Cyberattacks on US Water Utilities Expose Vulnerabilities in Critical Infrastructure
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a dire warning about a surge in cyberattacks targeting water and wastewater systems across the country. Hackers have already disrupted more than 30 community water systems in Minnesota, leaving thousands of people without access to clean drinking water. This alarming trend highlights the urgent need for critical infrastructure owners and operators to take immediate action to protect their assets from cyber threats.
The attacks, which began on Sunday and continued through Monday, involved hackers targeting internet-exposed programmable logic controllers (PLCs). These devices are used to control and monitor various aspects of water treatment and distribution systems. By exploiting vulnerabilities in these devices, hackers were able to change passwords, modify IP addresses, and even disconnect devices from the internet, causing operational disruptions.
CISA’s urgent alert emphasizes the importance of removing publicly exposed PLCs and other operational technology (OT) assets from the internet as soon as possible. This is particularly crucial for organizations with mature cybersecurity programs, which are often considered to be more secure than their less-experienced counterparts. However, even these organizations have been caught off guard by the recent attacks.
The bulletin also notes that many water and wastewater systems expose operational technology (OT) assets without realizing it. These assets may include undocumented cellular modems installed by operators, vendors, or system integrators. Internet-facing assets are vulnerable to defacement attacks, configuration changes, operational disruptions, and even physical damage.
To mitigate these risks, CISA recommends that organizations immediately remove exposed OT assets from direct internet exposure. If this is not possible, they should use a VPN connection or gateway devices for secure access. Additionally, default passwords should be changed, and access should be limited to an IP address allow-list.
The agency has also provided specific guidance for owners of Rockwell Automation MicroLogix 1400 PLCs, which have been identified as particularly vulnerable. CISA pointed owners to vendor guidance for recovering access if passwords have been changed.
A recent report by cybersecurity search company Censys highlights the scope of the problem. According to their data, there are more than 4,100 internet-exposed Rockwell Automation/Allen-Bradley hosts, 4,100 Siemens hosts, and over 2,000 Schneider Electric hosts. However, it’s essential to note that this map shows devices reachable over the public internet, not systems that are necessarily being targeted or compromised.
To protect themselves from these types of attacks, security teams should prioritize regular testing and assessment of their systems. This includes conducting breach and attack simulation tests, which can help identify vulnerabilities before they are exploited by attackers. By taking proactive steps to secure their infrastructure, organizations can reduce the risk of cyberattacks and ensure the continuity of critical services.
In conclusion, the recent surge in cyberattacks on US water utilities serves as a stark reminder of the importance of prioritizing cybersecurity in critical infrastructure sectors. By following CISA’s guidance and taking immediate action to protect exposed OT assets, organizations can help prevent similar disruptions in the future.
Source: Bleeping Computer — 2026-07-31