CISA Confirms Over 100 Internet-Exposed Water Systems Targeted in July

New CISA data reveals over 100 water utilities were hit by Iranian hackers in July, exposing critical vulnerabilities in industrial control systems.

By Central
CISA confirms over 100 internet-exposed water systems were targeted in a coordinated Iranian cyberattack campaign.
Highlights
  • CISA confirmed that over 100 water and wastewater systems were targeted by Iranian hackers in July 2026.
  • The attackers exploited programmable logic controllers connected directly to cellular modems, bypassing normal network security.
  • The breach has accelerated calls for a Senate bill to create a centralized Water Watch Center for threat monitoring.

The scale of cyberattacks against American water utilities is far larger than previously disclosed. In July 2026, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed that malicious cyber activity targeted more than 100 internet-exposed systems in the Water and Wastewater Systems (WWS) sector. This figure, the first official quantification of the incident, marks a critical turning point in the ongoing struggle to secure critical infrastructure from nation-state adversaries. The attacks, attributed to Iranian threat actors, exploited programmable logic controllers (PLCs) connected directly to cellular modems—a configuration that exposed vital operational technology (OT) to the open internet. While no significant disruptions were reported, the breadth of the targeting has raised urgent questions about the vulnerability of the nation’s water supply.

Over 100 Water Systems Compromised: What CISA Revealed

CISA’s guidance, released alongside the confirmation, details a coordinated wave of intrusions that struck at least 12 states. Confirmed states include Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama, though the full geographic scope remains undisclosed. The agency emphasized that the attacks specifically targeted PLCs—devices that control pumps, valves, and chemical dosing—by leveraging direct cellular modem connections that bypassed normal network security layers. This attack vector allowed the threat actors to interact with industrial control systems (ICS) without needing to penetrate corporate IT networks first.

The affected systems were not limited to small rural utilities. The list includes larger municipal systems, indicating that the attackers conducted broad reconnaissance and exploited common exposure patterns. CISA stated that the malicious activity was observed “commonly via programmable logic controllers connected directly to a cellular modem,” a deployment method used for remote monitoring and control but one that creates a direct internet-accessible attack surface. The agency’s admission that over 100 systems were hit represents a significant escalation compared to previous public reports, which had only cited isolated incidents.

Iran-Linked Hackers and the Pattern of OT Disruption

The attackers behind the July 2026 campaign are linked to Iranian state-sponsored groups. This attribution aligns with a series of incidents targeting critical infrastructure in the United States and allied nations. In the same period, CISA warned of Iran-linked attacks specifically targeting ICS devices manufactured by Siemens, Schneider Electric, and Rockwell Automation—three of the most widely deployed industrial automation platforms in the water sector. The pattern suggests a deliberate strategy to disrupt operational technology rather than simply steal data.

Notably, the water sector attacks follow a precedent: in a separate incident, Iran-linked hackers successfully shut down a United Kingdom power plant for four days. That intrusion, which also targeted PLCs and remote terminal units, demonstrated that these threat actors possess both the intent and the technical capability to cause physical disruption. The water attacks in July 2026 did not achieve the same level of impact, but the targeting of over 100 systems indicates a reconnaissance and positioning effort that could precede more destructive actions. Cybersecurity analysts note that Iranian groups have historically used low-sophistication tactics—default passwords, unpatched firmware, and exposed remote access—to gain footholds in OT environments. The July campaign suggests they are scaling up their operations.

The Specific Vulnerability: PLCs and Cellular Modems

The attack vector highlighted by CISA—PLCs connected directly to cellular modems—represents a systemic vulnerability in the water sector. Many utilities adopted cellular modems for cost-effective remote monitoring, especially in rural or distributed systems. However, these modems often assign public IP addresses, making the PLCs reachable from the internet without intermediate security controls. Attackers can then use Shodan and other search engines to discover exposed devices, then attempt default credentials or exploit known vulnerabilities. In the July 2026 attacks, this method allowed the threat actors to probe hundreds of systems rapidly, identifying those with weak authentication or unpatched firmware.

The implications are profound. A PLC controlling a chlorine disinfection system, for example, could be manipulated to alter chemical dosing, potentially endangering public health. While no such manipulation was confirmed in this campaign, the attackers demonstrated they could reach into the operational layer. The use of cellular modems also complicates incident response: traffic travels over the cellular provider’s network, often bypassing corporate firewalls and intrusion detection systems, making detection more difficult.

CISA’s Prescription: Reducing Internet Exposure for PLCs and ICS

In response to the July attacks, CISA released updated guidance urging all organizations—particularly those in the water, energy, and manufacturing sectors—to aggressively reduce their internet attack surface. The guidance is structured around a clear imperative: identify all internet-accessible OT systems, determine which exposures are truly necessary, and eliminate or restrict the rest. CISA specifically calls for:

  • Inventories and external scanning: Use both internal asset management systems and external scanning tools (such as Shodan) to find every device exposed to the internet.
  • Default credential changes: Immediately replace default passwords on all PLCs, HMIs, and remote access gateways.
  • Security updates: Apply vendor firmware patches and security updates, especially for devices with known vulnerabilities.
  • Secure remote access: Route all remote connections through secure jump hosts or VPN gateways, never allowing direct internet exposure of OT devices.
  • Multifactor authentication: Enforce MFA for all remote access to OT systems, including cellular-based connections where feasible.
  • Continuous monitoring: Deploy network monitoring that can detect anomalous traffic patterns or unauthorized commands to PLCs.

The guidance also emphasizes the need for regular reassessments. Networks and third-party connections evolve, and a system that was once safely tucked behind a firewall may become exposed after a network change or a contractor’s new connection. CISA recommends quarterly external scans and annual internal audits of OT exposure.

How to Implement CISA’s Recommendations in Water Utilities

For water and wastewater utilities, the practical steps can be challenging due to limited budgets and OT expertise. The first step is to create a comprehensive asset inventory. Many utilities do not have a complete list of all PLCs, RTUs, and intelligent field devices. Free tools like CISA’s own CSET (Cyber Security Evaluation Tool) can help. Next, utilities should work with their cellular modem providers to determine if modems can be configured for private APNs (Access Point Names) that do not assign public IPs. Where direct cellular connectivity is unavoidable, the device should be placed behind a cellular router with firewall capabilities and VPN support.

Another critical measure is to segment OT networks from IT networks and the public internet. While some argue that air-gapping is the only safe approach, modern operational requirements often demand some connectivity. The compromise is to use a demilitarized zone (DMZ) architecture where only read-only data passes from the OT network to corporate systems, and all remote access is authenticated and logged. Utilities should also consider deploying industrial intrusion detection systems (IDS) that can recognize malicious commands to PLCs, such as commands to change setpoints or disable alarms.

The Unseen Risks of Cellular Modems in Critical Infrastructure

The July 2026 attacks bring into sharp focus the hidden danger of cellular modems. These devices are often installed by system integrators for remote troubleshooting or data logging, then left in place with factory-default settings. Unlike Ethernet connections, cellular modems do not show up on corporate network scans; they are invisible to IT teams until discovered through external scanning. This visibility gap makes them a favored vector for threat actors. CISA’s guidance explicitly calls out “PLCs connected directly to a cellular modem” as a primary risk, and the agency’s data suggests that the vast majority of the 100+ compromised systems used this configuration.

Mitigations include replacing cellular modems with hardware that supports VPN tunnels, or using cellular routers with integrated stateful firewalls. If replacement is not immediately possible, utilities should at least change default passwords on the modems themselves and disable any remote administration interfaces. In the longer term, the water sector needs to adopt standards such as the NIST Cybersecurity Framework and the American Water Works Association (AWWA) process control system security guidelines. Federal support, including the new Senate bill that establishes a “Water Watch Center,” may provide resources for smaller utilities to conduct these upgrades.

What This Means for the Water Sector and Beyond

The confirmation of over 100 targeted systems is a watershed moment. It demonstrates that sophisticated nation-state actors are actively scanning and exploiting internet-exposed OT devices at scale, and that the water sector is a prime target. The attacks did not cause physical damage this time, but the reconnaissance gained could be used in a future, more destructive campaign. The water sector is particularly vulnerable because it relies heavily on legacy equipment, has limited cybersecurity budgets, and often operates under the assumption that OT systems are not attractive targets.

The implications extend beyond water. The same tactics—scanning for internet-exposed PLCs, using cellular modems as an entry point, and targeting default credentials—are being used against energy grids, chemical plants, and transportation systems. The Iranian-linked attacks on Siemens, Schneider, and Rockwell ICS devices are a precursor to a broader threat landscape. CISA’s guidance, while focused on water, applies universally. The agency’s emphasis on reducing internet exposure is a direct response to a trend that shows no signs of abating.

Meanwhile, the Senate bill that boosts cybersecurity for water systems and establishes a centralized threat monitoring center (“Water Watch Center”) offers a structural solution. It would fund vulnerability assessments, provide rapid threat intelligence sharing, and help small utilities deploy basic security controls. The July 2026 attacks may accelerate this legislation, as lawmakers confront the reality that over a hundred critical water systems were reachable from the internet with trivial effort. The question is not whether another attack will happen, but whether the sector will act before the next one causes major disruption.

For now, every utility operator should treat their cellular-connected PLCs as a top priority. If a device can be seen on the internet, it will be targeted. The Iranian hackers have proven that they can find and interact with hundreds of systems in a single month. The only effective defense is to remove those devices from public view, secure the ones that must be online, and continuously monitor for any signs of intrusion. The CISA guidance provides a roadmap, but the execution rests on the shoulders of thousands of public works departments that have rarely thought of their control systems as a cybersecurity frontier. That thinking must change, and quickly.

Share This Article