Water System PLCs Flooded by Cyber Attacks

CISA is aware of more than 100 internet-exposed systems targeted in July cyberattacks.

Water Treatment Plant Tuachanwatthana
istock.com/tuachanwatthana

CISA says it’s aware of more than 100 internet-exposed water systems targeted in cyberattacks in July. The information was shared as part of guidance released to help organizations reduce the internet exposure of systems that could be targeted by threat actors.

“In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” CISA stated in their advisory.

Until now, federal agencies had not publicly quantified the number of systems affected in the recent wave of attacks on water and wastewater utilities. The government has not said how many states are affected, but it appears there were at least 12 states. Not all of them are known, but states such as Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama have confirmed that they were targeted. 

The cyberattacks did not cause any significant disruption, but they have raised concerns about potential impact on any enterprise utilizing similar PLCs and industrial control systems. Industry stakeholders offer the following thoughts.

Matt Hartman, Chief Strategy Officer at Merlin Group

"The fact that more than 100 internet-exposed water systems were targeted in a single month underscores that this is a systemic risk, not a series of isolated incidents. Water utilities often rely on operational technology that was never designed to be directly exposed to the internet, while attackers are also looking for weaknesses across the vendors that support these environments. 

"The priority now should be exactly what CISA is emphasizing: identify internet-exposed assets, remove unnecessary exposure, change default credentials, patch supported systems, secure required remote access with controls like MFA, and continuously monitor for anomalous activity."

Dana Simberkoff, CISO at AvePoint

"Recent incidents have exposed risks that have existed across critical infrastructure for years: internet-facing controllers, weak segmentation, legacy systems, third-party access, and limited visibility into operational technology. Recent attacks on U.S. water systems have exploited those same conditions, sometimes forcing operators to switch to manual processes.  

"AI expands existing attack paths by helping adversaries identify exposed assets, generate exploit code, chain vulnerabilities, and operate at greater speed and scale. The underlying weaknesses are poor security hygiene and years of uneven investment. 

"It’s also important to note that regulations like DORA (Digital Operational Resilience Act) and NIS2 (Network and Information Security Directive 2) fundamentally shift cybersecurity from an organization-centric model to an ecosystem and supply chain model. This is especially important as critical infrastructure operators increasingly depend on AI systems, cloud providers, software dependencies, data providers, and third-party AI vendors.

John Gallagher, Vice President at Viakoo

"Malicious hackers and nation-state adversaries will often run live stress-tests against operators of critical infrastructure to test their defenses. AI makes these attacks faster and easier to launch, increasing the frequency of such attacks. 

"The increased volume and velocity of attacks means that passive advisory memos and slow cyber hygiene methods just won't work anymore (if they ever did). What is needed is active, ongoing, and automated cyber hygiene of critical infrastructure systems to prevent the initial intrusions from being successful.  

"Many countries, such as the UK and the US, rely on distributed and heterogeneous forms of public utilities. Successful attacks on small or rural utilities does not translate into a broad threat to the public. However, these 'warning shots' being fired by adversaries need to be taken seriously and more funding allocated to act on weak cyber defenses. 

"Adversaries will always have an upper hand because of speed when cyber defense relies on bureaucratic budget cycles and multi-year legislative processes. "

Louis Eichenbaum, Federal CTO at ColorTokens 

"Tthe cybersecurity conversation must move beyond prevention alone. We are never going to patch fast enough or prevent every intrusion. The focus now must be on resilience, assuming an adversary may gain access and ensuring they cannot move laterally or manipulate critical operations at scale.

"Granular microsegmentation and Zero Trust principles are essential in OT environments because they help contain breaches, restrict unauthorized communications, and reduce the blast radius when a compromise occurs. The goal is not simply to stop every attack, but to ensure that a localized intrusion does not become a catastrophic operational event.

David Brumley, Chief AI and Science Officer at Bugcrowd

"Many of the attacks start out simply to score political points, where Iran and other adversaries want to embarrass the US. The scary part is what happens afterwords, where an attacker may end up inside critical infrastructure."

Christopher Hills, Chief Security Strategist at BeyondTrust

"For many years, OT has prioritized uptime over security and threat actors know this, which is why they continue to compromise these OT environments in the way they do. We have seen this same type of attack with the Aliquippa Water Plant, where threat actors targeted the PLC that was broadcasting Modbus (Port 502) on the public internet. 

"They leveraged this as their foothold into their PLC and then pivoted to the Human Machine Interface (HMI) which had default credentials that were never changed, and used this to install a lightweight web shell for persistence, ultimately defacing the HMI screen and attempting to shut down the pumps and disrupt water pressure. These types of legacy systems do not use modern technology or security to secure.

"However, one thing remains: foundational security practices do not need modern security to take basics steps in security. Default admin and passwords are considered foundation security practices. Ensuring they are either turned off, managed, or at a minimum, rotated from their default/shipped state. This is where many organizations, including IT, tend to forget about the basics when it comes to foundational security. 

'And in most IT environments, you have additional layers of security that typically help layer some of this access, which makes it harder in most IT environments. Unfortunately, this is not the case in OT. OT does not have these additional security layers to help protect them and are therefore vulnerable right from the start. This is why you see NIST creating a special project/team to address critical infrastructure and OT, because they know this is a weakness across all OT environments.

"Threat actors already know our weakest infrastructure is our critical infrastructure, whether it be in our utilities sector or other OT. If we do not find a way to modernize these legacy systems, put modern security controls in place, and guard them against attacks, we will continue to suffer and see breaches and compromises across OT environments."

Jim Richberg, Head of Cyber Policy and Global Field CISO at Fortinet

"The ongoing targeting and successful exploitation of water systems is shining a light on a longstanding problem in the security of (especially) the small water/wastewater utilities that comprise 81 percent of all US public water systems. 

"Setting requirements is part of the answer, but it needs to be matched with providing resources–which can ‘parachuted’ in from the state or Federal level but ultimately need to be built into utility rates (often set and approved by someone other than the utility) to be sustainable. And there are volunteers pitching in to help the sector, such as DEF CON Franklin. Many of these small utilities lack the expertise to address the problem on their own, so they need to rely on external expertise, both paid and pro bono."

More in Cybersecurity