CISA: July cyberattacks targeted over 100 cyber-vulnerable water systems

CISA: July cyberattacks targeted over 100 cyber-vulnerable water systems

The Cybersecurity and Infrastructure Security Agency (CISA) says it is aware of 100 cyber-vulnerable water systems falling victim to cyberattacks in July.

The information was shared as part of Instructions Issued by CISA to help organizations reduce cyber exposure to systems that could be attacked by threat actors.

“In July 2026, CISA observed malicious cyber activity targeting over 100 internet-connected water and wastewater (WWS) systems, often through programmable logic controllers (PLCs) directly connected to a cellular modem,” CISA noted.

Practical cyber-physical systems training at the ICS Cybersecurity Conference

Previously, federal authorities had not publicly quantified the number of systems affected by the latest wave of attacks on water and wastewater utilities.

The water sector attacks, which have been linked to Iranian threat actors, were aimed at disrupting operational technology (OT) systems.

Advertising. Scroll to continue reading.

The government has not said how many states were affected, but it appears there were at least 12 states. Not all of them are known, but states such as Minnesota, Michigan, South Dakota, Georgia, New Jersey and Alabama have confirmed that they have been targeted.

The cyberattacks did not cause significant disruption, but raised concerns about their potential impact on the water sector.

Reduction of internet presence

CISA urges organizations to dramatically reduce their cyber attack surface, with a focus on operational technology (OT) used in critical infrastructure.

In its updated guidance, the agency recommends first identifying all internet-accessible systems through internal inventories and external scanning tools. Organizations should determine which risks are truly necessary to operations and remove or limit the rest.

For systems that must remain online, CISA recommends changing default passwords, applying security updates, routing remote access through secure gateways or jump hosts, enforcing multifactor authentication, and continually monitoring traffic.

The guidance specifically highlights the risks of leaving PLCs and other industrial control systems (ICS) accessible via cellular modems or the public Internet, noting that such exposure has enabled recent malicious activity against water and wastewater systems.

Periodic reassessments are recommended as networks and third party connections evolve.

The guidance comes shortly after CISA warned of Iran-linked attacks on ICSs from Siemens, Schneider Electric and Rockwell Automation.

The agency also called on the water sector to protect OT from attacks on PLCs.

Related: US water systems get cyber boost from new Senate bill and Water Watch Center

Related: Hackers use AI to target Siemens PLCs in critical US sectors

Related: Iran-linked hackers shut down British power plant for four days

Leave a Reply

Your email address will not be published. Required fields are marked *