ICS/OT

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.

Water system vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) says it’s aware of 100 internet-exposed water systems targeted in cyberattacks in July.

The information was shared as part of guidance released by CISA to help organizations reduce the internet exposure of systems that could be targeted by threat actors.

“In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” CISA noted.

Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference

Until now, federal agencies had not publicly quantified the number of systems affected in the recent wave of attacks on water and wastewater utilities.

The water sector attacks, linked to Iranian threat actors, sought to disrupt operational technology (OT) systems. 

Advertisement. Scroll to continue reading.

The government has not said how many states are affected, but it appears there were at least 12 states. Not all of them are known, but states such as Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama have confirmed that they were targeted.

The cyberattacks did not cause any significant disruption, but they have raised concerns about their potential impact on the water sector.

Reducing internet exposure

CISA is urging organizations to aggressively reduce their internet attack surface, with emphasis on operational technology (OT) used in critical infrastructure.

In its updated guidance, the agency recommends first identifying all internet-accessible systems via internal inventories and external scanning tools. Organizations should determine which exposures are truly necessary for operations and remove or restrict the rest. 

For systems that must remain online, CISA advises changing default passwords, applying security updates, routing remote access through secure gateways or jump hosts, enforcing multifactor authentication, and continuously monitoring traffic.

The guidance specifically highlights the risks of leaving PLCs and other industrial control systems (ICS) reachable via cellular modems or the public internet, noting that such exposure has enabled the recent malicious activity against water and wastewater systems. 

Regular reassessments are recommended as networks and third-party connections evolve.

The guidance comes shortly after CISA warned of Iran-linked attacks on ICS made by Siemens, Schneider Electric, and Rockwell Automation.

The agency also urged the water sector to protect OT amid attacks on PLCs.

Related: US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’

Related: Hackers Using AI to Target Siemens PLCs in Critical US Sectors

Related: Iran-Linked Hackers Shut Down UK Power Plant for Four Days

Related Content

ICS/OT

Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville.

Artificial Intelligence

Atalanta's Argo product is now being used to prove the resilience of Viasat’s satellite communications network.

Artificial Intelligence

A cybersecurity advisory with technical details and recommendations has been written by the NSA, CISA and other agencies.

Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and device takeover.

ICS/OT

CISA has also published several advisories describing vulnerabilities in ICS and other OT products.

Government

The Water Watch Center launched at DEF CON aims to help under-resourced utilities protect their systems against hackers.

ICS/OT

Hackers linked to Iran targeted industrial control systems (ICS) at water facilities in at least a dozen US states.

ICS/OT

CERT.PL said this appears to be the first instance of a private APN being used as an attack vector.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version