Friday, August 14, 2026

Independent technology reporting and practical analysis

Manila ·
TECHNOLOGY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Technology / news

CISA Warns of Surge in Cyberattacks Targeting Water Utility PLCs; Over 30 Systems Disrupted in Minnesota

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert after hackers disrupted operations at more than 30 community water systems in Minnesota by compromising internet-exposed programmable logic controllers.

An engineer monitors industrial controls inside a municipal water treatment facility.
An engineer monitors industrial controls inside a municipal water treatment facility.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a significant rise in cyberattacks targeting water and wastewater systems. Hackers are exploiting internet-exposed programmable logic controllers (PLCs) to disrupt services, the agency said in an alert published Thursday. The alert follows a coordinated attack that disrupted more than 30 community water utilities in Minnesota, which started on a Sunday and continued into Monday.

CISA described the threat activity: attackers accessed exposed PLCs and changed passwords to lock out legitimate operators, modified IP addresses to disconnect devices from the internet, and took other actions that caused operational disruptions. "CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible," the agency stated.

The campaign targeted organizations of all sizes, including some with mature cybersecurity programs. CISA highlighted a common blind spot: undocumented cellular modems installed by operators, vendors, or system integrators. Such devices can connect OT systems directly to the internet without the knowledge of security teams. Internet-facing assets are vulnerable to defacement, configuration changes, operational shutdowns, and even physical damage, the bulletin noted.

To mitigate these risks, CISA provided a set of immediate recommendations. The primary step is to remove OT assets from direct internet exposure. Where that is not possible, the agency advises using VPN connections or gateway devices for secure remote access. Additionally, default passwords must be changed and access should be restricted via IP address allow-lists. The agency also pointed owners of specific Rockwell Automation MicroLogix 1400 PLCs to vendor guidance on recovering access after passwords have been changed.

Cyber intelligence firm Censys published a blog post quantifying the internet exposure of industrial controllers. According to its data, more than 4,100 Rockwell Automation/Allen-Bradley hosts, 4,100 Siemens hosts, and over 2,000 Schneider Electric hosts are reachable online. Censys cautioned that these numbers reflect devices discoverable on the public internet, not systems necessarily targeted or compromised. However, the firm noted that many of the MicroLogix 1400 controllers highlighted in CISA's bulletin are running end-of-sale firmware, which may lack security patches.

Censys also identified a pervasive issue with cellular connectivity: nearly half of the exposed Rockwell devices are accessible via major carrier and ISP networks, including Verizon Business, AT&T, T-Mobile, Comcast, Charter, and Starlink. The firm shared an expanded set of indicators of compromise (IoCs) and threat-hunting guidance to help defenders detect related activity.

The Minnesota IT Services (MNIT) agency activated the state's cybersecurity incident response plan earlier this week after detecting what it described as "a coordinated cyberattack targeting operational technology at more than 30 Minnesota community water systems." Multiple municipalities reported disruptions; equipment malfunctions forced some utilities to temporarily switch to manual operations. MNIT has shared threat intelligence collected from the affected systems and provided guidance and best practices to help impacted utilities restore normal operations.

The attacks underscore the fragile cybersecurity posture of critical infrastructure sectors, where a single internet-exposed device can become an entry point for adversaries. CISA continues to urge water and wastewater facilities to assess their OT environments and apply fundamental protections.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Editorial illustration of a humanoid robot surrounded by neural networks, browser interfaces, code and an AI video timeline.
AI

AI's Biggest Week: GPT-5.6 Gets 80% Cheaper, Gemini Controls Humanoid Robots, and LinkedIn Fights AI Slop

Illustration representing the Lazarus hacking group targeting Windows systems
Technology

Lazarus Hackers Exploit Windows Zero-Day to Target Defense Firms

USB plug connected to a Windows computer, representing Plug and Pwn attacks
Technology

Plug and Pwn: Emulated USB Devices Force Windows to Install Vulnerable Software, Researchers Warn