CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
CISA has issued an alert urging water and wastewater utilities to secure operational technology (OT) devices, specifically programmable logic controllers (PLCs), following coordinated cyberattacks that disrupted automated controls at over 30 Minnesota water systems. Attackers targeted internet-exposed PLCs by changing passwords and IP addresses, causing operational disruptions and boil water notices. The attacks affected water entities of all sizes and highlighted risks from undocumented cellular modems. The alert references Iran-linked threat groups known for targeting water infrastructure and recommends immediate disconnection of PLCs from the internet, use of VPNs or gateways for remote access, password protections, and IP allowlisting. Utilities are also advised to maintain clean backups and review indicators of compromise from CISA advisories. No formal attribution or known exploits in the wild have been confirmed yet.
AI Analysis
Technical Summary
The US Cybersecurity and Infrastructure Security Agency (CISA) issued an alert following coordinated cyber intrusions that impacted operational technology in water and wastewater utilities in Minnesota. The attackers targeted internet-exposed programmable logic controllers (PLCs), modifying passwords to lock out operators and changing IP addresses to disconnect devices. These attacks caused operational disruptions including boil water notices and forced manual operations. The alert highlights that threat actors, including Iran-linked groups such as CyberAv3ngers and Handala, have been observed targeting PLCs from vendors like Rockwell Automation, Schneider Electric, and Siemens. CISA urges utilities to remove PLCs from direct internet exposure, implement VPN or gateway-based remote access, enable password protections, and restrict access via IP allowlisting. The alert also stresses the importance of identifying undocumented cellular modems that may be overlooked in security scans. While investigations continue, no formal attribution has been made, and no known exploits in the wild have been reported.
Potential Impact
The attacks disrupted automated control functions at dozens of water utilities, leading to boil water notices and sustained manual operations. Although water safety was maintained, the incidents caused operational challenges and highlighted vulnerabilities in internet-exposed OT devices. The targeting affects water entities of all sizes and can result in loss of remote control over critical infrastructure components, increasing operational risk and potential safety concerns.
Mitigation Recommendations
CISA recommends immediate disconnection of PLCs from direct internet exposure and routing remote access through VPNs or gateway devices. Operators should enable password protection on PLCs, change default passwords, and implement IP allowlisting to restrict remote access to known devices. Utilities should maintain known-clean backups of PLC images to recover from potential lockouts caused by password changes. Owners of Rockwell Automation MicroLogix 1400 controllers should follow Rockwell's guidance for restoring access if passwords are unknown. Utilities are also advised to review CISA advisory AA26-097A for tactics, techniques, and indicators of compromise to detect current or past intrusions. No official patch is indicated; securing network exposure and access controls is the primary mitigation.
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
Description
CISA has issued an alert urging water and wastewater utilities to secure operational technology (OT) devices, specifically programmable logic controllers (PLCs), following coordinated cyberattacks that disrupted automated controls at over 30 Minnesota water systems. Attackers targeted internet-exposed PLCs by changing passwords and IP addresses, causing operational disruptions and boil water notices. The attacks affected water entities of all sizes and highlighted risks from undocumented cellular modems. The alert references Iran-linked threat groups known for targeting water infrastructure and recommends immediate disconnection of PLCs from the internet, use of VPNs or gateways for remote access, password protections, and IP allowlisting. Utilities are also advised to maintain clean backups and review indicators of compromise from CISA advisories. No formal attribution or known exploits in the wild have been confirmed yet.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The US Cybersecurity and Infrastructure Security Agency (CISA) issued an alert following coordinated cyber intrusions that impacted operational technology in water and wastewater utilities in Minnesota. The attackers targeted internet-exposed programmable logic controllers (PLCs), modifying passwords to lock out operators and changing IP addresses to disconnect devices. These attacks caused operational disruptions including boil water notices and forced manual operations. The alert highlights that threat actors, including Iran-linked groups such as CyberAv3ngers and Handala, have been observed targeting PLCs from vendors like Rockwell Automation, Schneider Electric, and Siemens. CISA urges utilities to remove PLCs from direct internet exposure, implement VPN or gateway-based remote access, enable password protections, and restrict access via IP allowlisting. The alert also stresses the importance of identifying undocumented cellular modems that may be overlooked in security scans. While investigations continue, no formal attribution has been made, and no known exploits in the wild have been reported.
Potential Impact
The attacks disrupted automated control functions at dozens of water utilities, leading to boil water notices and sustained manual operations. Although water safety was maintained, the incidents caused operational challenges and highlighted vulnerabilities in internet-exposed OT devices. The targeting affects water entities of all sizes and can result in loss of remote control over critical infrastructure components, increasing operational risk and potential safety concerns.
Mitigation Recommendations
CISA recommends immediate disconnection of PLCs from direct internet exposure and routing remote access through VPNs or gateway devices. Operators should enable password protection on PLCs, change default passwords, and implement IP allowlisting to restrict remote access to known devices. Utilities should maintain known-clean backups of PLC images to recover from potential lockouts caused by password changes. Owners of Rockwell Automation MicroLogix 1400 controllers should follow Rockwell's guidance for restoring access if passwords are unknown. Utilities are also advised to review CISA advisory AA26-097A for tactics, techniques, and indicators of compromise to detect current or past intrusions. No official patch is indicated; securing network exposure and access controls is the primary mitigation.
Technical Details
- Article Source
- {"url":"https://www.securityweek.com/cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs/","fetched":true,"fetchedAt":"2026-07-30T22:22:06.979Z","wordCount":1393}
Threat ID: 6a6bce8e9c2644c7f8c7aa07
Added to database: 07/30/2026, 22:22:06 UTC
Last enriched: 07/30/2026, 22:22:20 UTC
Last updated: 07/30/2026, 22:22:20 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.