The Cybersecurity and Infrastructure Security Agency (CISA) says it’s aware of 100 internet-exposed water systems targeted in cyberattacks in July.
The information was shared as part of guidance released by CISA to help organizations reduce the internet exposure of systems that could be targeted by threat actors.
“In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” CISA noted.
Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference
Until now, federal agencies had not publicly quantified the number of systems affected in the recent wave of attacks on water and wastewater utilities.
The water sector attacks, linked to Iranian threat actors, sought to disrupt operational technology (OT) systems.
The government has not said how many states are affected, but it appears there were at least 12 states. Not all of them are known, but states such as Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama have confirmed that they were targeted.
The cyberattacks did not cause any significant disruption, but they have raised concerns about their potential impact on the water sector.
Reducing internet exposure
CISA is urging organizations to aggressively reduce their internet attack surface, with emphasis on operational technology (OT) used in critical infrastructure.
In its updated guidance, the agency recommends first identifying all internet-accessible systems via internal inventories and external scanning tools. Organizations should determine which exposures are truly necessary for operations and remove or restrict the rest.
For systems that must remain online, CISA advises changing default passwords, applying security updates, routing remote access through secure gateways or jump hosts, enforcing multifactor authentication, and continuously monitoring traffic.
The guidance specifically highlights the risks of leaving PLCs and other industrial control systems (ICS) reachable via cellular modems or the public internet, noting that such exposure has enabled the recent malicious activity against water and wastewater systems.
Regular reassessments are recommended as networks and third-party connections evolve.
The guidance comes shortly after CISA warned of Iran-linked attacks on ICS made by Siemens, Schneider Electric, and Rockwell Automation.
The agency also urged the water sector to protect OT amid attacks on PLCs.
Related: US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
Related: Hackers Using AI to Target Siemens PLCs in Critical US Sectors
Related: Iran-Linked Hackers Shut Down UK Power Plant for Four Days
