Connect with us

NEWS

CISA’s 100 Water System Hacks Hit One-Operator Plants

CISA counted over 100 exposed US water systems targeted in July, mostly through cellular-linked PLCs at thin-staffed plants, not a hardened national grid.

Published

on

CISA said attackers targeted over 100 internet-exposed U.S. water and wastewater systems in July, often through programmable logic controllers tied straight to cellular modems. The tally counts targeted systems, not 100 confirmed plant takeovers.

The people who felt it were the small crews who already run the well, drive the truck, and pick up the phone. In Braham, Minnesota, those crews restarted a shut well by hand before lunch.

CISA Counted More Than 100 Exposed Water Systems in July

In guidance on cutting internet exposure, CISA wrote that it observed malicious activity against over 100 internet-exposed systems in the Water and Wastewater Systems sector during July 2026, commonly through PLCs connected directly to a cellular modem. Directly connecting those controllers that way, the agency said, can create significant security risks.

THE JULY COUNT

  • Federal tally: CISA logged targeting of over 100 internet-exposed water and wastewater systems in July 2026.
  • Minnesota cluster: Minnesota IT Services said a coordinated attack hit operational technology at more than 30 community water systems on July 26 and 27.
  • FBI map: Since July 27, utilities in at least seven states reported incidents, and some of that activity degraded water operations.
  • The door: CISA said the path was often a PLC sitting on a cellular modem, including gear that never showed up in routine scans.

CISA Acting Executive Assistant Director for Cybersecurity Chris Butera had already warned, on July 22, that Iranian-affiliated actors were compromising unsecure internet-connected accounts and devices. FBI Assistant Director Brett Leatherman said Iranian cyber actors continue to target U.S. critical infrastructure. Officials have not publicly named the group behind the July water incidents in the same way they named CyberAv3ngers for the 2023 Unitronics wave.

Waiting on a flag does not pull a modem off a well. The number that moved in August was the exposure count, and it describes devices that answered from a phone network.

The Operator Who Also Drives the Truck

Nicole Tisdale, founder of Advocacy Blueprints and a former House Homeland Security and White House National Security Council staffer, told a House subcommittee on May 21, 2026, who actually keeps most of the country on tap.

There are roughly 50,000 community water systems across the United States. More than 91 percent of them serve fewer than 10,000 people. More than 81 percent serve fewer than 3,300.

Nicole Tisdale, Founder, Advocacy Blueprints, House Science subcommittee testimony

Those shares are the labor market the July attacks walked into. Tisdale’s 91 percent serve fewer than 10,000 figure is the starting point, not a side note.

THE BENCH INSIDE A SMALL PLANT

  • The second job: In most rural water systems, Tisdale said, the operator who runs the treatment plant also drives the truck, reads the meters, and answers the phone.
  • The retirement wave: Fifty-seven percent of rural water operators plan to retire within ten years, and nearly one-third within five.
  • The price gap: Cyber tools cost three to five times more per person in small communities than in large ones, and rural cyber roles take roughly 70 percent longer to fill.
  • The single point: Unlike big city systems with spare plants, most rural systems run one treatment plant, one operator, and one set of controls.

CISA still said the actors are targeting water entities of all sizes, including shops with mature cyber processes. That line is true, and it does not change the math of the sector. A 2024 EPA survey, cited in Tisdale’s testimony from an EPA inspector general report, found 97 drinking water systems serving 26 million people had critical or high-risk cybersecurity weaknesses. More than 400 military installations rely on civilian water systems, many of them rural, for drinking water, firefighting, and waste treatment.

Cellular Modems Were the Open Door

The remote gear that lets a one-person crew check a well at 2 a.m. is the same gear CISA told operators to hunt. The July 30 alert said even mature organizations should validate external connections, because the targeting includes cellular modems installed by vendors, operators, or system integrators that may not be documented or included in routine attack surface scans.

Braham officials later said the issue was limited to equipment connected via cellular communications, and crews kept working through manual procedures. That is the night-shift workaround in hardware form. A contractor mounts a modem so nobody has to sit in the pump house. Years later the inventory still says the controller is private.

Censys, in a July 30, 2026 snapshot issued after the CISA alert, counted internet-visible hosts for the three vendors CISA had named. The firm said the figures characterize exposure and do not confirm that any specific host was a victim.

INTERNET-VISIBLE INDUSTRIAL HOSTS

Vendor gear in the Censys snapshot Hosts seen July 30, 2026 What the count is
Rockwell/Allen-Bradley EtherNet/IP 4,148 Vendor-wide hosts, not confirmed victims
Siemens SIMATIC S7-1200 4,117 Named PLC family, exposure only
Schneider Electric 2,072 Vendor-wide, not PLC-scoped

Those controllers left on the public internet are how a password change becomes a plant shutdown. CISA’s first fix is not a new detection platform. It is to disconnect the PLC from the internet and send any needed remote access through a VPN or gateway, not straight to the controller.

What the FBI Logged After the Lockouts

The FBI and EPA said the actors were hitting internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs, then changing IP addresses and turning on and setting passwords. Operators lost view of the equipment, and in some cases lost function. The FBI has only observed that behavior on those Rockwell units so far, and it said similar care should apply to other brands.

Operational effects reported to the FBI included loss of pressure and flooding. Pressure loss in water systems, the bureau said, could potentially allow untreated ground water to seep into pipes. At least one organization reported modified PLC project files after noticing ladder logic discrepancies across several sites. Across several victims, similar third-party network setups gave the actors a chance to repeat the same hit at the next customer.

CISA’s July 30 alert put the human result in one line. Threat actors modified passwords to lock out operators and disconnected PLCs by changing their IP addresses, and this activity has resulted in boil water notices and sustained manual operations. Some intrusions, CISA has said, let attackers modify PLCs to disable shutdown processes and alarms, which can create unsafe conditions without notifying the operators.

Braham is where that lockout met a well. The city said around 9:30 a.m. on July 27 that its water treatment plant was offline for an unknown reason. A few hours later it named the cause.

This attack did not alter or cause any issue to the physical water plant or water quality or safety. Rather, the attackers shut down the operating controls, which shut down the well and water treatment plant.

City of Braham, Minnesota, July 27, 2026 statement

Workers isolated the affected system, restored a backup, and restarted the plant in about 90 minutes, Mayor Nate George said. Residents did not lose water. The city’s water tower typically holds enough drinking water to last about two days, and operators found the problem before an automated alert, so the pump had been offline only briefly. George’s account is the job description Tisdale described, executed under a clock.

Maple Plain, west of Minneapolis, declared a local emergency on July 27 after malicious activity hit portions of its public drinking water system. Mayor Julie M. Maas-Kusske terminated the local emergency on July 29 after staff, emergency managers, and utility operators said the immediate threat to public health had been addressed. City personnel kept water and wastewater running on contingency procedures. Maple Plain said drinking water service was not interrupted and it had no indication that quality or safety was compromised.

Aliquippa’s 2023 Script at a Larger Scale

The method is older than this July. In November 2023, IRGC-affiliated actors using the CyberAv3ngers persona compromised internet-accessible Unitronics Vision Series PLCs, often with default or no passwords, and left a defacement that named Israeli-made gear as a target. The Municipal Water Authority of Aliquippa, Pennsylvania, was the case that made the national wire. Between November 2023 and January 2024, CISA later said, the actors compromised at least 75 devices, including at least 34 in the U.S. water and wastewater sector.

THE ROAD TO THE JULY WAVE

  1. November 22, 2023: IRGC-affiliated actors begin hitting U.S. water facilities that run internet-accessible Unitronics Vision Series PLCs, often with default passwords.
  2. April 7, 2026: CISA, the FBI, the EPA, and partners publish advisory AA26-097A on Iranian-affiliated actors exploiting internet-connected Rockwell PLCs across water, energy, and government services.
  3. July 22, 2026: The same advisory expands to observed targeting of Schneider Electric and Siemens PLCs and adds guidance on malicious changes in reusable Rockwell code modules.
  4. July 26-27, 2026: Minnesota IT Services records a coordinated attack on operational technology at more than 30 community water systems.
  5. July 30, 2026: CISA and the FBI tell operators to pull exposed PLCs off the internet after password and IP lockouts, boil water notices, pressure loss, and flooding.

EPA Assistant Administrator for Water Jess Kramer said cybersecurity threats pose a legitimate risk to the communities, businesses, hospitals, schools, and other critical sectors that rely on drinking water and wastewater. The July 22 update described Iranian-affiliated activity that attempted to download malicious project files and manipulate data on HMI and SCADA displays, with operational disruption and financial loss at affected organizations.

The 2023 playbook used default passwords on a single Israeli brand. The 2026 wave, as CISA and the FBI describe it, uses the same class of mistake across Rockwell, Schneider, and Siemens, plus cellular modems that never made the asset list. Attackers did not need ransomware to take a well offline. They needed a controller that answered from the public internet and a password they could change.

Why Small Plants Stay Reachable

America’s Water Infrastructure Act of 2018 required community water systems serving more than 3,300 people to run risk and resilience assessments that include computer systems. That cutoff leaves the 81 percent of systems under 3,300 outside the same paper mandate. CISA still told every size of utility to disconnect exposed PLCs, enable password protection, change defaults, and allowlist remote access from known engineering laptops.

Brigit Hirsch, EPA press secretary, said many small water and wastewater systems lack dedicated cybersecurity staff, which opens gaps in monitoring, upgrades, and patching. Since a 2024 program began, she said, it has helped over 600 water systems mitigate over 800 internet-facing vulnerabilities, many of them human-machine interfaces. New exposures keep turning up. EPA has automated some HMI hunting and is trying to reach the system integrators who actually install the OT networks small utilities depend on.

The FBI’s own punch list matches that thin bench. Disconnect the PLC from the public internet. Secure cellular modems used for remote field access, turn on modem logs, and consider private APNs, VPNs, or similar isolated architectures. Keep the physical and software key switches in run mode so nobody can quietly rewrite logic. Practice running the plant by hand, because that is what Braham did in 90 minutes. Plan replacements for end-of-life hardware that no longer gets patches, which the bureau said attackers routinely target.

Rockwell published a notice on restoring access to a MicroLogix 1400 when the password is unknown, and CISA pointed MicroLogix 1400 owners there after the lockouts. That document exists because operators were already locked out of their own controllers.

No Spare Controls at Most Rural Plants

CISA’s August count did not say 100 towns lost drinking water. It said more than 100 internet-exposed systems were targeted in one month, commonly through PLCs on cellular modems, in a sector where most plants are small, rural, and run by people who already have another job before the pager goes off.

In Braham the tower held, the backup came up, and the water stayed drinkable. Maple Plain lifted its emergency in two days. The next plant that loses view of a pump will still be asking whether the modem on the cabinet was ever on the list, and whether anyone is in the building when the password changes.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending