


Perceptive Security
SOC/SIEM Consultancy

CISA warns of cyberattacks disrupting U.S. water utilities
Published:
31 juli 2026 om 18:49:49
Alert date:
31 juli 2026 om 19:02:18
Source:
bleepingcomputer.com
Critical Infrastructure, Network Infrastructure, Mobile & IoT
CISA has issued a warning about a significant increase in cyberattacks targeting internet-exposed programmable logic controllers (PLCs) in the U.S. water and wastewater systems sector. The attacks represent a growing threat to critical infrastructure, specifically operational technology (OT) devices used to manage water treatment and distribution. Threat actors are exploiting PLCs that are directly accessible via the internet, which lack adequate security controls. The advisory highlights the need for water utilities to reduce their internet-exposed attack surface. CISA is urging operators to implement stronger security measures to protect these critical systems from disruption. The campaign underscores ongoing vulnerabilities in industrial control systems (ICS) used in essential public services.
Technical details
Threat actors are conducting coordinated cyberattacks targeting internet-exposed Programmable Logic Controllers (PLCs) in the water and wastewater systems sector. Attack techniques include: changing PLC passwords to lock out legitimate operators, modifying IP addresses to disconnect devices from the internet, and other actions causing operational disruptions. The attacks have impacted over 30 community water systems in Minnesota, forcing some utilities to switch to manual operations. The targeted devices include Rockwell Automation MicroLogix 1400 PLCs, many running end-of-sale (EoS) firmware. Censys estimates over 4,100 internet-exposed Rockwell Automation/Allen-Bradley hosts, 4,100 Siemens hosts, and over 2,000 Schneider Electric hosts are publicly reachable. A notable exposure vector is undocumented cellular modems installed by operators, vendors, or system integrators — nearly half of exposed Rockwell devices are reachable via Verizon Business, AT&T, T-Mobile, Comcast, Charter, and Starlink networks. Internet-facing OT assets are vulnerable to defacement, configuration changes, operational disruptions, and physical damage.
Mitigation steps:
1. Immediately remove internet-exposed PLCs and other OT devices from direct public internet access. 2. If direct removal is not possible, use VPN connections or gateway devices to secure remote access. 3. Change all default passwords on PLCs and OT devices immediately. 4. Restrict access using an IP address allow-list. 5. Audit for undocumented cellular modems installed by operators, vendors, or system integrators and remove or secure them. 6. Owners of Rockwell Automation MicroLogix 1400 PLCs should follow vendor guidance for recovering access if passwords have been changed. 7. Review and apply firmware updates, especially for devices running end-of-sale (EoS) firmware. 8. Use Censys IoCs and threat-hunting guidance to identify exposed or compromised assets. 9. Activate cybersecurity incident response plans if compromise is suspected. 10. Share threat intelligence with CISA and relevant state agencies (e.g., MNIT) to support coordinated response.
Affected products:
Rockwell Automation MicroLogix 1400 PLCs (many running end-of-sale firmware)
Rockwell Automation / Allen-Bradley PLCs (general)
Siemens PLCs (general)
Schneider Electric PLCs (general)
Operational Technology (OT) devices with internet exposure in water and wastewater systems
Related links:
https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack/
https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs
https://censys.com/blog/cisa-alert-water-tower-plc-targeting/
https://www.bleepingcomputer.com/news/security/cisa-shares-advice-on-isolating-vital-systems-during-cyberattacks/
Related CVE's:
Related threat actors:
IOC's:
Internet-exposed Rockwell Automation/Allen-Bradley PLC hosts (4,100+ identified by Censys), Internet-exposed Siemens PLC hosts (4,100+ identified by Censys), Internet-exposed Schneider Electric PLC hosts (2,000+ identified by Censys), PLC devices reachable via Verizon Business, AT&T, T-Mobile, Comcast, Charter, and Starlink ASNs, Unauthorized password changes on PLCs, Unauthorized IP address modifications on PLCs, Undocumented cellular modems connected to OT devices
This article was created with the assistance of AI technology by Perceptive.
