CISA Urges Water Sector to Secure OT After Iran-Linked PLC Attacks
CISA has issued an urgent advisory urging water and wastewater system (WWS) operators to safeguard operational technology (OT) following a wave of cyberattacks targeting programmable logic controllers (PLCs). Published on July 30, the alert warns of a significant increase in threat actors exploiting internet-exposed PLCs, with attackers observed modifying administrative passwords to lock out operators and disconnecting controllers by altering their IP addresses. The intrusions have triggered "boil water notices" and forced facilities into sustained manual operations. CISA stressed that even mature security programs are at risk, particularly from undocumented cellular modems installed by vendors or system integrators that may not appear in routine attack surface scans.
The warning follows a coordinated cyberattack that struck OT systems at more than 30 community water utilities in Minnesota on July 26 and 27, according to Minnesota IT Services (MNIT). Cities including Maple Plain, Braham, South St. Paul, and Plymouth reported disrupted automated control functions, though contingency procedures kept water and wastewater operations functional and drinking water safe in most cases. State and federal agencies are actively investigating, but no formal attribution has been announced. Defenders can audit their own external attack surface with a port scanner to identify exposed controllers and OT endpoints before adversaries do.
The Minnesota incidents closely mirror tactics attributed to Iran-linked threat groups, including CyberAv3ngers and others tracked under advisory AA26-097A. The advisory was updated on July 22 to expand the list of targeted vendors beyond Rockwell Automation's Allen-Bradley controllers to include Schneider Electric and Siemens devices, naming specific models: Rockwell CompactLogix and Micro850, Schneider Electric Modicon M340, and Siemens S7-1200 series PLCs. Organizations responsible for critical infrastructure should immediately audit remote access paths, reset default and exposed credentials using a password checker to validate strength, and verify the legitimacy of upstream infrastructure via a WHOIS lookup for any unfamiliar domains or IP ranges. CISA recommends isolating OT networks from the public internet wherever feasible and segmenting exposed cellular modems behind authenticated, monitored gateways.