CISA: 100+ US Water Systems Targeted in Iran-Linked Cyberattacks
The Cybersecurity and Infrastructure Security Agency (CISA) has disclosed that more than 100 internet-exposed water and wastewater systems were targeted in malicious cyber activity during July 2026. The attacks primarily exploited programmable logic controllers (PLCs) connected directly to cellular modems, allowing threat actors to reach industrial control systems (ICS) without traversing internal networks. At least 12 U.S. states have been affected, with Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama publicly confirming targeting. The campaign has been attributed to Iran-linked actors and follows prior CISA warnings about intrusion activity aimed at ICS products from Siemens, Schneider Electric, and Rockwell Automation. While no significant operational disruption was reported, the campaign underscores persistent risks to critical OT environments.
In updated guidance, CISA is urging water utilities and other critical infrastructure operators to aggressively shrink their internet attack surface. The agency recommends starting with full asset discovery using internal inventories and external port scanning tools to identify every internet-reachable device, then removing or restricting exposures that are not operationally required. For systems that must remain online, CISA advises replacing factory-default credentials — a common entry vector — by testing them against a password strength checker, patching known vulnerabilities, routing remote access through hardened jump hosts or VPNs, enforcing multifactor authentication, and continuously monitoring network traffic for anomalies. Operators are also urged to eliminate direct internet connectivity for cellular-modem-attached PLCs whenever feasible.
The advisory lands alongside broader U.S. efforts to bolster water-sector cyber resilience, including a new Senate bill and the establishment of a "Water Watch Center" to coordinate threat intelligence across utilities. CISA's latest recommendations emphasize regular reassessments as networks and third-party connections evolve, noting that exposure footprints can shift quickly when integrators or remote vendors bring new pathways online. Security teams can validate their external posture in parallel by running an SSL/TLS configuration check on public-facing gateways and jump hosts to ensure encrypted channels are properly implemented. With Iran-linked groups continuing to demonstrate intent and capability against U.S. critical infrastructure, defenders are being pushed to treat every internet-reachable OT endpoint as a potential compromise point.