>samit_hota
Back to security news
SN-2026-250HighOpen

CISA Urges Water Sector to Secure Exposed PLCs Following Minnesota Cyberattacks

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Water and Wastewater Systems (WWS), Siemens S7-1200, Rockwell Automation (CompactLogix, Micro850, MicroLogix 1400), Schneider Electric Modicon M340
#news#data-breach#cisa

Coordinated Intrusions Hit Minnesota Water Systems

Over the weekend of July 26 and 27, a coordinated cyberattack targeted operational technology (OT) networks across more than 30 community water systems in Minnesota. Disclosures from local municipalities—including Maple Plain, Braham, South St. Paul, and Plymouth—indicate that attackers successfully disrupted automated control functions within municipal water and wastewater facilities. While contingency procedures were triggered promptly to keep drinking water safe and operational, the intrusions forced facilities into sustained manual operations and triggered boil water advisories in affected areas.

In response, the Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert on July 30, warning water and wastewater system (WWS) operators nationwide of a sharp uptick in malicious activity targeting programmable logic controllers (PLCs). The alert warns that threat actors are actively scanning for internet-exposed controllers, exploiting exposed management interfaces to lock operators out, alter network configurations, and interrupt critical automation processes.

Cellular Modems and the Exposure of Industrial Controllers

Programmable logic controllers are the primary workhorses of industrial automation, responsible for executing real-time operational commands such as regulating valve positions, controlling pump speeds, managing chemical dosing, and monitoring tank levels. In water treatment facilities, PLCs communicate with Human-Machine Interfaces (HMIs) and Supervisory Control and Data Acquisition (SCADA) servers to maintain safe, steady water distribution.

The primary attack vector in these recent intrusions is direct exposure to the public internet, frequently introduced through unmonitored cellular modems. Field technicians, third-party integrators, or equipment vendors often install 3G, 4G, or 5G cellular gateways to enable remote telemetry or simplified offsite servicing. When these modems bypass centralized OT perimeters and lack proper firewalls, they expose the PLC’s management interface directly to automated internet scanning engines.

Once attackers discover an exposed controller, they utilize direct network protocols to interact with the device. In observed campaigns, threat actors have executed the following actions:

  • Authentication Bypass and Default Password Exploitation: Exploiting default administrator credentials or unauthenticated access portals to gain full administrative privileges over the device.
  • Operator Lockout via Credential Changes: Modifying the local administrative password on the PLC, effectively locking engineering workstations and plant operators out of the controller’s configuration interface.
  • Network Interface Reconfiguration: Changing static IP addresses or subnet parameters on the PLC, breaking communication with the plant’s HMI and SCADA software.

Without communication between the HMI and the controller, automated control loops fail, triggering fail-safe alerts and forcing operators to manage chemical treatment and pumping physically on-site.

Threat Landscape and Iranian Actor TTPs

While state and federal agencies investigating the Minnesota incidents have not formally attributed the attacks to a specific group, the tactics closely mirror those employed by Iran-linked threat groups, including CyberAv3ngers and Handala. On July 22, the U.S. government updated advisory AA26-097A (originally published in April), warning critical infrastructure operators that Iranian state-sponsored actors have broadened their targeting of industrial control systems (ICS).

Historically focused on Rockwell Automation Allen-Bradley devices, recent advisories highlight that attackers are actively targeting a wider array of vendor hardware, specifically:

  • Siemens: S7-1200 series PLCs
  • Rockwell Automation: CompactLogix, Micro850, and MicroLogix 1400 controllers
  • Schneider Electric: Modicon M340 PLCs

Groups like CyberAv3ngers have an established track record of targeting small-to-medium municipal water utilities. In 2020, Iran-linked actors executed similar intrusions against Israeli water facilities by leveraging vulnerable cellular routers as their entry point. These groups frequently operate opportunistically, targeting any accessible utility regardless of its size or cybersecurity maturity.

Blast Radius and Operational Impact

The operational blast radius of a compromised PLC in a water utility extends beyond digital disruption into physical safety and operational sustainability:

  • Loss of Automated Dosing and Telemetry: If chemical feed pumps lose automated pacing controlled by PLCs, chemical levels (such as chlorine or fluoride) can drift outside safe parameters, requiring manual sampling and manual adjustments.
  • Resource Strain and Manual Operations: Small municipal water utilities often operate with lean staffing. Switching to round-the-clock manual operations places severe operational strain on local staff and increases the likelihood of human error during system monitoring.
  • Preemptive Boil Water Advisories: When automated monitoring cannot guarantee real-time water quality parameters, public health regulations frequently mandate issuing boil water notices to protect consumers.
  • Physical Device Lockout: If an attacker modifies local passwords without a documented offline recovery process, utility technicians cannot update ladder logic or adjust operational parameters without performing physical factory resets or hardware replacements.

Required Remediation and Hardening Actions

CISA strongly advises water sector owners, operators, and system integrators to execute immediate defensive actions to mitigate exposure:

  1. Conduct Field Audits for Cellular Modems: Audit all operational sites for unmapped cellular modems, field routers, and serial-to-Ethernet converters installed by vendors or integrators. Ensure no PLC or OT asset is reachable directly via a public IP address.
  2. Implement Secure Remote Access: Immediately disconnect PLCs from direct internet access. Force all remote administrative and telemetry traffic through an encrypted Virtual Private Network (VPN) or OT security gateway with strict IP address allowlisting (restricting connections solely to known engineering workstations).
  3. Enforce Strong Credentials: Enable password protection and change default administrative credentials across all PLCs, HMIs, cellular modems, and field routers. Ensure passwords conform to robust complexity standards.
  4. Maintain Offline Logic Backups: Maintain clean, offline, and out-of-band backups of PLC ladder logic program images. If a controller is locked out by unauthorized password modifications, clean backups are required to restore operational state.
  5. Rockwell MicroLogix 1400 Recovery: Facilities deploying Rockwell MicroLogix 1400 controllers that suspect credential tampering should consult Rockwell Automation’s dedicated hardware recovery guidance to reset administrative access safely when the password is unknown.
  6. Threat Hunting: Review OT network logs and firewall perimeter logs for indicators of compromise (IOCs) and tactics detailed in joint security advisory AA26-097A.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call