Over 100 U.S. Water Systems Targeted in July Cyberattacks
CISA says malicious activity targeted more than 100 internet-exposed U.S. water and wastewater systems in July. The attacks highlight the risks of directly connected PLCs and forgotten remote-access paths.
On this page
More than 100 internet-exposed systems in the U.S. water and wastewater sector were targeted by malicious cyber activity during July, according to new guidance from the Cybersecurity and Infrastructure Security Agency (CISA). The disclosure matters less because it gives the campaign a larger headline number than because it reveals the access path: programmable logic controllers, or PLCs, were in some cases connected directly to cellular modems, putting equipment that controls physical processes within reach of remote attackers.
The number describes targets, not 100 confirmed breaches
CISA's wording is worth reading carefully. The agency says it observed malicious activity targeting more than 100 internet-exposed systems, rather than saying attackers successfully compromised more than 100 separate water utilities. That distinction prevents the figure from being turned into a misleading breach count, while still showing how widely attackers were looking for exposed operational technology. Independent reporting indicates the activity reached water and wastewater facilities in at least a dozen states, although the full list has not been publicly identified.
The attacks also have not produced the kind of widespread loss of water service that the raw number might suggest. Reporting from the affected campaign says there has been limited impact on supplies, although some incidents caused outages or operational disruption while utilities investigated and responded. The more worrying evidence is what attackers could do after reaching certain controllers: previous intrusions allowed changes to PLC settings that could disable shutdown processes or alarms, creating the possibility of unsafe operating conditions without an operator immediately knowing.
Why a cellular modem can become the weakest link
A PLC is a computer designed to control machinery and physical processes rather than a general-purpose desktop application. In a water facility, that can mean managing pumps, valves, flow or treatment equipment. Cellular connectivity is useful when a remote facility needs monitoring or maintenance without a conventional wired connection, but putting a PLC directly on an externally reachable connection removes layers of protection that would normally sit between the controller and the public internet.
That is the central lesson in the new CISA guidance. The problem is not that cellular technology is inherently unsafe; it is that a controller designed to operate industrial equipment should not ordinarily be exposed directly to hostile internet traffic. CISA specifically recommends disconnecting PLCs from the internet and placing necessary remote access behind a virtual private network or secure gateway instead of connecting directly to the controller.
The real security problem is exposure that nobody remembers
Water utilities often operate equipment with long service lives, remote locations and limited security staffing. A controller may have been connected for legitimate maintenance years ago and then effectively forgotten, even though the network path remains active. The result is a security problem that vulnerability scanners and patch reports can miss if an organization does not first know which industrial devices are actually reachable from outside.
CISA's recommended response therefore starts with visibility rather than another generic warning to patch everything. Organizations are being urged to inventory internet-accessible systems, determine which connections are genuinely necessary and remove or restrict unnecessary exposure. For systems that must remain reachable, the agency recommends stronger authentication, security updates, controlled remote-access paths and ongoing monitoring.
Remote access needs a controlled path
The practical architecture is straightforward. Instead of allowing an engineer's laptop or an attacker to reach a PLC directly, remote connections should pass through a controlled gateway or virtual private network where access can be authenticated, restricted and logged. CISA also recommends password protection, changing default passwords and limiting allowed connections to known engineering systems or other authorized operational technology assets.
That approach also changes what defenders should monitor. A water utility does not necessarily need to treat every unusual packet as a crisis, but an unexpected remote connection to a controller, a change in its configuration or an unfamiliar engineering endpoint should be visible to the security and operations teams. The goal is to make the legitimate maintenance path predictable enough that abnormal activity stands out.
The campaign exposes a problem beyond water utilities
The significance of the campaign extends beyond municipal water systems because the same type of architecture exists throughout critical infrastructure. PLCs and other industrial control systems operate equipment in energy, manufacturing, transportation and other environments where a cyber incident can affect physical processes rather than simply expose files. Recent reporting has also identified activity involving PLCs from manufacturers including Rockwell, Schneider Electric and Siemens.
That makes internet exposure a cross-sector security issue. A company can have fully patched Windows servers, strong email protection and modern endpoint detection while still maintaining an industrial controller that is reachable through an old remote-access arrangement. The security posture of the organization is ultimately constrained by that weakest reachable path.
Attribution is still less certain than the access method
Several analysts and officials have linked the broader activity to Iran, but the U.S. government has not publicly assigned the campaign to a specific threat group. That distinction should remain intact. Cyber attackers can reuse infrastructure, borrow tools and route activity through compromised systems, making confident attribution harder than identifying the technical weakness that allowed access.
For defenders, that uncertainty does not change the immediate remediation. Whether the activity came from a state-backed team, a criminal group or another actor, an internet-facing PLC remains an unnecessary opportunity if the connection is not required. The strongest response is therefore based on what can be verified: identify exposed controllers, remove direct internet access, secure unavoidable remote connections and watch for unauthorized changes.
What water operators should check now
The new CISA guidance gives utilities a useful checklist, but the order matters. First establish what is exposed; then decide what actually needs to remain reachable. Only after that should teams concentrate on hardening the connections that cannot be removed.
- Inventory PLCs, industrial control systems and other operational technology that can be reached from outside the facility.
- Remove direct internet access from controllers wherever operational requirements allow it.
- Put necessary remote access behind a secure gateway or virtual private network.
- Replace default passwords and enforce strong authentication on systems that support it.
- Restrict remote connections to known engineering devices and approved network paths.
- Monitor controller access and configuration changes for unexpected activity.
- Recheck exposure after network, vendor or remote-maintenance changes rather than treating the inventory as permanent.
None of those steps depends on knowing who was behind the July campaign. That is precisely why the latest disclosure is useful: it turns a series of scattered incidents into evidence of a repeatable exposure pattern. More than 100 targeted systems in one month is a warning that internet-facing industrial equipment is not an obscure edge case. For utilities and other critical-infrastructure operators, the next security review should start with a simple question: which controllers can an outsider reach right now?
Written by


