July 31, 2026•4 min read

CISA Urges Water Sector to Secure OT Amid Rising Cyber Threats

CISA has issued a critical alert urging the water sector to bolster operational technology (OT) security following recent coordinated attacks on programmable logic controllers (PLCs) in Minnesota.

Technician monitoring water treatment facility control systems

The US Cybersecurity and Infrastructure Security Agency (CISA) is sounding alarms for water and wastewater system (WWS) operators to enhance the protection of operational technology (OT) systems against a surge of cyberattacks targeting programmable logic controllers (PLCs). This urgent call to action follows a series of recent cyber intrusions that disrupted automated functionalities at multiple water utilities in Minnesota.

CISA's Recent Alert

On July 30, 2026, CISA published its latest alert indicating a sharp increase in malicious activities aimed at PLCs within the water and wastewater sectors. The agency emphasized the need for critical infrastructure operators to take immediate actions, particularly in removing publicly accessible PLCs and other OT infrastructures from the internet.

Details of the Recent Attacks

This renewed caution comes in light of coordinated cyber assaults observed from July 26 to 27, 2026, which adversely impacted the OT systems of more than 30 community water systems in Minnesota, as confirmed by the Minnesota IT Services (MNIT). Several municipalities, including Maple Plain, Braham, South St. Paul, and Plymouth, reported disruptions in automated control functions. Despite the attacks, contingency measures ensured that water and wastewater services remained operational, with local authorities assuring residents of safe drinking water.

The Nature of the Threats

CISA outlined specific tactics that assailants have employed in targeting PLCs. Incidents of attackers altering passwords to lock operators out of systems were noted, along with disconnecting controllers by changing their IP addresses. Such invasive actions have led to distressing outcomes, including the issuance of "boil water notices" to residents and prolonged reliance on manual operational procedures. The trend reflects a worrying pattern that spans various sizes of water entities, highlighting the vulnerability even of those equipped with advanced cybersecurity programs.

Connections to Iranian Cyber Operations

The timing of these intrusions raises concerns, especially as they coincide with US government alerts regarding Iran-linked cyber threats directed at industrial control systems. A prior advisory from CISA updated on July 22, 2026, expanded the scope of potentially targeted vendors to include companies like Siemens and Schneider Electric, in addition to Rockwell Automation. Investigations revealed attempts against specific PLC models, such as Rockwell's CompactLogix and Micro850, Schneider Electric's Modicon M340, and Siemens' S7-1200 series.

CISA noted that Iranian groups like CyberAv3ngers and Handala may fit the profile for the types of cyber activities observed in Minnesota, leveraging similar operational strategies as seen in previous incidents, such as vulnerabilities in cellular routers.

Recommended Security Measures for Operators

CISA's recommendations for water and wastewater system operators remain critical in mitigating risks associated with cyber threats:

  • Disconnect PLCs from the Internet: Operators must eliminate direct internet exposure of PLCs and should facilitate remote access through secure VPN or gateway devices.
  • Implement Strong Password Protections: Changing default passwords and enabling robust password protection is essential for safeguarding against unauthorized access.
  • Whitelisting IP Addresses: Allowlisting only known IP addresses for remote access helps minimize exposure to malicious actors.

Furthermore, operators should maintain verified backups of PLC images and consult dedicated recovery guidance from manufacturers, particularly for Rockwell Automation’s MicroLogix 1400 controllers, to ensure quick restoration capabilities.

CISA representatives outlining best practices for cybersecurity

Steps for Enhanced Operational Security

Beyond immediate actions, CISA encourages utilities to conduct thorough reviews of tactics, techniques, and indicators of compromise detailed in advisory AA26-097A. This includes vigilance for signs of both current and historical malicious activities on their networks. Regular updates and scans of system configurations can significantly reduce vulnerabilities.

Investigation and Continuing Monitoring

Following the Minnesota attacks, both state and federal agencies are conducting investigations to determine the full extent of the cyber intrusions. As of now, no specific perpetrators have been publicly identified, and investigations remain ongoing. The coordinated nature of the attacks, coupled with the involvement of groups suspected of Iranian backing, signals a serious landscape of threats facing critical infrastructure in the US.

Key Takeaways

  • CISA has issued a warning regarding increased cyber threats against water and wastewater systems.
  • Recent coordinated cyberattacks affected over 30 community water systems in Minnesota.
  • Operators are urged to disconnect PLCs from the internet and enhance password protections.
  • Iran-linked groups are suspected in targeting critical infrastructure, emphasizing the need for robust cybersecurity measures.
  • CISA recommends regular reviews of networks and systems to detect any signs of compromise.

Conclusion

The increasing cyber threats against operational technology in the water sector underline a critical need for vigilance and proactive cybersecurity measures. As CISA continues to monitor and respond to these threats, water system operators must prioritize the security of their infrastructure to protect the health and safety of communities.

Frequently Asked Questions

CISA issued a warning following coordinated cyberattacks on over 30 water utilities in Minnesota that disrupted automated controls.
#CISA#water security#cybersecurity#PLC attacks#critical infrastructure