CISA: Over 100 US water systems targeted in July cyberattacks
This digest was compiled by AI from multiple sources — links to the originals are below.

The Cybersecurity and Infrastructure Security Agency said more than 100 internet-exposed water systems were targeted in cyberattacks throughout July. Attackers most commonly hit programmable logic controllers connected directly to cellular modems. The agency issued guidance to reduce internet exposure of operational technology.
Key Facts
- CISA observed more than 100 internet-exposed water systems targeted in cyberattacks during July.
- Attackers most commonly targeted programmable logic controllers connected directly to a cellular modem.
- At least a dozen states were affected, with confirmed impacts in Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama.
- CISA issued guidance recommending organizations remove remote access when possible and secure it when necessary.
- Water-sector supplier Micro-Comm had nearly 850,000 files leaked by attackers on Aug. 26, claimed by ransomware group Barracuda.
Attack Campaign
The Cybersecurity and Infrastructure Security Agency said the July campaign hit the water and wastewater sector most commonly through programmable logic controllers connected directly to a cellular modem. Hackers used internet-based search and discovery platforms to spot publicly reachable systems running misconfigurations, default credentials, and outdated software. CISA first flagged an upsurge in water system hacks in a July 30 alert, warning that attackers were changing PLC passwords to lock out operators and altering device IP addresses to sever access. Utilities of all sizes were hit nationwide, including some with more mature security programs, according to analysts.
Affected States
CISA has not said how many states were affected, but at least a dozen states were swept up in the attacks. Utilities or state agencies in Minnesota, Michigan, South Dakota, Georgia, New Jersey, and Alabama have all confirmed they were among those impacted. Previous reports said the attacks were on water systems in 12 states.
Guidance and Response
CISA published guidance to help organizations cut the internet exposure of systems that attackers can easily find. The guidance walks operators through four steps: assess what is currently reachable from the internet, evaluate whether that exposure is operationally necessary, mitigate the risk to assets that must stay exposed, and reassess routinely. For anything that must remain reachable, CISA told organizations to change default passwords, apply patches, and replace software and devices no longer receiving security support. CISA said all organizations in the water and other critical infrastructure sectors should route all necessary remote access through a secure gateway, firewall, VPN, or other centrally managed access solution, as opposed to connecting directly to a PLC, human-machine interface, or remote terminal unit.
2 sources
CISA: Over 100 US water systems targeted in July cyberattacks



