America’s water utilities faced a concentrated wave of cyberattacks in July, with exposed industrial control systems providing attackers a direct path into operational technology.
The Cybersecurity and Infrastructure Security Agency said malicious actors targeted more than 100 internet-exposed systems in the U.S. Water and Wastewater Systems sector during July 2026. In several cases, attackers remotely accessed programmable logic controllers, changed device settings and disrupted utilities’ ability to monitor or control equipment.
CISA said attackers remotely accessed exposed PLCs, changed device IP addresses and passwords, and in some cases caused utilities to lose monitoring and control capabilities. Some incidents also led to operational disruptions, although no confirmed widespread drinking-water contamination.
The campaign affected utilities in at least a dozen states, according to reports, including Minnesota, Michigan, Georgia, South Dakota and New Jersey. Minnesota alone confirmed malicious activity involving more than 30 community water systems.
The weak link: Remote access
CISA’s warning focuses heavily on a problem that can be easy to overlook: remote access that was added for convenience but left exposed.
“Directly connecting PLCs to the internet through cellular modems can create significant security risks,” CISA said in its guidance.
The agency recommends removing unnecessary remote access and routing legitimate connections through a secure gateway, firewall, VPN or centrally managed solution rather than connecting directly to a PLC, human-machine interface or remote terminal unit.
Utilities should also change default passwords, apply security patches, replace unsupported equipment and use multifactor authentication where possible. The guidance also encourages organizations to check vendor and contractor connections. That matters because third parties can introduce internet-facing equipment that may not appear in a utility’s own asset inventory.
Attribution remains unclear
The U.S. government has not publicly attributed the July campaign to a specific threat actor.
CISA’s count measures systems targeted, not necessarily successful breaches or separate utilities compromised. It also does not establish that every incident came from the same attacker.
The July campaign also highlights a difficult reality for smaller water providers: cybersecurity has to compete with operational demands and limited resources.
For water utilities, the immediate lesson is less about eliminating remote access than knowing exactly what is exposed.
CISA recommends that operators inventory internet-facing equipment, remove unnecessary direct connections, and verify systems installed or maintained by vendors and contractors. Exposure-discovery services such as Shodan, Censys and Shadowserver can also help utilities identify systems that may be reachable from the public internet.
For smaller providers with limited cybersecurity staff, that visibility may be the most important first step: a PLC cannot be secured if the utility does not know it is exposed.
More News: A cyberattack on medical device maker Boston Scientific disrupted global operations and its ability to process and ship customer orders, with no timeline yet for a full recovery.





