CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning to water and wastewater system operators: protect your operational technology (OT) from malicious activity targeting programmable logic controllers (PLCs). The agency’s alert comes on the heels of a coordinated cyberattack that disrupted automated controls at dozens of water utilities in Minnesota, leaving residents under boil water notices.

CISA is observing a significant increase in threat actors targeting PLCs in the water and wastewater sector. These attackers are modifying passwords to lock out operators and disconnecting PLCs by changing their IP addresses. This has resulted in manual operations that closely mirror what several Minnesota utilities reported this week. The alert stresses that even organizations with mature cybersecurity programs should validate their external connections, as the targeting spans water entities of all sizes.

The alert highlights a specific vulnerability: cellular modems installed by operators, vendors, or system integrators that may not be documented or captured in routine attack surface scans. These modems can provide an entry point for attackers to access OT systems. CISA is urging owners and operators to remove publicly exposed PLCs and other OT from the internet as soon as possible.

The coordinated cyberattack on Minnesota water utilities underscores the urgency of this warning. As reported by SecurityWeek earlier this week, statements from affected cities indicated that some automated control functions were disrupted, although contingency procedures were activated and water and wastewater operations remained functional in most cases. The affected cities assured residents that drinking water remained safe.

The timing of the Minnesota intrusions is notable. They came shortly after the US government warned critical infrastructure organizations about Iran-linked attacks on industrial control systems made by Siemens, Rockwell Automation, and Schneider Electric. This warning was issued via a July 22 update to advisory AA26-097A, which expanded the list of targeted vendors beyond Rockwell Automation’s Allen-Bradley controllers.

Iranian threat groups, including CyberAv3ngers and Handala, have been linked to attacks on water systems in the past. While investigators have not yet attributed the Minnesota incidents to a specific actor, these groups’ history of targeting small water utilities and municipal facilities raises concerns. In 2020, Iran-linked actors exploited vulnerable cellular routers as an entry point for attacking water facilities in Israel.

CISA’s core message to the sector is unchanged but increasingly urgent: internet-exposed OT must be secured. The agency recommends three immediate steps: disconnecting PLCs from the internet, enabling password protection and changing default passwords, and allowlisting IP addresses for remote access. Operators should also ensure they have a known-clean backup of the PLC image in case they are locked out by a modified password.

In light of these findings, water and wastewater system operators would do well to review their OT security posture. This includes disconnecting exposed controllers from the internet, enabling robust password protection, and conducting regular network scans for signs of current or historical activity. For more information on securing OT systems, read CISA’s full alert and explore resources from Rockwell Automation and Schneider Electric. By taking proactive steps to secure their OT systems, operators can mitigate the risk of disruption and protect public health and safety.


Source: SecurityWeek — 2026-07-30