More Than 100 Water Systems Were Targeted. The PLCs Were Still on the Internet
CISA says malicious activity targeted more than 100 internet-exposed US water and wastewater systems during July 2026. Many of the affected environments exposed programmable logic controllers through cellular modems, giving attackers a direct route to equipment that operators relied on for essential services.
The incidents did not require a sophisticated supply-chain compromise or an unknown industrial exploit. The recurring problem was exposure: operational technology that should have been reachable only through controlled management paths was available from the public internet.
What CISA observed
CISA says attackers changed passwords and IP addresses on exposed devices, locked operators out and forced some facilities to move to manual operations. In certain cases, the activity contributed to boil-water notices while staff worked to restore control.
The agency has not publicly attributed every incident to one actor or one campaign. Similar access can be attractive to ideologically motivated groups, opportunistic attackers and operators looking for disruption or attention. Defenders should avoid turning a broad pattern of malicious activity into a more specific attribution than the evidence supports.
Cellular connectivity is still internet exposure
A cellular modem can look like isolation because it is not connected through the organisation’s normal corporate firewall. In practice, a public address or remotely reachable management service can expose the same control interface with fewer monitoring and access controls.
That architecture creates an accountability gap. The utility may assume the cellular provider limits access. The integrator may assume the plant controls authentication. The vendor may assume the owner changed default settings. Attackers only need one of those assumptions to be wrong.
Why small systems are attractive
Many water facilities have limited security staff, long equipment lifecycles and operational requirements that make patching or replacement difficult. A single exposed controller may sit behind a small utility, but the public-health consequence of losing control can still be serious.
The incidents also show why severity cannot be measured only by data loss. Changing a controller’s address or password can deny operators access without destroying equipment. The resulting manual work, uncertainty and public notice can be the attacker’s objective.
CISA’s exposure-reduction guidance
CISA’s guidance asks organisations to remove operational technology from direct internet exposure, inventory externally reachable services and use secure remote-access architecture. It also emphasises changing default credentials, applying multi-factor authentication where supported and restricting management to known administrative paths.
Facilities should not wait for a perfect asset inventory before acting. External discovery can identify exposed addresses quickly, while local validation confirms which devices are still in use and who owns the connection.
What water operators should do now
- Identify PLCs, human-machine interfaces, gateways and cellular modems reachable from the public internet.
- Remove direct exposure and place remote administration behind a controlled, monitored access service.
- Change default and shared passwords, then document who can recover access during an emergency.
- Restrict inbound management and outbound communication to approved addresses and protocols.
- Keep offline copies of controller configurations, network settings and restoration procedures.
- Alert on password, IP-address, firmware and configuration changes outside approved maintenance windows.
- Test manual operation and public-notification procedures before an incident forces their use.
- Coordinate with cellular providers and integrators so responsibility for exposure is explicit.
The BlackTree view
The number matters because it demonstrates a repeatable opportunity, not an isolated mistake. More than 100 targets were reachable because convenience had quietly become architecture.
Water security does not begin with exotic industrial malware. It begins with knowing which control interfaces are on the internet and having the authority to take them off. A cellular connection is not a security boundary, and manual operation is not a substitute for preventing avoidable access.
Sources
- CISA exposure-reduction guidance for operational technology, accessed 31 August 2026. CISA’s July 2026 observations describe malicious activity against more than 100 internet-exposed water and wastewater systems.
- TechCrunch: CISA confirms hackers targeted over 100 US water systems during July, published 26 August 2026 at 07:31 PDT, or 16:31 Europe/Madrid.
- SecurityWeek: CISA says over 100 internet-exposed water systems were targeted, published in August 2026. Consult the source page for its displayed publication time.


