The Cybersecurity and Infrastructure Security Agency (CISA) has reported that over 100 internet-exposed water systems were targeted in cyberattacks this past July. This revelation was part of CISA’s guidance aimed at helping organizations minimize the internet exposure of their systems to prevent such attacks.
Cyberattacks on Critical Water Systems
In a statement, CISA highlighted that in July 2026, over 100 systems within the Water and Wastewater Systems (WWS) sector were compromised through programmable logic controllers (PLCs) connected to cellular modems. This represents a significant breach in cybersecurity for critical infrastructure.
Prior to this disclosure, no federal agency had provided a detailed count of the affected systems. The attacks, reportedly linked to Iranian threat actors, targeted operational technology (OT) systems, raising concerns about potential operational disruptions.
States Affected by Cyber Threats
The cyberattacks impacted various states, with confirmed reports from Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. Although the exact number of affected states remains unspecified, at least 12 states were involved.
Despite no significant disruptions reported, the incidents underscore the vulnerabilities in the water sector and highlight the need for stringent cybersecurity measures.
Steps to Mitigate Internet Exposure
CISA is proactively urging organizations to minimize their internet attack surface, particularly focusing on OT systems in critical infrastructure sectors. Their guidance suggests identifying all internet-accessible systems, assessing their necessity, and removing unnecessary exposures.
For systems that must remain online, CISA recommends changing default passwords, applying regular security updates, routing remote access through secure gateways, enforcing multifactor authentication, and continuous traffic monitoring.
The guidance cautions against leaving PLCs and other industrial control systems accessible via cellular modems or the public internet, a factor contributing to the recent malicious activities against water and wastewater systems.
Regular reassessments of systems are advised as network configurations and third-party connections evolve. This guidance follows warnings of Iranian-linked attacks on industrial control systems by major manufacturers.
Ensuring the cybersecurity of water systems and other critical infrastructure remains a priority, as underscored by recent legislative efforts and security initiatives.
