system vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) says it’s aware of 100 internet-exposed water systems targeted in cyberattacks in July.

The information was shared as part of guidance released by CISA to help organizations reduce the internet exposure of systems that could be targeted by threat actors.

“In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” CISA noted.

Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference

Until now, federal agencies had not publicly quantified the number of systems affected in the recent wave of attacks on water and wastewater utilities.

The water sector attacks, linked to Iranian threat actors, sought to disrupt operational technology (OT) systems. 

Advertisement. Scroll to continue reading.

The government has not said how many states are affected, but it appears there were at least 12 states. Not all of them are known, but states such as Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama have confirmed that they were targeted.

The cyberattacks did not cause any significant disruption, but they have raised concerns about their potential impact on the water sector.

Reducing internet exposure

CISA is urging organizations to aggressively reduce their internet attack surface, with emphasis on operational technology (OT) used in critical infrastructure.

In its updated guidance, the agency recommends first identifying all internet-accessible systems via internal inventories and external scanning tools. Organizations should determine which exposures are truly necessary for operations and remove or restrict the rest. 

For systems that must remain online, CISA advises changing default passwords, applying security updates, routing remote access through secure gateways or jump hosts, enforcing multifactor authentication, and continuously monitoring traffic.

The guidance specifically highlights the risks of leaving PLCs and other industrial control systems (ICS) reachable via cellular modems or the public internet, noting that such exposure has enabled the recent malicious activity against water and wastewater systems. 

Regular reassessments are recommended as networks and third-party connections evolve.

The guidance comes shortly after CISA warned of Iran-linked attacks on ICS made by Siemens, Schneider Electric, and Rockwell Automation.

The agency also urged the water sector to protect OT amid attacks on PLCs.

Related: US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’

Related: Hackers Using AI to Target Siemens PLCs in Critical US Sectors

Related: Iran-Linked Hackers Shut Down UK Power Plant for Four Days

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Trellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.

Mike Marshall has been appointed State Chief Information Security Officer at the California Department of Technology.

Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.