Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

0
Medium
Vulnerability
Published: 07/30/2026 (07/30/2026, 22:18:36 UTC)
Source: SecurityWeek

Description

CISA has issued an alert urging water and wastewater utilities to secure operational technology (OT) devices, specifically programmable logic controllers (PLCs), following coordinated cyberattacks that disrupted automated controls at over 30 Minnesota water systems. Attackers targeted internet-exposed PLCs by changing passwords and IP addresses, causing operational disruptions and boil water notices. The attacks affected water entities of all sizes and highlighted risks from undocumented cellular modems. The alert references Iran-linked threat groups known for targeting water infrastructure and recommends immediate disconnection of PLCs from the internet, use of VPNs or gateways for remote access, password protections, and IP allowlisting. Utilities are also advised to maintain clean backups and review indicators of compromise from CISA advisories. No formal attribution or known exploits in the wild have been confirmed yet.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 22:22:20 UTC

Technical Analysis

The US Cybersecurity and Infrastructure Security Agency (CISA) issued an alert following coordinated cyber intrusions that impacted operational technology in water and wastewater utilities in Minnesota. The attackers targeted internet-exposed programmable logic controllers (PLCs), modifying passwords to lock out operators and changing IP addresses to disconnect devices. These attacks caused operational disruptions including boil water notices and forced manual operations. The alert highlights that threat actors, including Iran-linked groups such as CyberAv3ngers and Handala, have been observed targeting PLCs from vendors like Rockwell Automation, Schneider Electric, and Siemens. CISA urges utilities to remove PLCs from direct internet exposure, implement VPN or gateway-based remote access, enable password protections, and restrict access via IP allowlisting. The alert also stresses the importance of identifying undocumented cellular modems that may be overlooked in security scans. While investigations continue, no formal attribution has been made, and no known exploits in the wild have been reported.

Potential Impact

The attacks disrupted automated control functions at dozens of water utilities, leading to boil water notices and sustained manual operations. Although water safety was maintained, the incidents caused operational challenges and highlighted vulnerabilities in internet-exposed OT devices. The targeting affects water entities of all sizes and can result in loss of remote control over critical infrastructure components, increasing operational risk and potential safety concerns.

Mitigation Recommendations

CISA recommends immediate disconnection of PLCs from direct internet exposure and routing remote access through VPNs or gateway devices. Operators should enable password protection on PLCs, change default passwords, and implement IP allowlisting to restrict remote access to known devices. Utilities should maintain known-clean backups of PLC images to recover from potential lockouts caused by password changes. Owners of Rockwell Automation MicroLogix 1400 controllers should follow Rockwell's guidance for restoring access if passwords are unknown. Utilities are also advised to review CISA advisory AA26-097A for tactics, techniques, and indicators of compromise to detect current or past intrusions. No official patch is indicated; securing network exposure and access controls is the primary mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/","fetched":true,"fetchedAt":"2026-07-30T22:22:06.979Z","wordCount":1393}

Threat ID: 6a6bce8e9c2644c7f8c7aa07

Added to database: 07/30/2026, 22:22:06 UTC

Last enriched: 07/30/2026, 22:22:20 UTC

Last updated: 07/30/2026, 22:22:20 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses