Overview
- CISA disclosed that in July 2026 it observed malicious activity against more than 100 internet‑exposed water and wastewater systems that used directly reachable programmable logic controllers, often tied to cellular modems.
- The intruders remotely accessed PLCs, changed device IP addresses and passwords, and in some cases disabled alarms or shutdown controls, creating monitoring losses and localized operational disruptions without causing widespread loss of water service.
- U.S. investigators say attackers are using AI‑assisted tooling and public code to generate scripts that target PLCs from vendors such as Siemens, Rockwell and Schneider Electric, and U.S. intelligence assesses Iran‑linked actors are likely though formal public attribution has not been made.
- CISA, the FBI and EPA are investigating and CISA has issued exposure‑reduction guidance that tells utilities to inventory internet‑accessible devices, remove unnecessary exposures, route remote access through secure gateways, apply patches, use unique credentials, and enable multi‑factor authentication.
- The incidents highlight chronic gaps in small and rural water utilities that use legacy PLCs and direct internet or cellular connections, and they renew policy calls for federal funding, mandatory cyber standards, and shared services to help operators track and secure OT devices.