CISA warns of cyberattacks disrupting U.S. water utilities

A Growing Concern: Cyberattacks Disrupt US Water Utilities, Leaving Residents Without Access to Clean Drinking Water

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning about a significant increase in cyberattacks targeting the water and wastewater systems sector across the country. The agency’s alert comes after hackers disrupted more than 30 community water systems in Minnesota, leaving residents without access to clean drinking water.

At the heart of these attacks are internet-exposed programmable logic controllers (PLCs), which are essentially computerized control devices that manage and regulate various aspects of a water system’s operations. Hackers are targeting these devices by changing passwords, modifying IP addresses, and taking other actions that disrupt operations and leave operators locked out.

CISA is urging critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs from the internet as soon as possible. This warning is not limited to small or vulnerable organizations; even those with mature cybersecurity programs are being targeted. The bulletin notes that exposed operational technology (OT) may include undocumented cellular modems installed by operators, vendors, or system integrators.

The problem of exposed OT assets has been highlighted by Censys, a cybersecurity search company, which estimates that there are over 4,100 internet-exposed Rockwell Automation/Allen-Bradley hosts, 4,100 Siemens hosts, and over 2,000 Schneider Electric hosts. While it’s unclear how many of these devices are being targeted or compromised, the sheer number is alarming.

One of the most critical concerns is that many of these exposed PLCs are running outdated firmware versions, making them vulnerable to attacks. Censys has also highlighted the problem of undocumented cellular modems as a common blind spot, with nearly half of the exposed Rockwell devices reachable via various networks.

To mitigate this risk, CISA recommends removing internet-facing assets from direct exposure or using a VPN connection or gateway devices for secure access. Default passwords should be changed, and access should be limited to an IP address allow-list. The agency has also provided guidance for recovering access if passwords have been changed, specifically for Rockwell Automation MicroLogix 1400 PLCs.

The Minnesota IT Services (MNIT) agency activated the state’s cybersecurity incident response plan after identifying a coordinated cyberattack targeting operational technology at more than 30 Minnesota community water systems. Multiple municipalities reported disruptions caused by the cyberattack, with equipment malfunctions forcing some utilities to temporarily switch to manual operations.

This attack serves as a stark reminder of the importance of prioritizing OT security and ensuring that critical infrastructure is protected from cyber threats. As we continue to rely on complex technology to manage our essential services, it’s imperative that we take proactive measures to prevent these types of attacks from occurring in the first place.

For those responsible for managing water and wastewater systems, this alert should serve as a wake-up call to review their OT security posture and take immediate action to protect against potential threats. For the general public, it highlights the importance of supporting efforts to prioritize cybersecurity and infrastructure resilience in our communities.


Source: Bleeping Computer — 2026-07-31