NEWS
CISA’s 100 Water System Hacks Hit One-Operator Plants
CISA counted over 100 exposed US water systems targeted in July, mostly through cellular-linked PLCs at thin-staffed plants, not a hardened national grid.
CISA said malicious activity hit internet-exposed systems at more than 100 U.S. water and wastewater entities in July, mostly through controllers tied to cellular modems. The figure appeared on Aug. 21 in federal guidance on shrinking internet exposure, the first official scale for a month that began in public as a Minnesota weekend.
The path was the one agencies have been naming for years. Programmable logic controllers that open valves, dose chemicals, and hold pressure were reachable from the public internet, often because a modem sat on the box.
More Than 100 Water Entities Were Reachable in July
THE JULY COUNT IN BRIEF
- The tally: CISA observed malicious activity against internet-exposed systems at more than 100 Water and Wastewater Systems Sector entities in July 2026.
- The common path: programmable logic controllers connected directly to a cellular modem, a setup the agency says creates serious security risk.
- The first public cluster: Minnesota IT Services said more than 30 community water systems were hit on July 26 and 27.
- The FBI window: utilities in at least seven states reported incidents after July 27, and some of that activity degraded water operations.
The Aug. 21 note is careful about what it is counting. It describes activity against internet-exposed systems at more than 100 water sector entities, not 100 towns without tap water. Attackers commonly reached those sites through PLCs hung off cellular modems, then changed device IP addresses and passwords, which cut monitoring and control and, in some cases, disrupted operations.
CISA’s July 30 sector alert, issued while the incidents were still landing, said the same campaign produced boil-water notices and long stretches of manual operations. It also said the targeting hit water entities of all sizes, including shops that already thought their attack surface was inventoried.
Attackers Changed Passwords and Cut Controllers Off the Network
The FBI and EPA, in a July 30 public service announcement, described a blunt sequence. After they reached internet-facing devices, the actors changed IP addresses and passwords, which produced a loss of monitoring and, in some cases, a loss of function on connected equipment. The bureau said it had observed that behavior on Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 series PLCs, and it warned other brands deserved the same scrutiny.
WHAT THE ATTACKERS CHANGED
| What they altered | What the plant lost |
|---|---|
| Controller passwords | Operators locked out of their own PLCs |
| Device IP addresses | Controllers dropped off the plant network |
| Project files and control logic | Loss of view, and in some cases loss of function |
| HMI and SCADA display data | Screens that no longer matched the physical process |
| Networked pumps and field stations | Pressure problems, flooding, and boil-water notices |
The FBI said reported operational effects included pressure loss and flooding. Pressure loss in a drinking-water system can let untreated groundwater seep into pipes. How far a site fell depended on whether the PLC was only watching equipment or actually running it, which MicroLogix model was in the cabinet, and whether crews could switch to manual.
That is a plant problem, not an office-network problem. In a lot of these sites nobody had to phish a clerk or hop a firewall. They found the box that runs the pump, because that box was sitting on a modem.
Minnesota’s Wave Arrived Four Days After a Federal Update
On July 22, CISA, the FBI, the NSA, the EPA, the Energy Department, U.S. Cyber Command, and Treasury updated a joint advisory first published on April 7. The update, AA26-097A, widened observed targeting from Rockwell Automation gear to Schneider Electric and Siemens controllers, and it added detection notes for tampered reusable code modules inside Rockwell programs.
Four days later, Minnesota IT Services reported a coordinated attack on operational technology at more than 30 community water systems. Towns that confirmed operational hits included Braham, where automated controls at the plant went down, and Plymouth, which took cellular-connected equipment at water towers and sewer lift stations offline. Maple Plain and South St. Paul also disclosed incidents. Minnesota health officials said drinking-water quality was not affected at the impacted systems.
The July 22 paper did not predict Minnesota by name. It did say Iranian-affiliated actors had been going after internet-connected PLCs across government services, water and wastewater, and energy since at least March 2026, using leased foreign infrastructure and the vendors’ own programming software. Inbound traffic showed up on ports 44818, 2222, 102, and 502, and on port 22 of some modems. Named product lines included Rockwell CompactLogix and Micro850 units, Schneider Electric Modicon M340 / BMX P34 controllers, and Siemens S7-1200 series PLCs.
Cybersecurity threats are a serious concern for our nation’s drinking water and wastewater systems, and these threats pose a legitimate risk to the communities, businesses, hospitals, schools, and other critical sectors that rely on these lifeline services.
Jess Kramer, EPA Assistant Administrator for Water, July 22 update
Rural systems felt the staffing pinch first, especially one-operator water plants in rural counties that have no spare crew when a controller goes dark and the plant has to be run by hand.
Aliquippa Already Ran This Playbook
The July method is a cousin of a campaign federal agencies documented in late 2023. IRGC-affiliated actors using the CyberAv3ngers persona went after internet-accessible Unitronics Vision Series PLCs and human-machine interfaces, including at U.S. water and wastewater sites. A joint advisory, AA23-335A, later said those actors compromised at least 75 devices, including at least 34 in the water sector in the United States. The Municipal Water Authority of Aliquippa, Pennsylvania, was the incident that put the pattern on the map: a pressure-regulating site was disrupted, crews moved to manual, and drinking water was not reported as contaminated.
AA26-097A treats that history as the same family of activity. It says CyberAv3ngers, also referred to in industry reporting under several other cluster names, is affiliated with Iran’s Islamic Revolutionary Guard Corps Cyber Electronic Command, and that the 2026 activity is meant to cause disruption inside the United States. The agencies say Iranian-affiliated targeting of U.S. critical infrastructure has recently escalated, likely in response to hostilities between Iran and the United States and Israel.
THE WARNINGS THAT CAME BEFORE JULY
- November 2023: IRGC-affiliated actors compromise internet-accessible Unitronics PLCs at U.S. water sites, including Aliquippa, often on default passwords.
- December 2024 update to AA23-335A: CISA reports at least 75 compromised devices and at least 34 in the U.S. water and wastewater sector.
- April 7, 2026: Joint advisory AA26-097A warns that Iranian-affiliated actors are exploiting internet-connected Rockwell PLCs across water, energy, and municipal systems.
- July 22, 2026: The same advisory expands to Schneider Electric and Siemens, and documents a victim where attackers added logic that overrode safe operating parameters.
- July 26-27, 2026: Minnesota reports a coordinated hit on more than 30 community water systems.
- July 30, 2026: CISA tells the sector to pull exposed PLCs off the internet; the FBI and EPA confirm incidents in at least seven states.
- August 19, 2026: NSA, CISA, the FBI, Energy, and EPA warn of an active threat to Siemens S7 series PLCs using AI-written scripts.
- August 21, 2026: CISA’s exposure-reduction guidance puts a number on July: more than 100 water and wastewater entities.
At one U.S. victim described in the July 22 update, the FBI watched the actors download a malicious project file with the vendor’s configuration software. The file kept downstream ladder logic working, then added logic that overrode instruction sets meant to keep the process inside safe limits. That is a quieter failure than a smashed pump. The plant can keep running while the interlock that should stop it, or the alarm that should wake someone, no longer does what the operators think it does.
Why Cellular Modems Keep Showing Up in These Hacks
CISA’s July 30 alert spent as much ink on undocumented connections as it did on passwords. Even utilities with mature cyber programs were told to re-check external links, because this activity includes cellular modems installed by operators, vendors, or system integrators that may never appear in a routine attack-surface scan. A lift station or a water tower gets a modem so someone can check a pump from a truck. The modem then becomes the front door.
The Aug. 21 guidance repeats the point in plainer language. Reducing internet exposure does not mean killing remote access that a crew actually needs. It means taking remote access off the PLC itself and putting it behind a gateway, a firewall, a VPN, or another centrally managed path. Directly connecting a controller to the internet through a cellular modem is the pattern July punished.
CISA also told owners to demand the external IP addresses of anything an integrator stood up, and to re-check those addresses if they change. Third-party remote access, vendor laptops, and leftover cellular kits are how a plant that thinks it is “offline” still answers a scan. Ports the agency wants operators to hunt include industrial standbys such as EtherNet/IP on 44818, Modbus on 502, and Siemens-style traffic on 102, plus the usual remote-access holes on SSH, Telnet, and RDP.
AI Scripts Now Probe Siemens S7 Controllers
On Aug. 19 the NSA, CISA, the FBI, the Energy Department, and the EPA issued a separate warning about Siemens S7 series PLCs. The authoring agencies said threat actors are doing reconnaissance and capability development against U.S. installations with AI-generated exploitation scripts for Siemens PLCs, dressed up as legitimate monitoring tools. They find internet-exposed controllers through scanning services, then aim at boxes running old software or weak authentication. Water and wastewater is on the target list, alongside manufacturing, energy, chemical plants, food and agriculture, and commercial facilities.
SIEMENS FAMILIES NAMED IN THE AUGUST WARNING
- S7-200 series: All CPU variants, still common in smaller skids and older plants.
- S7-300 series: All CPU variants, including 314, 315, and 317 models.
- S7-400 series: All CPU variants, often in larger process applications.
- S7-1200 series: CPU 1211C through 1217C variants, already named in the July 22 Iran-focused advisory.
- S7-1500 series: All CPU variants, including F-series safety controllers.
The technical picture is not a secret zero-day. Actors are combining the open-source snap7 / python-snap7 libraries, the same ones engineers use to talk to Siemens hardware, with AI-assisted Python scripts that read and write PLC memory, configuration, and ladder logic over the S7comm protocol. The August paper calls that an evolution in attacker capability, because it cuts the skill and time needed to build a working industrial script. If a controller is on the internet, it is at high risk.
The Siemens warning does not pin that activity on a named state. It sits on top of the July water incidents and the earlier Iran-affiliated advisory, and it tells every PLC owner, not only Siemens shops, to treat internet exposure as the urgent problem. The authoring agencies assess the pattern as persistent reconnaissance and capability development, with read access used to learn a plant before a later write that could disrupt it.
The Fix CISA Keeps Repeating
The July 30 alert’s punch list is short on purpose. Disconnect the PLC from the internet and put any needed remote access through a VPN or gateway, not straight onto the controller. Turn on password protection and change default passwords. Allowlist IP addresses so only known engineering laptops and other critical assets can talk to the box. After the disconnect, keep a known-clean backup of the PLC image, because a changed password is how operators get locked out of their own plant. Rockwell published a separate restore notice for MicroLogix 1400 units whose password is unknown.
By early August, CISA officials were still finding water-system controllers open on the internet with no password or a default password, even as they helped utilities recover. The homework did not change. Take the control gear off the public internet. Set a password.
WHAT WE KNOW
- July’s scale: CISA observed malicious activity against internet-exposed systems at more than 100 water and wastewater entities, commonly via PLCs on cellular modems.
- Confirmed effects: lockouts, lost monitoring and control, boil-water notices, manual operations, and FBI-reported pressure loss and flooding in some sites.
- The related campaign: AA26-097A, updated July 22, attributes ongoing PLC targeting across water, energy, and municipal systems to Iranian-affiliated actors active since at least March 2026.
- The 2023 precedent: the same advisory family documents IRGC-affiliated Unitronics compromises of at least 75 devices, including at least 34 U.S. water-sector units.
WHAT IS UNCONFIRMED
- A public unit-level ID for the July tally: the Aug. 21 100-count guidance and the July 30 sector alert do not name a country or group.
- Whether every July incident is one actor: Minnesota called its weekend coordinated and did not claim a single author for every hit.
- A full state list: the FBI cited at least seven states as of July 30; later public confirmations included Michigan, Georgia, South Dakota, and New Jersey, and federal agencies have not published a complete roster.
On July 31, President Donald Trump said he did not think there was an Iranian cyberattack and pointed at Minnesota, the first state to disclose the cluster. That public split is still sitting next to a July 22 joint advisory that does name Iranian-affiliated actors for the wider PLC campaign. Alignment with last year’s playbook is easy to copy, because an exposed controller with a weak password looks the same to any scanner. The part that no longer depends on a courtroom ID is the door. More than 100 water entities had a controller reachable in July, and CISA is still telling the sector to pull those boxes off the internet.
-
NEWS3 weeks agoThameslink Will Pad 60,000 Ironing-Board Seats From 2027
-
BUSINESS3 weeks agoBurger King Rebuilds Chicken Nuggets After Calling Them Rubbery
-
NEWS3 weeks agoTwenty Controllers Closed Norwich Airport for a Bank Holiday
-
NEWS3 weeks agoRoyal Caribbean Sends Los Angeles Ships to Singapore and Brisbane
-
NEWS3 weeks agoMicron Sells the Memory Shortage as Five-Year Contracts
-
BUSINESS3 weeks agoSweetmore Bakeries Buys Fantasy Baking for Bar Work
-
BUSINESS3 weeks agoU.S. Forces Clear Hormuz Mines, Then Hit Minelayers Again
-
NEWS3 weeks agoFrontier Miles Cuts Basic Fares After the Barclays Pact
