Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.

Water system vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) says it’s aware of 100 internet-exposed water systems targeted in cyberattacks in July.

The information was shared as part of guidance released by CISA to help organizations reduce the internet exposure of systems that could be targeted by threat actors.

“In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” CISA noted.

Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference

Until now, federal agencies had not publicly quantified the number of systems affected in the recent wave of attacks on water and wastewater utilities.

The water sector attacks, linked to Iranian threat actors, sought to disrupt operational technology (OT) systems. 

Advertisement. Scroll to continue reading.

The government has not said how many states are affected, but it appears there were at least 12 states. Not all of them are known, but states such as Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama have confirmed that they were targeted.

The cyberattacks did not cause any significant disruption, but they have raised concerns about their potential impact on the water sector.

Reducing internet exposure

CISA is urging organizations to aggressively reduce their internet attack surface, with emphasis on operational technology (OT) used in critical infrastructure.

In its updated guidance, the agency recommends first identifying all internet-accessible systems via internal inventories and external scanning tools. Organizations should determine which exposures are truly necessary for operations and remove or restrict the rest. 

For systems that must remain online, CISA advises changing default passwords, applying security updates, routing remote access through secure gateways or jump hosts, enforcing multifactor authentication, and continuously monitoring traffic.

The guidance specifically highlights the risks of leaving PLCs and other industrial control systems (ICS) reachable via cellular modems or the public internet, noting that such exposure has enabled the recent malicious activity against water and wastewater systems. 

Regular reassessments are recommended as networks and third-party connections evolve.

The guidance comes shortly after CISA warned of Iran-linked attacks on ICS made by Siemens, Schneider Electric, and Rockwell Automation.

The agency also urged the water sector to protect OT amid attacks on PLCs.

In addition to resources from CISA, the OT security community and defenders can check out the Infracritical website that details all currently known technical information.

Related: US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’

Related: Hackers Using AI to Target Siemens PLCs in Critical US Sectors

Related: Iran-Linked Hackers Shut Down UK Power Plant for Four Days

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.