CISA warns of increased cyberattacks targeting US water utilities
THE BRIEF
US cybersecurity authorities warned that water and wastewater systems were facing increased targeting after coordinated incidents affected utilities in multiple states. Reuters reported that attacks on 26–27 July disrupted more than 30 water systems in Minnesota, with related activity seen in at least seven states. Attackers interfered with internet-exposed operational technology, including programmable controllers, causing effects such as password changes, pressure loss and service disruption that required manual intervention. Authorities urged utilities to remove vulnerable systems from direct internet exposure and strengthen monitoring and access controls. The incidents formed part of a broader pattern of hostile interest in poorly protected industrial control systems.
WHY IT MATTERS
Water utilities illustrate the asymmetry of operational-technology risk: relatively simple access to exposed controllers can create physical and public-service consequences far beyond the cost of the initial intrusion. Many smaller utilities operate legacy systems with limited segmentation, telemetry and security staffing, making basic exposure reduction unusually valuable. The incidents also show why OT assets cannot be managed as ordinary IT endpoints. Owners need accurate inventories, safe patching processes, manual fallback procedures and incident-response plans that account for operational safety as well as confidentiality and data loss.
WHO SHOULD CARE
Utilities, OT security teams, critical-infrastructure operators, local government, CISOs and operational-resilience leaders.
WHAT TO DO NOW
- Identify and remove direct internet exposure from PLCs and remote engineering interfaces.
- Segment operational technology from enterprise and public networks.
- Review privileged access, remote maintenance accounts and default credentials.
- Monitor controllers for configuration changes and unusual commands.
- Rehearse manual operations and recovery procedures for loss of automated control.
VERIFICATION NOTE
Verified against Reuters reporting dated 30 July 2026 and CISA/FBI guidance referenced in the report.