
A recent string of cyber attacks on U.S. water systems underscores the threat the municipal water sector is facing and the criticality of emergency preparedness and cybersecurity measures.
According to multiple news reports, cyber attacks across seven states last week were reported to the Federal Bureau of Investigation (FBI). News of the cyber incidents followed another report that more than 30 water systems in Minnesota were targeted in a coordinated cyber attack last weekend. The seven states affected in the most recent attack were not named, but according to a CBS News report and others, Minnesota and Michigan were among seven states with utilities affected.
The Cybersecurity and Infrastructure Security Agency (CISA) is urging critical infrastructure owners, operators and integrators to remove publicly exposed programmable logic controllers (PLC) devices and other operational technology (OT) from the internet as soon as possible.
CISA said it is currently observing a significant increase in cyber threat actors targeting PLC devices in the water and wastewater sector. The agency said threat actors targeting exposed PLCs have modified passwords to lock out operators and have disconnected the PLCs by changing their IP addresses.
The activity resulted in boil water notices and sustained manual operations, CISA said. Despite the incidents, multiple reports have said there has been no reported contamination of municipal drinking water as as result.
Cyber, physical security fact sheets offer tips for utilities
Threat actors are targeting water entities of all sizes, CISA said. In an advisory, CISA also said water organizations with mature cybersecurity processes should validate their external connections, as the targeting activity includes cellular modems installed by operators, vendors or system integrators that may not be documented or included in routine attack surface scans.
CISA said OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage. It recommends organizations implement the following mitigations:
- Disconnect the PLC from the internet. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC.
- Enable password protection and change default passwords.
- Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets.
More on CISA’s recent recommendations can be found here.
While attribution of these attacks remains pending federal investigation, many have pointed out that the timing coincides with escalating Iranian-affiliated PLC exploitation activity documented in CISA Advisory AA26-097A.
That CISA advisory, published July 22, said the authoring agencies of CISA are urgently warning U.S. organizations of ongoing cyber exploitation of internet-connected OT devices — including PLCs manufactured by Rockwell Automation/Allen-Bradley, Schneider Electric, Siemens, and potentially other manufactured PLCs — across multiple U.S. critical infrastructure sectors.
The FBI and U.S. Environmental Protection Agency (EPA) also recently issued a Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/AllenBradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. The FBI said that while it has only observed this behavior with the referenced Rockwell PLCs, similar considerations should also be made with other branded PLCs.
The National Rural Water Association (NRWA) said it, along with its State Rural Water Associations are engaging in conversations with federal partners about this issue. If you need assistance, please contact your State Rural Water Association or your local CISA Regional Office.
Cyber Treats in the U.S. Water Sector
The water sector has experienced an escalation in threats over recent years, from physical security breaches to cyber attacks from foreign adversaries, including ransomware attacks and infiltration of online utility programs.
Fitch Ratings: Iran conflict elevates cyber risk for public finance
Earlier in February, the U.S. Environmental Protection Agency (EPA) highlighting what it called “progress” in protecting water systems from cyberattacks in 2025. EPA’s Office of Water said it proactively identified cybersecurity vulnerabilities at 277 water systems and worked to fix the issues with individualized solutions ranging from authentication protocols to enforcing strict access controls along with other technical updates and restrictions.
EPA said those cyber weaknesses included critical system components, such as technologies that control drinking water and wastewater processes, that are attractive targets to potential threat actors. The agency said the work is critical to safeguarding U.S. public health and economic growth.
Source/s: CISA, EPA, WaterISAC








Leave a Reply