CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

A coordinated cyberattack has disrupted automated controls at dozens of water utilities in Minnesota, prompting a fresh warning from the US Cybersecurity and Infrastructure Security Agency (CISA) to protect operational technology (OT) against malicious activity targeting programmable logic controllers (PLCs).

The alert comes on the heels of a wave of targeted attacks on OT systems, with CISA observing a significant increase in threat actors seeking to disrupt water and wastewater operations. Specifically, attackers have modified passwords to lock out operators and disconnected PLCs by changing their IP addresses, resulting in “boil water notices” and sustained manual operations.

The Minnesota attacks are just the latest example of a growing trend: Iran-linked threat groups, including CyberAv3ngers and Handala, have been observed targeting small water utilities and municipal facilities. In fact, these actors have exploited vulnerable cellular routers as an entry point in previous attacks on water facilities in Israel. The US government has warned critical infrastructure organizations about the risk of Iranian PLC campaigns, which have targeted devices from manufacturers such as Rockwell Automation, Schneider Electric, and Siemens.

CISA’s alert emphasizes that the targeting spans water entities of all sizes, even those with mature cybersecurity programs. The agency stresses the importance of validating external connections, particularly cellular modems installed by operators or vendors, which may not be documented or captured in routine attack surface scans. This is a critical reminder for OT operators: even if you think your systems are secure, it’s essential to regularly review and validate your network configurations.

The attacks on Minnesota water utilities underscore the need for immediate action. CISA recommends three steps to protect against these types of attacks:

First, disconnect the PLC from the internet and route remote access through a VPN or gateway device rather than directly to the controller.

Second, enable password protection and change default passwords to prevent attackers from locking out operators.

Third, allowlist IP addresses so that remote access is permitted only from known engineering laptops or other critical OT assets.

After disconnecting PLCs, operators should ensure they have a known-clean backup of the PLC image in case they are locked out by a modified password. Rockwell Automation MicroLogix 1400 controller owners and operators can refer to the manufacturer’s dedicated guidance for restoring access when the password is unknown.

In addition to these immediate steps, utilities should review the tactics, techniques, and indicators of compromise in AA26-097A for signs of current or historical activity on their networks. By taking proactive measures to secure OT systems, water utilities can prevent disruptions and protect public health.

As a practical takeaway, it’s essential for OT operators to regularly review and validate their network configurations, including external connections such as cellular modems. This will help prevent attackers from exploiting vulnerabilities and ensure the continued safety of drinking water supplies. By prioritizing OT security, we can mitigate the risk of these types of attacks and protect our critical infrastructure.


Source: SecurityWeek — 2026-07-30