CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
CISA reports over 100 internet-exposed water systems targeted by Iran-linked hackers in July.
Summary
CISA has revealed that over 100 internet-exposed water and wastewater systems were targeted in cyberattacks during July. The attacks, linked to Iranian threat actors, primarily exploited programmable logic controllers (PLCs) connected via cellular modems to disrupt operational technology. While no significant disruptions were reported, CISA has issued guidance urging organizations to reduce internet exposure of critical infrastructure systems.
Full text
The Cybersecurity and Infrastructure Security Agency (CISA) says it’s aware of 100 internet-exposed water systems targeted in cyberattacks in July. The information was shared as part of guidance released by CISA to help organizations reduce the internet exposure of systems that could be targeted by threat actors. “In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” CISA noted. Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference Until now, federal agencies had not publicly quantified the number of systems affected in the recent wave of attacks on water and wastewater utilities. The water sector attacks, linked to Iranian threat actors, sought to disrupt operational technology (OT) systems. Advertisement. Scroll to continue reading. The government has not said how many states are affected, but it appears there were at least 12 states. Not all of them are known, but states such as Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama have confirmed that they were targeted. The cyberattacks did not cause any significant disruption, but they have raised concerns about their potential impact on the water sector. Reducing internet exposure CISA is urging organizations to aggressively reduce their internet attack surface, with emphasis on operational technology (OT) used in critical infrastructure. In its updated guidance, the agency recommends first identifying all internet-accessible systems via internal inventories and external scanning tools. Organizations should determine which exposures are truly necessary for operations and remove or restrict the rest. For systems that must remain online, CISA advises changing default passwords, applying security updates, routing remote access through secure gateways or jump hosts, enforcing multifactor authentication, and continuously monitoring traffic. The guidance specifically highlights the risks of leaving PLCs and other industrial control systems (ICS) reachable via cellular modems or the public internet, noting that such exposure has enabled the recent malicious activity against water and wastewater systems. Regular reassessments are recommended as networks and third-party connections evolve. The guidance comes shortly after CISA warned of Iran-linked attacks on ICS made by Siemens, Schneider Electric, and Rockwell Automation. The agency also urged the water sector to protect OT amid attacks on PLCs. Related: US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ Related: Hackers Using AI to Target Siemens PLCs in Critical US Sectors Related: Iran-Linked Hackers Shut Down UK Power Plant for Four Days Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs First Malware Built Specifically for Car Head Units Fuels BotnetCISA Warns of Exploited Oracle WebLogic VulnerabilityReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited91 Vulnerabilities Patched in Spring Application FrameworkVenezuelan Gets Record Federal Prison Term for ATM JackpottingPersonal Information Exposed in Apollo Global Data BreachAnthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundBanking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight Latest News The MFA Identity Trap: When Authentication Creates a False Sense of SecurityChrome 152 Patches Over 300 VulnerabilitiesSensitive Information Exposed in Nutex Health Data BreachCISA Warns of Exploited Gitea VulnerabilityLinux Foundation to Govern TRACE, an Open Standard for AI Runtime AttestationAlice Raises $140M to Expand AI Model Defenses and Enterprise GuardrailsWordPress Websites Targeted via MiniOrange Plugin VulnerabilitiesWhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveTrellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.Mike Marshall has been appointed State Chief Information Security Officer at the California Department of Technology.Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.More People On The MoveExpert Insights The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email