CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
Description
In July 2026, over 100 internet-exposed water and wastewater systems in the United States were targeted in cyberattacks linked to Iranian threat actors. These attacks primarily exploited programmable logic controllers (PLCs) connected directly to cellular modems. While no significant disruptions were reported, the incidents raised concerns about the security of operational technology (OT) in critical infrastructure. CISA has issued guidance urging organizations to reduce internet exposure by inventorying internet-accessible systems, removing unnecessary exposures, changing default passwords, applying security updates, enforcing multifactor authentication, and routing remote access through secure gateways. The attacks highlight risks associated with leaving industrial control systems reachable via public internet or cellular connections. The affected states include at least Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. CISA continues to recommend regular reassessments of network exposure and third-party connections to mitigate future risks.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Cybersecurity and Infrastructure Security Agency (CISA) reported that in July 2026, more than 100 water and wastewater systems in the U.S. were targeted by cyberattacks linked to Iranian threat actors. The attacks exploited internet-exposed programmable logic controllers (PLCs) connected via cellular modems, aiming to disrupt operational technology (OT) systems in the Water and Wastewater Systems (WWS) sector. Although no significant operational disruptions occurred, the attacks underscore the vulnerabilities of OT systems exposed to the internet. CISA's guidance emphasizes identifying and reducing internet exposure, securing remote access, changing default credentials, applying patches, and enforcing multifactor authentication. The advisory also highlights the dangers of leaving PLCs and ICS devices accessible through cellular modems or public internet connections. The affected systems span at least 12 states, including Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. CISA recommends continuous monitoring and reassessment of network exposure to mitigate ongoing threats.
Potential Impact
The cyberattacks targeted over 100 internet-exposed water and wastewater systems, potentially threatening the operational technology controlling critical infrastructure. Although no significant disruptions were reported, the attacks demonstrate the risk posed by internet-exposed PLCs and ICS devices, which could allow threat actors to interfere with water sector operations. The exposure of these systems via cellular modems or public internet increases the attack surface and vulnerability to malicious activity. The incidents highlight the potential for disruption or manipulation of water system controls if adequate security measures are not implemented.
Defensive Guidance
CISA recommends organizations aggressively reduce internet exposure of operational technology systems by first identifying all internet-accessible devices through internal inventories and external scanning. Systems that do not require internet connectivity should have their exposure removed or restricted. For systems that must remain online, CISA advises changing default passwords, applying all relevant security updates, routing remote access through secure gateways or jump hosts, enforcing multifactor authentication, and continuously monitoring network traffic. The guidance specifically warns against leaving PLCs and ICS devices accessible via cellular modems or the public internet. Organizations should perform regular reassessments of network exposure and third-party connections to maintain security posture. No official patch or fix applies as this is an operational security issue rather than a software vulnerability.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/cisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks/","fetched":true,"fetchedAt":"2026-08-26T11:37:11.922Z","wordCount":1122}
Threat ID: 6a8ecfe7acd9273b49ce1128
Added to database: 08/26/2026, 11:37:11 UTC
Last enriched: 09/10/2026, 11:39:18 UTC
Last updated: 10/03/2026, 07:23:32 UTC
Views: 68
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.