NEWS
Water PLC Hacks Echo 2023 Pattern as CISA Counts Pass 100
CISA now says more than 100 U.S. water systems faced PLC attacks in July 2026, far above early counts.
CISA now says malicious cyber activity targeted over 100 internet-exposed systems in the Water and Wastewater Systems sector during July 2026, most often through programmable logic controllers tied straight to cellular modems. Early public counts stayed near 30 community systems in Minnesota plus scattered hits elsewhere.
The revised figure, published in late August guidance, turns the month-long episode into the largest known municipal water cyber campaign on record and returns the sector to a vulnerability first exploited at scale three years earlier.
CISA Raises the Count to More Than 100 Systems
Federal agencies initially described a coordinated burst that began July 26-27 against operational technology at more than 30 Minnesota water and wastewater facilities. The FBI later stated that utilities in at least seven states had reported similar incidents, some of which degraded operations.
By late August the picture had widened. In its over 100 internet-exposed systems in the WWS Sector note, CISA wrote that it observed the activity “commonly via programmable logic controllers (PLCs) connected directly to a cellular modem.” Reporting and state confirmations place the affected systems across a dozen states that stretch coast to coast, among them Minnesota, Michigan, Wisconsin, South Dakota, Georgia, New Jersey and Alabama.
| Metric | Early public picture | Revised CISA picture |
|---|---|---|
| Systems targeted | ~30 in Minnesota + scattered | Over 100 nationwide |
| States | Minnesota focus, “few others” | At least 12 |
| Primary vector | Internet-facing Rockwell MicroLogix | PLCs (multiple vendors) via cellular modems |
| Public health impact | Boil notices, manual ops, no contamination reported | Same; some unsafe-condition risk if alarms disabled |
Illinois does not appear on the confirmed list. State rules also do not require water systems to notify law enforcement or the public after a computer intrusion, so any local hits could stay silent.
The Cellular Modem Blind Spot That Kept Recurring
Attackers did not need sophisticated zero-days. They reached controllers that operators, vendors or integrators had left reachable from the public internet, frequently through cellular links installed for remote monitoring. Once inside, they changed device passwords to lock operators out and altered IP addresses to drop the PLCs from the network.
CISA’s July 30 alert urged owners, operators and integrators to remove publicly exposed PLCs from the internet as soon as possible. The agency noted that even mature utilities can miss cellular modems installed by third parties that never appear on routine attack-surface scans.
Rockwell Automation MicroLogix 1100 and 1400 series devices featured heavily in the FBI’s early description. Later guidance and industry scans also flagged Siemens S7-1200, Schneider Electric Modicon and other brands. The common thread was direct internet exposure rather than a single firmware flaw.
On X and in industry channels the same observation kept surfacing: cheap remote connectivity created a permanent, scannable surface that threat actors simply keep probing. One reply to CISA’s own warning put it plainly: if a PLC needs the public internet for support, that path must be treated like a production control system, not a convenience feature.
Pressure Loss, Boil Notices and Manual Mode
Operational effects varied by what each PLC controlled. Some sites lost remote view and control. Others saw pressure drops or flooding. Pressure loss in a distribution network can allow untreated groundwater to seep into pipes, which is why several utilities issued boil-water notices and shifted to sustained manual operations while they restored clean configurations.
The FBI and EPA public service announcement documented loss of pressure and flooding at some sites. At least one organization found modified project files and ladder-logic discrepancies. CISA later noted that certain intrusions disabled shutdown processes and alarms, creating the potential for unsafe conditions without operator notification.
- Loss of view and control after password and IP changes locked operators out of the PLC.
- Boil-water notices issued while systems ran on manual oversight.
- Pressure anomalies and localized flooding where pumps or valves were affected.
- No confirmed contamination of finished drinking water supplies in public reports.
Most communities experienced temporary disruption rather than long outages. Rural and smaller systems felt the impact more sharply because they often lack spare staffing for extended manual runs.
Small Utilities Face Detection They Cannot Afford
Roughly 50,000 community water systems operate in the United States; about 91 percent serve fewer than 10,000 people. Many run on thin budgets, aging equipment and volunteer or part-time operators. Cyber detection and continuous monitoring sit far down the priority list.
Lesley Carhart, a critical-infrastructure first responder at Dragos and a Naperville native, told NBC Chicago the detection gap is structural. “The ability for small water utilities to detect a cyber incident and cyber threat is out of reach due to funding cuts and limited budgets,” she said. “A lot of them didn’t know for a long time, unfortunately.”
People have had the same objectives in terms of sabotaging infrastructure for a long time, but once there’s an idea out there, like these utilities are exposed, they are easy to find and tools like AI and LLM can allow you to understand how to interact with them a little. People start using other people’s experiences to launch their own attacks and try the same tactics. So the knowledge is out there, the genie is out of the bottle.
Lesley Carhart, critical infrastructure first responder, Dragos
Carhart described the July wave as both predictable and preventable. Once scanners and scripts circulate, copycat activity follows. AI tools simply lower the skill bar for mapping and interacting with exposed devices.
Volunteer programs such as DEF CON Franklin have begun pairing outside cyber talent with rural systems, yet the scale remains tiny next to the 45,000-plus small utilities that need routine help.
The 2023 Unitronics Playbook Returned
The tactics and the target set are not new. In late 2023, IRGC-affiliated actors known as CyberAv3ngers compromised Unitronics Vision Series PLCs at multiple U.S. water facilities, including a booster station in Aliquippa, Pennsylvania. They left defacement messages and forced operators onto manual control. A joint advisory later confirmed the same group had hit devices across several states by exploiting default credentials and internet exposure.
CISA, FBI, NSA, EPA and partners updated their Iranian-affiliated PLC advisory in April 2026 and again on July 22, just days before the Minnesota burst. That document assessed that Iranian-affiliated actors targeting PLCs since at least 2023 were still active against Rockwell, Schneider, Siemens and other brands, using leased foreign infrastructure and manufacturer programming software to reach misconfigured devices on ports such as 44818, 2222, 102 and 502.
- November 2023: CyberAv3ngers begin exploiting Unitronics PLCs at U.S. water sites; CISA issues emergency guidance.
- April 7, 2026: Joint advisory AA26-097A warns of ongoing Iranian-affiliated PLC targeting across water, energy and government sectors.
- July 22, 2026: Advisory updated with new Rockwell code-module guidance and broader vendor scope.
- July 26-27, 2026: Coordinated activity hits 30-plus Minnesota systems; FBI later confirms seven-plus states.
- July 30, 2026: CISA and FBI/EPA issue fresh alerts urging immediate removal of internet-exposed PLCs.
- Late August 2026: CISA exposure-reduction guidance states the July activity reached over 100 systems.
Attribution for the July wave remains “likely” Iranian in intelligence assessments and media reports citing officials, but federal agencies have stopped short of a definitive public claim. Some investigators have also considered false-flag possibilities amid broader U.S.-Iran tensions. The technical pattern, however, matches the earlier campaigns exactly: find exposed PLCs, alter configuration, force manual recovery.
What Federal Guidance Now Demands
CISA, FBI and EPA recommendations have been consistent across three years of alerts. The core steps are mechanical and low-cost relative to the risk.
- Disconnect PLCs and other OT from direct internet access; route any necessary remote connections through a VPN, jump host or secure gateway.
- Change default passwords, enforce unique complex credentials, and enable password protection where it exists.
- Place physical and software key switches into run mode to block unauthorized logic or firmware changes.
- Inventory and secure cellular modems, including private APNs or site-to-site VPNs where possible; log and review modem traffic.
- Maintain tested clean backups of PLC images and the ability to operate fully in manual mode.
- Use free services such as CISA Cyber Hygiene scanning and publicly available exposure tools (Shodan, Censys) to find unintended open ports on organizational IP space.
- Replace end-of-life controllers on a planned schedule; isolate those that cannot yet be upgraded.
Rockwell published specific recovery guidance for MicroLogix 1400 devices locked by unknown passwords. EPA offers a Cybersecurity Technical Assistance Program for the water sector. Reporting channels remain CISA’s 24/7 operations center, FBI field offices and IC3.
Legislation introduced after the July incidents would expand EPA assessment authority, mandate more incident reporting for publicly owned systems, and authorize hundreds of millions in revolving-fund support for cyber upgrades. Whether those measures pass and reach the smallest systems is still open.
Three years after Unitronics and one month after the Minnesota burst, the same class of controller still sat on the open internet via cellular links. The higher CISA count simply made the unfinished work visible at national scale. Operators who pull those devices offline and lock the remaining paths shut the door the next scan will try.
-
FINANCE3 months agoZcash Patched a Double-Spend Bug as ZEC Climbed 5%
-
ENTERTAINMENT3 months agoSteam Summer Sale 2026 Locks In June 25 to July 9 Dates
-
FINANCE2 months agoCLARITY Act Final Text Expected This Weekend as 60-Vote Hurdle Looms
-
NEWS4 months agoMeta Adds AI Replies to Threads, But Users Can’t Block It
-
NEWS3 months agoYouTube Shorts is testing a heart in place of the thumbs-up
-
NEWS4 weeks agoSenators Force Apple Off Chinese Memory as Big Three Cash In
-
NEWS3 months agoNEURA Robotics’ $1.4B Series C Redraws Europe’s Physical AI Bet
-
ENTERTAINMENT5 months agoExtraction 3 Is Officially Coming to Netflix in 2027
