>samit_hota
Back to security news
SN-2026-257CriticalOpen

CISA Warns of Surge in Water Utility Cyberattacks as Minnesota Incidents Probed

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Water and Wastewater Systems (WWS) sector, Minnesota community water systems, utilities across seven US states
#news#data-breach#cisa

Federal cybersecurity authorities are urging water and wastewater operators to immediately disconnect industrial controllers from the public internet following a sharp rise in malicious attacks targeting critical infrastructure. A coordinated cyberattack beginning July 26 hit more than 30 community water systems in Minnesota, triggering state and federal investigations into whether the intrusions were carried out by state-sponsored actors linked to Iran.

The Cybersecurity and Infrastructure Security Agency (CISA), alongside the Federal Bureau of Investigation (FBI) and the Environmental Protection Agency (EPA), issued urgent warnings detailing an escalating campaign against water utilities across at least seven states. Intruders are actively probing for accessible operational technology (OT) assets, hijacking programmable logic controllers (PLCs), and disrupting remote monitoring capabilities. In multiple instances, the attacks forced affected municipalities to issue boil water notices and transition treatment facilities to sustained manual operations.

Exploited Vulnerability Class: Public Internet OT Exposure

The root cause of these disruptions is not a sophisticated zero-day vulnerability, but rather improper access control and architectural exposure: industrial assets directly accessible over the public internet. Programmable Logic Controllers (PLCs) are specialized, ruggedized computers that regulate physical processes in industrial environments, such as controlling valve openings, regulating water pressure, and managing chemical dosing levels.

In standard deployment models, PLCs rely on proprietary or unencrypted industrial protocols—such as Modbus, EtherNet/IP, or S7comm—that lack robust authentication, session encryption, or brute-force protections. When these devices or their administrative Human-Machine Interfaces (HMIs) are exposed directly to public IP addresses without a VPN or firewall perimeter, any remote attacker can locate them using public scanning engines like Shodan or Censys.

A primary contributor to this risk surface is the widespread use of cellular modems. Maintenance teams, third-party system integrators, and equipment vendors routinely install cellular gateways (such as Sierra Wireless or Cradlepoint devices) directly onto field PLCs to enable out-of-band remote maintenance. Because these modems bypass the utility’s core IT firewalls and enterprise monitoring, they frequently remain undocumented, unmonitored, and secured only by default manufacturer passwords or static, unauthenticated IP channels.

Attack Mechanics and Operational Impact

The threat actors driving this campaign employ low-complexity, high-impact disruption techniques once internet-facing PLCs or cellular modems are discovered:

  1. Credential Abuse and Takeover: Attackers authenticate to the HMI or Web management interface using default administrative credentials, simple dictionary attacks, or exposed management portals.
  2. Configuration Tampering: Once inside, the intruders modify administrative credentials to lock out legitimate system operators.
  3. Network Isolation: Attackers alter the IP address configurations of the PLCs, severing communication between the physical controllers and the Supervisory Control and Data Acquisition (SCADA) master station.
  4. HMI Defacement and Disruption: In addition to locking out staff, actors often clear system logs, alter setpoints, or display political messaging on connected touchscreen interfaces.

When SCADA operators lose visibility and control over automated chemical feeds and pump stations, safety protocols require immediate contingency actions. Facilities must switch to manual hand-cranking of valves and localized chemical testing, which is labor-intensive and difficult to maintain over extended periods. If pressure drops or chemical balances fluctuate during the outage, utilities are legally obligated to issue precautionary boil water advisories to prevent potential public health contamination.

Threat Actor Profile: Iranian-Linked Cyber Operations

The Water Information Sharing and Analysis Center (WaterISAC) and federal investigators have linked the recent campaign to Iranian-state-sponsored threat groups. Iran-aligned cyber operators—most notably groups associated with the Islamic Revolutionary Guard Corps (IRGC), such as Cyber Av3ngers—have historically targeted critical infrastructure using opportunistic, widespread scanning rather than bespoke malware.

These threat groups systematically target low-hanging fruit in adversary or Western infrastructure. Their standard operating procedure relies on scanning global IP ranges for specific embedded operating systems, default port assignments, and unpatched edge devices. Once access is established, their primary objective is operational disruption, public embarrassment of target governments, and psychological impact, rather than prolonged espionage or ransomware extortion.

By targeting small-to-medium municipal water districts, these actors exploit a known security gap: smaller utilities often operate with limited IT/OT security staff, minimal cyber budgets, and legacy equipment that was never designed to resist direct exposure to adversary state actors.

Required Mitigation Actions

CISA, the FBI, and the EPA advise all OT asset owners and operators—particularly within the Water and Wastewater Systems sector—to execute the following immediate remediation steps:

  • Identify and Isolate Exposed OT: Immediately perform external attack surface scans to identify all internet-facing PLCs, HMIs, and OT devices. Remove these assets from the public internet entirely.
  • Audit Cellular Modems: Inspect all field installations for unauthorized or undocumented cellular modems installed by vendors or operators. Ensure all remote connections route through an enterprise-managed, encrypted Virtual Private Network (VPN) or Zero Trust Network Access (ZTNA) gateway enforcing Multi-Factor Authentication (MFA).
  • Reset Default Credentials: Change all factory-default administrative passwords on PLCs, cellular gateways, routers, and HMIs across the operational environment.
  • Network Segmentation: Isolate OT networks from corporate IT networks using industrial firewalls configured with strict ingress and egress filtering rules. Disable public-facing management interfaces on ports 80, 443, 22, and 23 for all field devices.
  • Implement Out-of-Band Backups: Maintain offline, verified backups of all PLC logic files, device configurations, and HMI applications to allow rapid restoration if logic is altered or erased.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call