Skip to main content

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

0
High
News
Published: 08/26/2026 (08/26/2026, 11:29:50 UTC)
Source: SecurityWeek

Description

In July 2026, over 100 internet-exposed water and wastewater systems in the United States were targeted in cyberattacks linked to Iranian threat actors. These attacks primarily exploited programmable logic controllers (PLCs) connected directly to cellular modems. While no significant disruptions were reported, the incidents raised concerns about the security of operational technology (OT) in critical infrastructure. CISA has issued guidance urging organizations to reduce internet exposure by inventorying internet-accessible systems, removing unnecessary exposures, changing default passwords, applying security updates, enforcing multifactor authentication, and routing remote access through secure gateways. The attacks highlight risks associated with leaving industrial control systems reachable via public internet or cellular connections. The affected states include at least Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. CISA continues to recommend regular reassessments of network exposure and third-party connections to mitigate future risks.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 11:39:18 UTC

Technical Analysis

The Cybersecurity and Infrastructure Security Agency (CISA) reported that in July 2026, more than 100 water and wastewater systems in the U.S. were targeted by cyberattacks linked to Iranian threat actors. The attacks exploited internet-exposed programmable logic controllers (PLCs) connected via cellular modems, aiming to disrupt operational technology (OT) systems in the Water and Wastewater Systems (WWS) sector. Although no significant operational disruptions occurred, the attacks underscore the vulnerabilities of OT systems exposed to the internet. CISA's guidance emphasizes identifying and reducing internet exposure, securing remote access, changing default credentials, applying patches, and enforcing multifactor authentication. The advisory also highlights the dangers of leaving PLCs and ICS devices accessible through cellular modems or public internet connections. The affected systems span at least 12 states, including Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama. CISA recommends continuous monitoring and reassessment of network exposure to mitigate ongoing threats.

Potential Impact

The cyberattacks targeted over 100 internet-exposed water and wastewater systems, potentially threatening the operational technology controlling critical infrastructure. Although no significant disruptions were reported, the attacks demonstrate the risk posed by internet-exposed PLCs and ICS devices, which could allow threat actors to interfere with water sector operations. The exposure of these systems via cellular modems or public internet increases the attack surface and vulnerability to malicious activity. The incidents highlight the potential for disruption or manipulation of water system controls if adequate security measures are not implemented.

Defensive Guidance

CISA recommends organizations aggressively reduce internet exposure of operational technology systems by first identifying all internet-accessible devices through internal inventories and external scanning. Systems that do not require internet connectivity should have their exposure removed or restricted. For systems that must remain online, CISA advises changing default passwords, applying all relevant security updates, routing remote access through secure gateways or jump hosts, enforcing multifactor authentication, and continuously monitoring network traffic. The guidance specifically warns against leaving PLCs and ICS devices accessible via cellular modems or the public internet. Organizations should perform regular reassessments of network exposure and third-party connections to maintain security posture. No official patch or fix applies as this is an operational security issue rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/cisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks/","fetched":true,"fetchedAt":"2026-08-26T11:37:11.922Z","wordCount":1122}

Threat ID: 6a8ecfe7acd9273b49ce1128

Added to database: 08/26/2026, 11:37:11 UTC

Last enriched: 09/10/2026, 11:39:18 UTC

Last updated: 10/03/2026, 07:23:32 UTC

Views: 68

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses