September 3, 2026

CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

In brief

CISA has warned water and wastewater utilities about a significant increase in attacks targeting internet-exposed programmable logic controllers. The alert followed coordinated intrusions on July 26–27, 2026, affecting operational technology at more than 30 Minnesota community water systems. Attackers have reportedly changed controller passwords to lock out operators and altered IP addresses to disconnect PLCs, sometimes forcing utilities into prolonged manual operation or prompting boil-water notices. Although several Minnesota facilities experienced disrupted automated controls, contingency procedures kept most services running and officials said drinking water remained safe. CISA emphasized that utilities of every size are at risk and should identify undocumented external connections, particularly cellular modems installed by operators, vendors or system integrators.

The Minnesota attacks have not been formally attributed, but they occurred soon after US authorities expanded a warning about Iran-linked activity targeting industrial controllers from Rockwell Automation, Schneider Electric and Siemens. CISA’s immediate recommendations are to remove PLCs from direct internet exposure, route necessary remote access through VPNs or secure gateways, replace default passwords and restrict connections to allowlisted IP addresses. Utilities should also maintain a verified clean backup of each PLC image so they can restore operations if attackers change credentials, and review the tactics and indicators described in the government’s broader advisory for evidence of previous compromise.

Source: SecurityWeek

Explore More Insightful Articles: