- CISA warned of rising cyberattacks on US water systems, targeting 100+ exposed PLCs in July 2026
- Attacks caused password changes, IP reassignments, boil water notices, and manual operations
- Attribution uncertain, but reports suggest Iranian group; CISA urges removing PLCs from internet
CISA has warned of a “significant increase” in cyberattacks targeting US water systems, urging organizations to implement mitigations, strengthen their security posture, and make sure they’re resilient against these attempts.
CISA revealed it has seen hackers targeting more than 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, in July 2026 alone.
These attacks see the threat actors targeting programmable logic controllers (PLC), industrial computers used to control physical processes such as regulating water pumps or valves, allowing operators to monitor and control machinery in critical infrastructure such as water and wastewater facilities, and by targeting them, the attackers can disrupt services and potentially even create unsafe conditions for the citizens.
Blaming Iran
In its writeup, CISA did not discuss who the threat actors are or what they are trying to achieve.
In a report by The Register, however, it was said that the attacks were most likely done by a single threat actor, an Iranian state-sponsored group.
The publication also said that facilities in at least 12 US states were targeted, and that these attacks are merely testing the waters for a larger campaign that is being prepared.
This is all in the domain of speculation, however. Attribution is notoriously difficult and until it is confirmed, CISA is focused mostly on providing immediate assistance to the targets: “CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible,” the agency wrote.
“Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations.”
This articles is written by : Nermeen Nabil Khear Abdelmalak
All rights reserved to : USAGOLDMIES . www.usagoldmines.com
You can Enjoy surfing our website categories and read more content in many fields you may like .
Why USAGoldMines ?
USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.
