Security advisory
Critical InfrastructureHighActiveUpdated Aug 26, 2026

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

The agency's first hard number for the ongoing wave of attacks on US water utilities points to exposed PLCs on cellular modems as the common entry point.

Emanuel De AlmeidaAug 26, 2026, 8:57 PM7 min read
Severity
High
Status
Active
Entity
CISA
Confirmed by
CISA guidance

CISA says it observed malicious cyber activity targeting more than 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector during July 2026, according to guidance the agency released to help organizations reduce internet exposure of operational technology. The disclosure marks the first time a federal agency has publicly quantified the scale of the recent wave of attacks on US water utilities.

The number confirms that attacks previously reported piecemeal across individual states were part of a broader campaign against poorly secured water sector control systems reachable from the public internet.

Key takeaways

  • CISA confirmed over 100 internet-exposed WWS Sector systems were targeted by malicious activity in July 2026.
  • Attackers commonly reached PLCs connected directly to cellular modems rather than through corporate IT networks.
  • At least 12 US states are affected, with Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama confirming they were targeted.
  • The attacks are linked to Iranian threat actors and did not cause significant water supply disruption.
  • CISA is urging utilities to inventory internet-facing systems, remove unnecessary exposure, and route remote access through secure gateways with MFA.

Affected

Vendors
SiemensSchneider ElectricRockwell Automation
Products
Programmable Logic Controllers (PLCs)Siemens ICSSchneider Electric ICSRockwell Automation ICS
Organizations
Micro-Comm
Threat actors
Iran-linked threat actors
Geography
United StatesMinnesotaMichiganSouth DakotaGeorgiaNew JerseyAlabama
Industry
Water and Wastewater SystemsCritical Infrastructure

What did CISA disclose about the July water sector attacks?

CISA disclosed that over 100 internet-exposed water systems were targeted in July cyberattacks, offering the agency's first public count for a campaign that had previously been described only through scattered state-level reports. The agency said the activity hit systems in the Water and Wastewater Systems (WWS) Sector, most commonly programmable logic controllers (PLCs) connected directly to a cellular modem rather than routed through a utility's managed IT network.

The number was published as part of updated CISA guidance aimed at helping critical infrastructure organizations reduce their internet attack surface. Until this release, federal agencies had not quantified how many systems were hit in the recent wave of attacks on water and wastewater utilities, according to SecurityWeek.

Why does this matter for water utilities and MSPs?

The scale disclosed by CISA turns a series of individual incidents into evidence of a systemic exposure problem across the water sector. Matt Hartman, chief strategy officer at Merlin Group, said the fact that more than 100 internet-exposed systems were targeted in a single month shows this is a systemic risk rather than isolated incidents, since much of the OT in water utilities was never designed to sit directly on the internet.

For managed service providers and integrators supporting water utilities, the exposure risk extends beyond the utility itself. SC World reported that water-sector supplier Micro-Comm had roughly 850,000 files leaked around the same time CISA's guidance was published, with the ransomware group Barracuda claiming responsibility. Kevin Surace, CEO of TokenCore, said the Micro-Comm incident shows that protecting the utility is only half the problem, since attackers can also target the companies that manufacture, configure, and remotely support utility technology.

Who is affected?

Water and wastewater utilities in at least 12 US states have been affected, according to CISA, though the full list has not been made public. Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama have each confirmed they were targeted, per SecurityWeek. TechCrunch reported the affected utilities span Michigan, Minnesota, and at least five other states, with many of the hit communities in rural or isolated areas where infrastructure disruption can affect a large population.

  • PLCs made by Rockwell Automation, Schneider Electric, and Siemens have been targeted in recent weeks.
  • CISA previously warned of Iran-linked attacks on ICS from these three manufacturers.
  • Water-sector vendor Micro-Comm was separately hit by a ransomware group calling itself Barracuda.

How are attackers reaching these control systems?

A PLC connected directly to a cellular modem is, by CISA's account, the common entry point in the July campaign: it bypasses a utility's firewall and internal network monitoring entirely, exposing the controller straight to the public internet. TechCrunch reported that some intrusions let attackers modify affected PLCs to disable shutdown processes and alarms, which could create unsafe conditions without alerting the operator.

Denis Calderone, chief technology officer at Suzu Labs, told SC World that the sophistication of these intrusions has grown sharply since 2023, when the CyberAv3ngers group mainly changed default passwords on Unitronics PLCs and posted political messages on HMI screens. By July 2026, Calderone said, CISA confirmed actors were exfiltrating PLC project files using vendors' own engineering software and modifying add-on instructions while keeping operator displays looking normal. A separate five-agency advisory said attackers are also using AI tools to generate exploitation scripts against Siemens S7 controllers from public vulnerability information.

US officials have not issued a formal attribution, but reports citing senior American officials say intelligence agencies believe Iran is likely behind the largely opportunistic attacks, possibly in response to the US and Israel-led war against Iran, according to TechCrunch.

What is CISA recommending utilities do now?

CISA's guidance tells organizations to first identify every internet-accessible system through internal inventories and external scanning, then determine which exposures are actually necessary for operations and remove or restrict the rest. For systems that must stay online, the agency recommends changing default passwords, applying available security updates, routing remote access through secure gateways or jump hosts, enforcing multifactor authentication, and continuously monitoring traffic.

  • Route remote access through a secure gateway, firewall, or VPN instead of connecting directly to a PLC, HMI, or RTU, per CISA.
  • Change default credentials and apply available patches on internet-facing OT.
  • Enforce MFA on all remote access paths into control systems.
  • Reassess network and third-party connections regularly as exposure changes.

Danny Jenkins, CEO of ThreatLocker, told SC World that utilities should disconnect PLCs from the public internet as quickly as possible and move to alternatives like private lines or satellite communications where a cellular or public internet connection is not required.

What happens next for water sector cybersecurity?

CISA's guidance follows earlier warnings about Iran-linked activity against ICS made by Siemens, Schneider Electric, and Rockwell Automation, and about AI-assisted exploitation attempts against Siemens PLCs. Watch for whether CISA or state agencies release a full list of affected utilities, whether patches or firmware mitigations follow for the targeted PLC lines, and whether the Micro-Comm breach investigation surfaces further downstream utility exposure.

No significant disruption to water or wastewater supply has been reported so far, but the disclosed scale, combined with a separate ransomware breach at a water-sector vendor, has renewed pressure on Congress and CISA to accelerate mandatory OT exposure reduction across the sector.

Timeline

Jul 1, 2026
July attacks begin against exposed water systemsCISA says it observed malicious cyber activity targeting over 100 internet-exposed systems in the WWS Sector during July 2026, mostly via PLCs connected to cellular modems.
Aug 26, 2026
CISA publishes exposure-reduction guidance and confirms scaleCISA released updated guidance urging critical infrastructure organizations to reduce internet exposure, publicly quantifying the July attacks for the first time.
Aug 26, 2026
Micro-Comm data leak reportedReports emerged the same day that water-sector supplier Micro-Comm had roughly 850,000 files leaked, with the ransomware group Barracuda claiming responsibility, separate from the Iran-linked PLC intrusions.

Impact & actions

CISA confirmed over 100 internet-exposed water and wastewater systems were targeted in July 2026, mostly through PLCs reachable via cellular modems, with no significant disruption to water supply reported.

Security: CISA's advisory shows the water sector attack surface extends beyond individual utilities to third-party vendors, as illustrated by the nearly 850,000 files leaked in the Micro-Comm breach, per SC World's report.

Privacy: According to SC World, an expert speculated that files leaked in the Micro-Comm breach could include product diagrams, system architecture documents, and customer-specific configurations, rather than personal consumer data.

Recommended actions · High urgency

  1. 1Inventory all internet-accessible OT systems using internal records and external scanning tools
  2. 2Remove or restrict exposures that are not operationally necessary
  3. 3Route required remote access to PLCs, HMIs, and RTUs through a secure gateway, firewall, or VPN instead of direct connections
  4. 4Change default passwords, apply available security updates, and enforce multifactor authentication on remaining exposed systems
  5. 5Continuously monitor OT network traffic for anomalous activity and reassess exposure regularly

Technical details

Exploitation
Exploited in the wild
Attack vector
Direct internet exposure of PLCs connected to cellular modems, allowing attackers to bypass corporate IT networks and reach OT devices directly.

Mitigations

  • Remove unnecessary internet exposure of PLCs and other ICS
  • Route remote access through secure gateways or jump hosts rather than direct PLC connections
  • Enforce multifactor authentication on remote access to OT systems

Response

Vendor

CISA said in its guidance that it observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems Sector in July 2026, commonly via PLCs connected directly to a cellular modem.

Authorities

CISA is urging organizations to aggressively reduce their internet attack surface, prioritizing OT used in critical infrastructure, including inventorying internet-accessible systems and removing unnecessary exposure.

Customer guidance

CISA advises utilities to identify all internet-accessible systems, remove or restrict unnecessary exposure, change default passwords, apply available updates, route remote access through secure gateways with MFA, and continuously monitor traffic.

Updates

Aug 26, 2026CISA quantifies July water sector attacks

CISA released guidance disclosing over 100 internet-exposed WWS Sector systems were targeted in July 2026; reporting also noted a related Micro-Comm supplier breach disclosed the same day.

FAQ

How many water systems did CISA say were targeted in July 2026?

CISA said it observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems Sector during July 2026.

How were attackers reaching these water sector systems?

CISA said attacks commonly occurred via programmable logic controllers (PLCs) connected directly to a cellular modem rather than through corporate IT networks.

Which states have confirmed they were targeted?

Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama have confirmed being targeted, and reports indicate at least 12 US states were affected overall.

Did the attacks disrupt water supply?

According to CISA and reporting from TechCrunch, the intrusions did not cause significant disruption to water or wastewater supplies, though they did trigger incident response activity.

Who is believed to be behind the attacks?

US officials cited by TechCrunch say intelligence assessments point to Iran as the likely actor behind the largely opportunistic attacks, though officials have stopped short of formal attribution.

What is CISA telling utilities to do now?

CISA's guidance calls for inventorying internet-facing OT systems, removing unnecessary exposure, routing remote access through secure gateways with multifactor authentication, and continuously monitoring traffic.

The bottom line

CISA disclosed that more than 100 internet-exposed water and wastewater systems were targeted in July 2026, largely through PLCs connected directly to cellular modems, and issued guidance to cut OT internet exposure.

What happens next

Utilities are expected to begin inventorying and restricting internet-facing OT assets as CISA and affected states continue investigating the scope of the July intrusions.

What to do

Water sector IT/OT teams should inventory internet-facing PLCs and other ICS now and apply CISA's exposure-reduction guidance.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles