[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgFuu2-BGpWoP2NMJi6bGg3EULg5-KDSDfkELXnW0bp0":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"fe743d1d-8e9b-4ae5-b196-878809858c7c","CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs","cisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs-e79f38","CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems. The post CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs appeared first on SecurityWeek.","CISA has issued an urgent alert for water and wastewater utilities to secure their operational technology (OT), particularly internet-exposed programmable logic controllers (PLCs). This follows a coordinated cyberattack that disrupted automated controls at dozens of Minnesota water systems, leading to boil water notices and manual operations. The agency noted a significant increase in threat actors targeting PLCs and highlighted that attacks have involved modifying passwords and changing IP addresses to lock out operators.","CISA urges water utilities to secure internet-exposed PLCs after coordinated attacks.","The US Cybersecurity and Infrastructure Security Agency (CISA) is urging water and wastewater system (WWS) operators to protect operational technology (OT) against malicious activity targeting programmable logic controllers (PLCs). The alert is a fresh call to action that comes just days after a coordinated cyberattack disrupted automated controls at dozens of water utilities in Minnesota. In an alert published July 30, CISA said it is observing a significant increase in threat actors targeting PLCs in the water and wastewater sector, and urged critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other OT from the internet as soon as possible. The agency described specific tactics it has seen against exposed controllers: attackers have modified passwords to lock out operators and disconnected PLCs by changing their IP addresses. According to CISA, the attacks have resulted in “boil water notices” and sustained manual operations that closely mirror what several Minnesota utilities reported this week. Notably, the alert stressed that the targeting spans water entities of all sizes, and that even organizations with mature cybersecurity programs should validate their external connections. CISA specifically called out cellular modems installed by operators, vendors, or system integrators that may not be documented or captured in routine attack surface scans. Minnesota attacks underscore the warning CISA’s renewed push follows a coordinated cyberattack that, according to Minnesota IT Services (MNIT), hit OT systems at more than 30 community water systems on July 26 and 27.Advertisement. Scroll to continue reading. As SecurityWeek reported earlier this week, statements from affected cities, including Maple Plain, Braham, South St. Paul, and Plymouth, indicated that some automated control functions were disrupted, though contingency procedures were activated and water and wastewater operations remained functional in most cases. The affected cities told residents that drinking water remained safe. State and federal agencies are investigating, and no formal attribution has been made. Ties to the Iranian PLC campaign The timing of the Minnesota intrusions is notable. They came shortly after the US government warned critical infrastructure organizations about Iran-linked attacks on industrial control systems made by Siemens, Rockwell Automation, and Schneider Electric. That warning came via a July 22 update to advisory AA26-097A, originally published in April, which expanded the list of targeted vendors beyond Rockwell Automation’s Allen-Bradley controllers to include Schneider Electric and Siemens devices, and noted that PLCs from other manufacturers may also be at risk. Investigators have observed activity against Rockwell CompactLogix and Micro850, Schneider Electric Modicon M340, and Siemens S7-1200 series PLCs. Iranian threat groups including CyberAv3ngers and Handala fit the profile for attacks on water systems of the kind seen in Minnesota, though investigators have not linked the incidents to any specific actor. CyberAv3ngers has a long track record of targeting small water utilities and municipal facilities, and in 2020 attacks on water facilities in Israel, Iran-linked actors exploited vulnerable cellular routers as an entry point. What OT operators should do CISA’s core message to the sector is unchanged but increasingly urgent: internet-exposed OT must be secured. The July 30 alert recommends three immediate steps. Operators should disconnect the PLC from the internet, routing any remote access for operational purposes through a VPN or gateway device rather than directly to the controller; enable password protection and change default passwords; and allowlist IP addresses so that remote access is permitted only from known engineering laptops or other critical OT assets. CISA also advised that, after disconnecting PLCs, operators ensure they have a known-clean backup of the PLC image in case they are locked out by a modified password. Owners and operators of Rockwell Automation MicroLogix 1400 controllers are pointed to Rockwell’s dedicated guidance for restoring access when the password is unknown. Beyond the immediate steps, utilities are encouraged to review the tactics, techniques, and indicators of compromise in AA26-097A for signs of current or historical activity on their networks. For more information, read the full alert from CISA. Learn More at the ICS Cybersecurity Conference | Nashville Written By Mike Lennon For more than 15 years, Mike Lennon has been closely monitoring the threat landscape and analyzing trends in the National Security and enterprise cybersecurity space. In his role at SecurityWeek, he oversees the editorial direction of the publication and is founder and director of several leading cybersecurity industry conferences around the world. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Mike Lennon Capital One Open Sources AI-Powered ‘VulnHunter’ Security ToolCISA Reportedly Using Anthropic’s Mythos to Scan Government Software for FlawsKeyfactor Scores $1 Billion+ Investment for AI, Post-Quantum SecuritySecurityWeek ICS Cybersecurity Conference Heads to Nashville for Special 25-Year Anniversary EditionCisco Moves to Acquire Astrix Security to Tackle Non-Human Identity RisksIran-Linked Hackers Disrupt US Critical Infrastructure via PLC AttacksSenate Confirms Joshua Rudd to Lead NSA and US Cyber CommandUS Cyber Strategy Targets Adversaries, Critical Infrastructure, and Emerging Technologies Latest News Bank of America to Acquire Cybersecurity Firm MDSecOkta to Acquire Identity Threat Detection Firm PermisoTimeless Compliance: Why Better Questions Beat Bigger FrameworksDataBahn Raises $40 Million for Agentic Data Pipeline ManagementDiscern Security Raises $13 Million in Series A FundingCantina Emerges From Stealth With $8 Million in FundingOnyx Security Raises $113 Million to Control AI Agents in the Enterprise‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveAlex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).More People On The MoveExpert Insights Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten ","https:\u002F\u002Fwww.securityweek.com\u002Fcisa-urges-water-sector-to-protect-ot-after-coordinated-attacks-on-plcs\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2023\u002F04\u002FCISA-Cybersecurity.jpg","2026-07-30T22:18:36+00:00","2026-07-31T00:00:07.929618+00:00",9,[18,21,23,25,27,30],{"name":19,"type":20},"CompactLogix","product",{"name":22,"type":20},"Micro850",{"name":24,"type":20},"Modicon M340",{"name":26,"type":20},"S7-1200",{"name":28,"type":29},"Siemens","vendor",{"name":31,"type":29},"Rockwell Automation","d6f63bb8-0801-486a-be7f-171400700454",{"id":32,"icon":34,"name":35,"slug":36},null,"IoT\u002FOT","iot-ot",[38,43,48,50],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":49},{"id":32,"icon":34,"name":35,"slug":36},{"category":51},{"id":52,"icon":34,"name":53,"slug":54},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[56,60],{"type":57,"value":58,"context":59},"mitre_attack","T1078.004","Valid Accounts: Cloud Accounts - Attackers modified passwords to lock out operators.",{"type":57,"value":61,"context":62},"T1570","Lateral Tool Transfer - Attackers changed IP addresses to disconnect PLCs."]