Key Takeaways
- CISA confirmed that over 100 internet‑exposed water and wastewater systems were targeted in July 2026, mainly via PLCs linked to cellular modems.
- The activity is attributed to Iranian threat actors seeking to disrupt operational technology (OT) in critical infrastructure.
- At least twelve states were affected, with confirmed incidents in Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama.
- No major service disruption was reported, but the incidents highlight serious vulnerabilities in OT exposure.
- CISA urges organizations to inventory internet‑accessible assets, eliminate unnecessary exposure, and harden required systems with strong passwords, patches, secure gateways, MFA, and continuous monitoring.
- Regular reassessments are essential as networks and third‑party connections evolve.
Overview of CISA Alert
The Cybersecurity and Infrastructure Security Agency (CISA) issued a notice stating that it observed malicious cyber activity targeting more than 100 internet‑exposed systems in the Water and Wastewater Systems (WWS) Sector during July 2026. The agency made this information public as part of updated guidance aimed at helping critical‑infrastructure operators reduce their attack surface. This marks the first time a federal agency has quantified the scale of the recent wave of cyber intrusions against water utilities, providing a concrete basis for risk‑based mitigation efforts.
Details of the July 2026 Activity
According to CISA, the majority of the compromised assets were programmable logic controllers (PLCs) that were directly connected to cellular modems, making them reachable from the public internet. Threat actors, assessed to be linked to Iran, exploited this exposure to attempt manipulation of operational technology (OT) components that control treatment processes, pumping stations, and distribution networks. The reliance on cellular modems for remote connectivity, while convenient, created a facile entry point for adversaries seeking to interfere with essential water‑services infrastructure.
Geographic Spread and Affected States
Although CISA did not disclose an exact state‑by‑state breakdown, the agency indicated that the intrusion campaign spanned at least twelve states. Confirmed victims include Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama, with additional states presumed to be impacted based on threat‑intelligence sharing and sector‑wide reporting. The geographic dispersion underscores that the vulnerability is not confined to a single region but reflects a nationwide exposure pattern among water and wastewater facilities that inadvertently expose OT to the internet.
Impact Assessment
To date, the cyberattacks have not caused any significant disruption to water supply or wastewater treatment services. Operators were able to detect and contain the malicious activity before it could affect process control or public health. Nevertheless, the incidents have heightened concern across the sector because they demonstrate that adversaries possess the capability to reach and potentially manipulate critical OT assets. The lack of overt impact does not diminish the strategic risk; rather, it highlights the importance of proactive defenses before a successful intrusion can lead to service outages, contamination, or environmental harm.
CISA Guidance on Reducing Internet Exposure
CISA’s updated guidance emphasizes a systematic approach to shrinking the internet attack surface, with particular focus on OT systems that support critical infrastructure. The agency recommends that organizations first gain full visibility of all internet‑accessible assets, then rigorously evaluate which exposures are truly required for business operations. Any unnecessary connections should be disabled, segmented, or placed behind strong security controls. By adopting this risk‑based posture, utilities can dramatically reduce the likelihood that threat actors will find an exploitable entry point.
Identifying and Inventorying Internet‑Accessible Systems
The first step in CISA’s prescription is to create a comprehensive inventory of every device that can be reached from the public internet. This includes conducting internal asset scans, leveraging external vulnerability‑scanning services, and reviewing network diagrams for points of egress such as firewalls, routers, and cellular gateways. Organizations should document not only the hardware (e.g., PLCs, RTUs, HMIs) but also the associated software versions, communication protocols, and remote‑access mechanisms. A detailed baseline enables informed decisions about which connections are essential and which can be safely removed.
Determining Necessary Exposures and Restricting Unneeded Ones
Once the inventory is complete, CISA advises a rigorous justification process for each internet‑facing asset. If a system’s remote accessibility is not required for routine operations, maintenance, or emergency response, it should be disabled or placed behind an air‑gap. For assets that must remain reachable, the agency recommends implementing network segmentation, using virtual LANs (VLANs) or demilitarized zones (DMZs) to isolate OT from corporate IT and the internet. This step reduces the attack surface while preserving legitimate functionality.
Securing Required Online Systems
For those systems that legitimately need internet connectivity—such as PLCs that rely on cellular modems for remote telemetry—CISA outlines a series of hardening measures. Default passwords must be replaced with strong, unique credentials; firmware and software should be kept up to date with the latest security patches. Remote access should be funneled through secure gateways, jump hosts, or virtual private networks (VPNs) that enforce multifactor authentication (MFA). Continuous monitoring of traffic, including anomaly detection and logging, is essential to spot unauthorized attempts in real time.
Specific Risks of PLCs and Cellular Modems
The guidance singles out the combination of PLCs and cellular modems as a particularly high‑risk configuration. Cellular links often bypass traditional perimeter defenses, providing a direct conduit to the internet that may not be captured by standard network‑scanning tools. When PLCs are exposed in this manner, threat actors can issue commands to alter setpoints, disable safety interlocks, or interfere with sensor readings. CISA therefore urges utilities to reassess the necessity of cellular connections for each PLC and, where unavoidable, to apply the same hardening controls outlined above.
Ongoing Reassessment and Network Evolution
Because network architectures, third‑party vendors, and threat tactics evolve continuously, CISA stresses that exposure reduction is not a one‑time effort. Organizations should schedule regular reassessments—at least quarterly or whenever significant changes occur, such as new equipment deployments, contractor access, or modifications to cellular service plans. Updating inventories, re‑evaluating the justification for each exposure, and verifying that security controls remain effective are critical components of a resilient cyber‑hygiene program.
Broader Context: Iran‑Linked ICS Threats
The water‑sector alerts follow earlier CISA warnings about Iranian‑linked intrusion attempts against industrial control systems manufactured by Siemens, Schneider Electric, and Rockwell Automation. Those advisories highlighted similar tactics, including exploitation of default credentials and unpatched vulnerabilities in widely used PLC families. The convergence of warnings across multiple sectors suggests a coordinated campaign aimed at undermining the reliability of U.S. critical infrastructure, reinforcing the need for sector‑wide vigilance and information sharing.
Related Initiatives and Legislative Actions
In response to the growing threat landscape, Congress has advanced a Senate bill designed to bolster cybersecurity funding for water systems and to establish a “Water Watch Center” that would centralize threat intelligence and incident response coordination. Additionally, recent reports have described hackers employing artificial intelligence to automate the discovery and exploitation of Siemens PLCs in critical sectors, and Iranian actors have been credited with shutting down a UK power plant for four days. These developments illustrate the evolving sophistication of adversaries and underscore the importance of the proactive measures advocated by CISA.
By heeding CISA’s guidance—inventorying assets, trimming unnecessary exposure, hardening required connections, and maintaining continuous vigilance—water and wastewater utilities can significantly reduce their risk of compromise and help safeguessential public‑health services against future cyber threats.

