Connect with us

NEWS

Water PLC Hacks Echo 2023 Pattern as CISA Counts Pass 100

CISA now says more than 100 U.S. water systems faced PLC attacks in July 2026, far above early counts.

Published

on

CISA now says malicious cyber activity targeted over 100 internet-exposed systems in the Water and Wastewater Systems sector during July 2026, most often through programmable logic controllers tied straight to cellular modems. Early public counts stayed near 30 community systems in Minnesota plus scattered hits elsewhere.

The revised figure, published in late August guidance, turns the month-long episode into the largest known municipal water cyber campaign on record and returns the sector to a vulnerability first exploited at scale three years earlier.

CISA Raises the Count to More Than 100 Systems

Federal agencies initially described a coordinated burst that began July 26-27 against operational technology at more than 30 Minnesota water and wastewater facilities. The FBI later stated that utilities in at least seven states had reported similar incidents, some of which degraded operations.

By late August the picture had widened. In its over 100 internet-exposed systems in the WWS Sector note, CISA wrote that it observed the activity “commonly via programmable logic controllers (PLCs) connected directly to a cellular modem.” Reporting and state confirmations place the affected systems across a dozen states that stretch coast to coast, among them Minnesota, Michigan, Wisconsin, South Dakota, Georgia, New Jersey and Alabama.

Metric Early public picture Revised CISA picture
Systems targeted ~30 in Minnesota + scattered Over 100 nationwide
States Minnesota focus, “few others” At least 12
Primary vector Internet-facing Rockwell MicroLogix PLCs (multiple vendors) via cellular modems
Public health impact Boil notices, manual ops, no contamination reported Same; some unsafe-condition risk if alarms disabled

Illinois does not appear on the confirmed list. State rules also do not require water systems to notify law enforcement or the public after a computer intrusion, so any local hits could stay silent.

The Cellular Modem Blind Spot That Kept Recurring

Attackers did not need sophisticated zero-days. They reached controllers that operators, vendors or integrators had left reachable from the public internet, frequently through cellular links installed for remote monitoring. Once inside, they changed device passwords to lock operators out and altered IP addresses to drop the PLCs from the network.

CISA’s July 30 alert urged owners, operators and integrators to remove publicly exposed PLCs from the internet as soon as possible. The agency noted that even mature utilities can miss cellular modems installed by third parties that never appear on routine attack-surface scans.

Rockwell Automation MicroLogix 1100 and 1400 series devices featured heavily in the FBI’s early description. Later guidance and industry scans also flagged Siemens S7-1200, Schneider Electric Modicon and other brands. The common thread was direct internet exposure rather than a single firmware flaw.

On X and in industry channels the same observation kept surfacing: cheap remote connectivity created a permanent, scannable surface that threat actors simply keep probing. One reply to CISA’s own warning put it plainly: if a PLC needs the public internet for support, that path must be treated like a production control system, not a convenience feature.

Pressure Loss, Boil Notices and Manual Mode

Operational effects varied by what each PLC controlled. Some sites lost remote view and control. Others saw pressure drops or flooding. Pressure loss in a distribution network can allow untreated groundwater to seep into pipes, which is why several utilities issued boil-water notices and shifted to sustained manual operations while they restored clean configurations.

The FBI and EPA public service announcement documented loss of pressure and flooding at some sites. At least one organization found modified project files and ladder-logic discrepancies. CISA later noted that certain intrusions disabled shutdown processes and alarms, creating the potential for unsafe conditions without operator notification.

  • Loss of view and control after password and IP changes locked operators out of the PLC.
  • Boil-water notices issued while systems ran on manual oversight.
  • Pressure anomalies and localized flooding where pumps or valves were affected.
  • No confirmed contamination of finished drinking water supplies in public reports.

Most communities experienced temporary disruption rather than long outages. Rural and smaller systems felt the impact more sharply because they often lack spare staffing for extended manual runs.

Small Utilities Face Detection They Cannot Afford

Roughly 50,000 community water systems operate in the United States; about 91 percent serve fewer than 10,000 people. Many run on thin budgets, aging equipment and volunteer or part-time operators. Cyber detection and continuous monitoring sit far down the priority list.

Lesley Carhart, a critical-infrastructure first responder at Dragos and a Naperville native, told NBC Chicago the detection gap is structural. “The ability for small water utilities to detect a cyber incident and cyber threat is out of reach due to funding cuts and limited budgets,” she said. “A lot of them didn’t know for a long time, unfortunately.”

People have had the same objectives in terms of sabotaging infrastructure for a long time, but once there’s an idea out there, like these utilities are exposed, they are easy to find and tools like AI and LLM can allow you to understand how to interact with them a little. People start using other people’s experiences to launch their own attacks and try the same tactics. So the knowledge is out there, the genie is out of the bottle.

Lesley Carhart, critical infrastructure first responder, Dragos

Carhart described the July wave as both predictable and preventable. Once scanners and scripts circulate, copycat activity follows. AI tools simply lower the skill bar for mapping and interacting with exposed devices.

Volunteer programs such as DEF CON Franklin have begun pairing outside cyber talent with rural systems, yet the scale remains tiny next to the 45,000-plus small utilities that need routine help.

The 2023 Unitronics Playbook Returned

The tactics and the target set are not new. In late 2023, IRGC-affiliated actors known as CyberAv3ngers compromised Unitronics Vision Series PLCs at multiple U.S. water facilities, including a booster station in Aliquippa, Pennsylvania. They left defacement messages and forced operators onto manual control. A joint advisory later confirmed the same group had hit devices across several states by exploiting default credentials and internet exposure.

CISA, FBI, NSA, EPA and partners updated their Iranian-affiliated PLC advisory in April 2026 and again on July 22, just days before the Minnesota burst. That document assessed that Iranian-affiliated actors targeting PLCs since at least 2023 were still active against Rockwell, Schneider, Siemens and other brands, using leased foreign infrastructure and manufacturer programming software to reach misconfigured devices on ports such as 44818, 2222, 102 and 502.

  1. November 2023: CyberAv3ngers begin exploiting Unitronics PLCs at U.S. water sites; CISA issues emergency guidance.
  2. April 7, 2026: Joint advisory AA26-097A warns of ongoing Iranian-affiliated PLC targeting across water, energy and government sectors.
  3. July 22, 2026: Advisory updated with new Rockwell code-module guidance and broader vendor scope.
  4. July 26-27, 2026: Coordinated activity hits 30-plus Minnesota systems; FBI later confirms seven-plus states.
  5. July 30, 2026: CISA and FBI/EPA issue fresh alerts urging immediate removal of internet-exposed PLCs.
  6. Late August 2026: CISA exposure-reduction guidance states the July activity reached over 100 systems.

Attribution for the July wave remains “likely” Iranian in intelligence assessments and media reports citing officials, but federal agencies have stopped short of a definitive public claim. Some investigators have also considered false-flag possibilities amid broader U.S.-Iran tensions. The technical pattern, however, matches the earlier campaigns exactly: find exposed PLCs, alter configuration, force manual recovery.

What Federal Guidance Now Demands

CISA, FBI and EPA recommendations have been consistent across three years of alerts. The core steps are mechanical and low-cost relative to the risk.

  • Disconnect PLCs and other OT from direct internet access; route any necessary remote connections through a VPN, jump host or secure gateway.
  • Change default passwords, enforce unique complex credentials, and enable password protection where it exists.
  • Place physical and software key switches into run mode to block unauthorized logic or firmware changes.
  • Inventory and secure cellular modems, including private APNs or site-to-site VPNs where possible; log and review modem traffic.
  • Maintain tested clean backups of PLC images and the ability to operate fully in manual mode.
  • Use free services such as CISA Cyber Hygiene scanning and publicly available exposure tools (Shodan, Censys) to find unintended open ports on organizational IP space.
  • Replace end-of-life controllers on a planned schedule; isolate those that cannot yet be upgraded.

Rockwell published specific recovery guidance for MicroLogix 1400 devices locked by unknown passwords. EPA offers a Cybersecurity Technical Assistance Program for the water sector. Reporting channels remain CISA’s 24/7 operations center, FBI field offices and IC3.

Legislation introduced after the July incidents would expand EPA assessment authority, mandate more incident reporting for publicly owned systems, and authorize hundreds of millions in revolving-fund support for cyber upgrades. Whether those measures pass and reach the smallest systems is still open.

Three years after Unitronics and one month after the Minnesota burst, the same class of controller still sat on the open internet via cellular links. The higher CISA count simply made the unfinished work visible at national scale. Operators who pull those devices offline and lock the remaining paths shut the door the next scan will try.

As the founder of Thunder Tiger Europe Media, Dr. Elias Thornwood brings over 25 years of experience in international journalism, having reported from conflict zones in the Middle East, Asia, and Africa for outlets like BBC World and Reuters. With a PhD in International Relations from Oxford University, his expertise lies in geopolitical analysis and global diplomacy. Elias has authored two bestselling books on European foreign policy and received the Pulitzer Prize for International Reporting in 2015, establishing his authoritativeness in the field. Committed to trustworthiness, he enforces rigorous fact-checking protocols at Thunder Tiger, ensuring unbiased, evidence-based coverage of worldwide news to empower informed global audiences.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending