01 What Happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an alert on July 30, 2026, urging water and wastewater systems (WWS) sector operators to protect operational technology (OT) against a significant increase in malicious activity targeting programmable logic controllers (PLCs). The alert calls on critical infrastructure owners, operators, and system integrators to identify and remove publicly exposed PLCs and other OT assets from the internet as soon as possible.
CISA said observed tactics include attackers modifying passwords to lock out legitimate operators and disconnecting PLCs by changing their IP addresses, activity that has resulted in boil water notices and sustained manual operations at affected utilities. The agency noted that targeting spans water entities of all sizes, and that even organizations with mature cybersecurity programs should validate their external connections, specifically flagging cellular modems installed by operators, vendors, or system integrators that may not be captured in routine attack-surface scans.
The alert follows a coordinated cyberattack that, according to Minnesota IT Services, disrupted OT systems at more than 30 community water utilities across the state on July 26 and 27, 2026. Water and wastewater utilities in at least seven states have reported related incidents to the FBI since July 27, with some activity degrading water operations. Affected Minnesota cities, including Maple Plain, Braham, South St. Paul, and Plymouth, reported disruptions to some automated control functions, though contingency procedures were activated and water and wastewater operations remained functional in most cases; officials said drinking water remained safe. State and federal agencies are investigating, and no formal attribution has been made.
The timing follows a July 22 update to advisory AA26-097A — originally published in April 2026 — which had warned critical infrastructure organizations about Iran-linked activity targeting industrial control systems made by Rockwell Automation, Schneider Electric, and Siemens. Investigators have observed activity against Rockwell CompactLogix and Micro850 controllers, Schneider Electric Modicon M340 devices, and Siemens S7-1200 series PLCs, with the advisory noting that devices from other manufacturers may also be at risk. Iranian-linked groups including CyberAv3ngers and Handala fit the profile of actors known to target water-sector OT, though investigators have not linked the Minnesota incidents to a specific group.
CISA’s July 30 alert recommends three immediate steps for operators: disconnect PLCs from the internet and route any remote access through a VPN or gateway device rather than directly to the controller; enable password protection and change default passwords; and allowlist IP addresses so remote access is permitted only from known engineering laptops or other critical OT assets. The agency also advised operators to maintain a known-clean backup of each PLC’s image in case a device is locked out by a modified password, and pointed owners of Rockwell Automation MicroLogix 1400 controllers to Rockwell’s dedicated guidance for restoring access when a password is unknown. CISA further encouraged utilities to review the tactics, techniques, and indicators of compromise listed in advisory AA26-097A to check for signs of current or historical activity on their networks.
02 Key Takeaways
- 01 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an alert on July 30, 2026, urging water and wastewater systems (WWS) sector operators to protect operational technology (OT) against a significant increase in malicious activity targeting programmable logic controllers (PLCs).
- 02 The alert calls on critical infrastructure owners, operators, and system integrators to identify and remove publicly exposed PLCs and other OT assets from the internet as soon as possible.
- 03 CISA said observed tactics include attackers modifying passwords to lock out legitimate operators and disconnecting PLCs by changing their IP addresses, activity that has resulted in boil water notices and sustained manual operations at affected utilities.
- 04 The agency noted that targeting spans water entities of all sizes, and that even organizations with mature cybersecurity programs should validate their external connections, specifically flagging cellular modems installed by operators, vendors, or system integrators that may not be captured in routine attack-surface scans.
03 Why It Matters
CISA has issued an alert urging water and wastewater utilities to secure internet-exposed programmable logic controllers, days after a coordinated cyberattack disrupted operational technology at more than 30 Minnesota water systems.
04 ATLAS Engineering View
This record does not include a separate ATLAS engineering interpretation.
05 Sources
- This report is based on an alert published by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on July 30, 2026: “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs”, with additional reporting from SecurityWeek.