The US Cybersecurity and Infrastructure Security Agency (CISA) has disclosed new details about a July wave of attacks against the Water and Wastewater Systems (WWS) sector. According to CISA, the activity targeted over 100 water systems that were reachable from the internet.
CISA shared the information to support organizations in lowering the likelihood that threat actors can reach operational technology (OT) environments. While CISA did not describe widespread operational outages, it emphasized that these incidents underline how quickly “internet-exposed” systems can become valuable targets.
What CISA observed in July
CISA stated that in July 2026 it observed malicious cyber activity targeting more than 100 internet-exposed systems within the WWS sector. The agency noted that the attacks commonly involved programmable logic controllers (PLCs) connected directly to a cellular modem.
Until now, CISA had not publicly quantified the number of affected systems in this particular round of activity against water and wastewater utilities. This new figure is therefore intended to help organizations gauge the scale of the exposure risk across the sector.
Why PLCs and cellular connectivity mattered
At the center of CISA’s concern is how industrial control components can become reachable. When PLCs or other industrial control system (ICS) elements sit behind pathways that allow internet connectivity—especially through cellular modems—the attack surface can widen significantly.
In CISA’s view, that kind of reachability enabled the recent malicious activity. Even if immediate impact is limited, the potential for future disruption remains a major reason for urgency.
Impact on operations and affected states
CISA reported that the cyberattacks did not cause significant disruption. Still, the agency said the events raised serious concerns about what could happen if adversaries were to leverage similar access paths more effectively.
CISA did not publicly name how many states were involved, but it indicated that it appears to be at least 12. Several states—including Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama—have confirmed that they were targeted. Not every state was identified in public reporting.
Threat actor context and targeting goals
CISA linked the activity to Iranian threat actors. The stated goal of the attacks was to disrupt operational technology (OT) systems used by utilities in the water sector.
This matters because OT environments often support real-world processes where reliability is critical. When OT systems are reached and manipulated, even small changes can create cascading risks for monitoring, control, and safety workflows.
CISA guidance: reduce internet attack surface fast
Alongside the July observations, CISA released updated guidance urging organizations to aggressively reduce their internet attack surface—especially for OT environments in critical infrastructure.
CISA’s recommended approach starts with visibility: organizations should identify internet-accessible systems through internal inventories and external scanning tools. Once you understand what is reachable, you can distinguish between exposures that are truly necessary and those that can be removed or restricted.
1) Identify what is exposed
CISA recommends using both internal records and external scanning to map internet-accessible assets. This combined approach helps ensure that teams do not rely solely on documentation, which may lag behind real-world connectivity.
2) Remove or restrict unnecessary exposure
After identifying exposures, CISA advises determining which connections are required for operations. For anything that is not essential, organizations should remove it or apply restrictions to limit who or what can reach it.
3) Harden systems that must remain online
For systems that still need internet connectivity, CISA outlined several protective measures. These include:
- Changing default passwords to eliminate well-known credentials.
- Applying security updates to address known vulnerabilities.
- Routing remote access through secure gateways or jump hosts rather than exposing control components directly.
- Enforcing multifactor authentication to reduce the risk of account takeover.
- Continuously monitoring traffic to detect suspicious behavior early.
4) Reassess as networks evolve
CISA also recommends regular reassessments. As network architecture changes, and as third-party connectivity arrangements evolve, the exposure profile can shift—sometimes without clear internal awareness.
Regular review helps prevent “configuration drift,” where systems remain internet-reachable longer than intended.
The warning about cellular modems
CISA’s updated guidance specifically highlights the danger of leaving PLCs or other industrial control systems reachable via cellular modems or the public internet. In this context, reachability is not a minor detail; it can be the difference between an attacker only scanning broadly and an attacker successfully reaching the components used for operational control.
The agency’s message is clear: where internet reachability exists, the risk must be managed deliberately—through removal, restriction, and strong access controls.
Connection to broader ICS security warnings
The WWS guidance comes after CISA warned about Iran-linked attacks targeting ICS environments made by major industrial technology vendors, including Siemens, Schneider Electric, and Rockwell Automation. In earlier messaging, CISA also urged the water sector to protect OT from attacks involving PLCs.
Taken together, the guidance suggests that CISA views PLC-focused pathways and internet exposure as recurring themes in recent threat activity across critical infrastructure.
Practical takeaways for utilities and OT teams
If you are responsible for water or wastewater operations, CISA’s disclosure offers a concrete checklist mindset. The key is not only to respond to incidents, but to prevent easy access in the first place.
Start by confirming what your environment exposes externally, then prioritize the most risky elements—particularly PLCs and other ICS components that can be reached through cellular modems or public internet paths. From there, strengthen access paths with secure gateways, multifactor authentication, and monitoring, and keep security updates current.
Conclusion
CISA’s report that 100 water systems targeted were involved in July cyberattacks is a reminder that internet reachability can turn OT assets into high-value targets. Even without major disruption in this wave, the potential consequences justify immediate action.
By mapping exposure, reducing unnecessary internet access, and hardening systems that must remain online, water and wastewater organizations can meaningfully reduce the chance that threat actors gain a pathway into operational control environments.
